NewsCryptoConsenSys Founder Joseph Lubin Says MetaMask Wallets Safe After Security Incident

ConsenSys Founder Joseph Lubin Says MetaMask Wallets Safe After Security Incident

Author: Cryptopolitan·

Key Takeaways

  • •Joseph Lubin confirmed that MetaMask users' Secret Recovery Phrases, private keys, and assets were not part of the security incident because the wallet's self-custody model keeps those credentials entirely under users' control.
  • •MetaMask disclosed on September 30 that part of its infrastructure had been impacted and responded by rotating validator keys and temporarily shutting down some Ethereum staking machines it operates for clients.
  • •MetaMask have begun an exit process finishing October 7, with ETH withdrawals potentially taking about 45 days and a further 45-day Ethereum entry queue, meaning staked assets could sit dormant, miss standard yields, and risk offline penalties.
  • •MetaMask has warned users to be alert to phishing attempts and to never share their Secret Recovery Phrase or private keys, directing users to official channels while the investigation remains open.
  • •Earlier in 2026, a North Korea-linked operative using the alias 'Tyler Knapp' worked inside MetaMask for roughly a month and integrated code into wallet features before being terminated, with no funds stolen.
ConsenSys Founder Joseph Lubin Says MetaMask Wallets Safe After Security Incident

ConsenSys founder Joseph Lubin has reassured MetaMask users that there is no indication the company's recent cyberattack has affected the MetaMask wallet system itself, confirming that user wallets and private keys remain completely safe.

The update comes after MetaMask disclosed on September 30 that part of its infrastructure had been impacted by a security incident. MetaMask is the self-custodial wallet developed by ConsenSys, a design in which users — not the company — hold the credentials that control their funds.

In a post on X (https://x.com/ethereumJoseph/status/210616220729802928?s=20), Lubin assured customers: “Your Secret Recovery Phrase, your keys, and the assets in your wallet were not part of this incident because they CANNOT be. You custody and control your own keys. That is how self custody works.”

When the breach was first discovered on Thursday, MetaMask temporarily shut down some Ethereum staking machines it operates on behalf of clients. Even at that stage, the company indicated it had seen no “immediate threat” to customer wallets.

Lubin says validator keys were rotated

In his X post, Lubin explained why it took him some time to publicly address the incident. He noted that MetaMask limits public commentary while an investigation remains open, but alerts core partners and relevant stakeholders once the issue has been fully diagnosed.

He maintained that clients' funds remained secure because the company operates on a self-custody model, meaning users retain complete control over their own money.

Lubin also noted that the company rotated its validator keys, though he acknowledged a downside: validators must exit the staking queue and rejoin in order to stake again — a process that can take considerable time. Ethereum builds entry and exit queues into its protocol to regulate how quickly validators can leave and rejoin the network, and wait times stretch when large numbers of validators move at once.

The firm additionally shut down some of its staking machines. Lido, a major staking protocol, had previously noted that while such a shutdown helps protect staked coins, it also comes at a cost. Validators operated by MetaMask have begun leaving the system, and the remaining validators are expected to stop staking by Oct. 7.

MetaMask validators have begun an exit process that finishes on October 7. Withdrawing the ETH could take about 45 days. Moreover, clearing the subsequent 45-day Ethereum entry queue means the assets face prolonged dormancy, miss out on standard yields, and risk penalties if knocked offline.

What the incident means for MetaMask users

The distinction between MetaMask's infrastructure and users' self-custodied wallets is crucial to assessing the impact of the incident. MetaMask allows users to control their own private keys and Secret Recovery Phrases rather than holding them on users' behalf. An attack on part of ConsenSys' infrastructure therefore does not automatically give an attacker access to the funds stored in users' wallets. That stands in contrast to custodial services, where a provider holds keys on customers' behalf and a successful breach of the provider can expose user funds directly.

However, the attack has once again highlighted the risks facing the infrastructure that supports crypto services. MetaMask works with Ethereum validators and other blockchain infrastructure, meaning a compromise can disrupt operations even when customer keys and assets remain outside the attacker's reach.

MetaMask has also warned users to watch for phishing attempts following the incident, stressing that users should never share their Secret Phrase or private keys with anyone claiming to offer support. Because Lubin said the company limits public commentary while its investigation remains open, official MetaMask channels are the reliable source for follow-up details as the diagnosis progresses.

MetaMask faced another security risk earlier in the year

The infrastructure incident follows closely on the heels of another high-profile security scare for ConsenSys. In July 2026, it was revealed that a North Korea-linked software developer had spent roughly a month working within MetaMask, with ConsenSys entirely unaware of the developer's true identity.

Using the alias 'Tyler Knapp,' the operative secured a consulting role and successfully integrated code into critical wallet features handling cash-to-crypto bridging. ConsenSys severed his backend access upon discovery and confirmed that no funds had been stolen.

The operative's access spanned from March 9 until his termination in April — a multi-week window that raised alarms among cybersecurity analysts. According to blockchain intelligence firm TRM Labs, targeting developer environments has become the fastest method for adversaries to harvest a crypto firm's private keys and infiltrate withdrawal approval pipelines.

Upon discovering the breach in April, ConsenSys immediately notified federal law enforcement and initiated a comprehensive overhaul of its contractor background-check protocols. “We discovered the threat… and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security,” Matt Corva, ConsenSys general counsel, noted.

The breach is far from an isolated incident. State-sponsored North Korean operatives routinely masquerade as qualified engineers to secure remote roles, using their access to exfiltrate proprietary data or establish backdoors.

Researchers from the Ethereum-funded Ketman Project had flagged 100 suspected North Korean IT workers who successfully penetrated 53 different crypto platforms. These operatives generally use false identity documents and fake recruiter profiles to bypass HR vetting, occasionally relying on U.S. citizens — some of whom have since been jailed — to launder the workers' physical and digital locations.