Key Highlights
- Joseph Lubin said there is currently no evidence that the security incident affected MetaMask wallets or user funds.
- MetaMask recovery phrases, private keys, and wallet-held assets were not included in the reported scope of the incident.
- Consensys and its partners changed validator keys as a precaution, causing some validators to exit and re-enter the staking queue.
Joseph Lubin Says MetaMask Wallets and Funds Were Not Affected
Joseph Lubin, co-founder of Ethereum and founder of Consensys, provided an update on the security incident affecting part of Consensys’ infrastructure. Lubin said investigations conducted so far have found no evidence that MetaMask wallets or users’ funds were affected.
According to Lubin, confidential MetaMask recovery phrases, private keys, and assets stored in users’ wallets were outside the scope of the incident. The update addresses concerns about whether the infrastructure issue could have exposed the credentials or digital assets used to access MetaMask accounts.
MetaMask Users Retained Control of Their Keys
Lubin highlighted MetaMask’s private storage model, emphasizing that users retained control of their keys. He also stated that Consensys did not have access to those keys, meaning the company’s infrastructure did not hold users’ confidential recovery phrases or private keys within the reported scope of the incident.
The findings specifically distinguish the affected infrastructure from the user-controlled components of MetaMask wallets. Based on the investigation described by Lubin, there is no indication that the incident compromised the wallet credentials or assets held by MetaMask users.
Validator Key Changes Caused Staking Disruptions
As a precautionary measure following the security incident, Consensys and its partners reportedly changed their validator keys. The change created operational disruptions for some validators and required them to exit the staking queue before rejoining it.
Lubin said that exiting and re-entering the staking queue can be time-consuming. The process affected validator operations, but the reported disruption was separate from the findings concerning MetaMask wallets, private keys, recovery phrases, and user funds.
Why This Matters
The incident underscores the operational impact that infrastructure security measures can have on blockchain staking services, even when investigations find no evidence of compromised user wallets or funds. Changing validator keys can require validators to move through staking-queue procedures, potentially delaying their return to active operations.
For MetaMask users, the update indicates that the reported incident did not include their confidential recovery phrases, private keys, or wallet-held assets. Consensys’ ongoing findings and the validator-key changes remain central to understanding the incident’s operational effects.
Frequently Asked Questions
Were MetaMask wallets affected by the security incident?
Joseph Lubin said investigations so far have found no evidence that MetaMask wallets or user funds were affected.
Were MetaMask recovery phrases and private keys exposed?
According to Lubin, confidential recovery phrases and private keys were not included in the scope of the incident. He also stated that Consensys did not have access to users’ keys.
Why did some validators experience disruptions?
Consensys and its partners reportedly changed validator keys as a precaution. Some validators consequently had to exit and re-enter the staking queue, a process that can take time.




