Joseph Lubin: No MetaMask Wallets or Customer Funds Affected by Security Incident
Key Takeaways
- •A security incident affected part of Consensys' infrastructure, but the investigation to date has found no indication that MetaMask wallets or customer funds were affected.
- •Users' Secret Recovery Phrases and private keys were not involved in the incident because MetaMask operates on a self-custody model in which users control their own keys.
- •Consensys and its partners rotated validator keys as a precaution, a process Lubin described as operationally inconvenient because validators must exit and re-enter the staking queue.
- •Ethereum's architecture separates validator keys from withdrawal keys, meaning the incident could not have resulted in unauthorized transfers of staked ETH.
- •Consensys has not disclosed the technical nature of the event, though it says it discloses issues promptly to partners and relevant stakeholders once an issue is sufficiently understood.

Joseph Lubin, the Ethereum co-founder and founder of Consensys, said a security incident affected part of the company's infrastructure, but the investigation to date has found no indication that MetaMask wallets or customer funds were affected. According to Lubin, users' Secret Recovery Phrases and private keys were not involved in the incident. MetaMask, Consensys' widely used self-custody wallet, allows users to hold their own keys rather than entrusting them to an intermediary — a distinction with direct security implications, since in custodial arrangements the provider holds users' keys and a provider-side compromise can directly expose customer funds.
As a precaution, Consensys and its partners rotated validator keys following the incident. Lubin also stressed that validator keys and withdrawal keys are separate under Ethereum's design, meaning the incident could not result in unauthorized transfers of staked ETH.
Lubin Clarifies the Scope of the Incident
In a post shared on X on October 2, 2026, Lubin said he had just returned from a packed week in Seoul for Korea Blockchain Week (KBW), an annual industry event, during which he stayed on top of his company's response to the security event. The post came after Consensys publicly disclosed the incident, and Lubin wrote that he could now respond to queries and speculation about what was impacted and what was not.
Coming up for air now after a very dense excellent week in Seoul at KBW, while staying on top of our response to a security affecting part of our infrastructure. I can now respond to queries and speculation regarding what is impacted and what is not affected. Based on…
— Joseph Lubin (@ethereumJoseph) October 2, 2026
Source: @ethereumJoseph on X
In the post, Lubin stated that "there is no indication that MetaMask wallets or customer funds in wallets have been affected." Turning to user keys directly, he said the Secret Recovery Phrase and wallet assets "were not part of this incident because they CANNOT be," adding: "You custody and control your own keys. That is how self custody works."
Lubin also noted that Consensys faces attempted attacks from a range of threat actors and, like many providers, periodically encounters security issues. He explained that the company does "not publicly discuss the details of an open incident," and has not detailed the technical nature of this event, but discloses issues "promptly to partners and relevant stakeholders once an issue is sufficiently understood." Until the company shares more, the technical specifics of what occurred remain the main open detail for readers to track.
In this case, Consensys shared details with its partners, both sides agreed on a response strategy and implemented it together, and the company then disclosed the incident publicly — a sequence that matches the approach Lubin described.
Validator Rotation and Ethereum's Staking Design
The precautionary rotation of validator keys by Consensys and its partners was, in Lubin's words, "operationally inconvenient" and regrettable. Validators must exit the staking queue and then re-enter it to restake, a process that takes time, and the change also required coordination with partners.
Lubin explained that Ethereum's validator architecture separates two keys: one proposes and attests, while the other can withdraw the stake. Because of this separation, he said, "an issue in the validator infrastructure CANNOT result in the improper movement of the underlying ETH." And because that separation is built into Ethereum's protocol itself, the protection applies to any validator operator rather than being specific to Consensys.
On custody, Lubin stated: "In accordance with the Ethereum principle of self-custody, we do not hold withdrawal keys for our clients." As a result, the incident could not have led to unauthorized transfers of staked ETH, and rotating the keys further reduced residual operational risk.
Self-Custody as a Core Principle
Lubin described self-custody and user control as central design principles at Consensys, saying they guide the company's MetaMask wallet, its staking services, and its validation operations. He argued that the same principles apply across Ethereum more broadly.
He concluded that "self custody plus rigorous decentralization represents a paradigm shift in security," noting that the world is increasingly waking up to the benefits of this architecture.