Joseph Lubin, co-founder of Ethereum and founder of Consensys, commented on the security incident affecting part of the company’s infrastructure. Lubin stated that investigations so far have found no evidence that MetaMask wallets or user funds were affected.
According to Lubin, MetaMask users’ confidential recovery phrases, private keys, and assets held in their wallets were not included in the scope of the incident. Highlighting MetaMask’s private storage model, Lubin emphasized that users retained control of their keys and that Consensys did not have access to them.
Following the security incident, Consensys and its partners reportedly changed their validator keys as a precautionary measure. Lubin stated that this caused some operational disruptions, requiring validators to exit and rejoin the staking queue, a process that can be time-consuming.
Lubin pointed out that in Ethereum’s staking architecture, the keys used for verification processes and the keys used to withdraw staked ETH are separate, and that the company does not hold customer withdrawal keys. Therefore, he stated that a security issue in the validator infrastructure could not lead to the unauthorized transfer of staked ETH to another address.
Lubin noted that the change in the validator keys was carried out to reduce remaining operational risks. He also stated that the company did not share details of the security incident with the public while the investigation was ongoing, but would share information with business partners and relevant parties once the situation was sufficiently clear.
*This is not investment advice.


