Joseph Lubin: MetaMask Ethereum (ETH) Wallets Unaffected by September 30 Security Incident
ConsenSys founder Joseph Lubin says MetaMask wallets and funds are safe after the September 30 security incident; ETH validators stop staking October 7.
AI SummaryAI
- ConsenSys disclosed a security incident affecting part of MetaMask's infrastructure on September 30.
- Joseph Lubin said MetaMask wallets, private keys and user funds show no signs of compromise.
- MetaMask halted some Ethereum staking machines after detecting the breach on October 1.
- MetaMask-run validators are expected to stop staking by October 7.
MetaMask Infrastructure Incident
ConsenSys, the company behind the MetaMask wallet, disclosed on Wednesday, September 30, that a security incident had affected part of its infrastructure. Joseph Lubin, the
Ethereum (ETH) co-founder who leads the firm, has now addressed the event directly, saying reviews carried out so far have found nothing indicating that MetaMask wallets or user funds were touched. His statement on X is blunt: “Your secret recovery phrase, your keys, and the assets held in your wallet were not part of this incident because they could not be. You hold custody and control of your own private keys.” The company's customer-facing lead delivered the same message in parallel posts. The design matters here. MetaMask is a self-custody wallet, meaning users, not the company, hold the keys and the recovery phrases, so a breach of backend systems does not automatically hand an attacker access to funds sitting in individual wallets. Lubin's own framing stressed that ConsenSys never gains access to those keys under the personal-custody model. He also noted the company has withheld detailed findings while the investigation continues, communicating with core partners and relevant stakeholders once a problem has been fully diagnosed. MetaMask separately warned users to expect phishing attempts in the wake of the event, repeating that no legitimate support channel will ever ask for a recovery phrase or a private key. The episode sits above the network layer rather than on it: the Ethereum (ETH) price and chain operations were never in play, and no loss of funds has been reported so far.
@ethereumJoseph · X post
Statement on X.
View on X
Validator Keys Rotated
The operational response has landed on Ethereum's staking side. As a precaution, ConsenSys and its partners rotated their validator keys, the credentials validators use to sign attestations on the network. Lubin acknowledged the move caused some operational friction: validators had to exit the staking queue and rejoin to restake, a process that can take considerable time. When the breach was first detected on Thursday, October 1, MetaMask temporarily halted some
Ethereum (ETH) staking machines running on behalf of clients, while stating at the time that it saw no immediate threat to customer wallets. MetaMask-run validators have begun leaving the system, and the remaining ones are expected to stop staking by October 7. Their ETH withdrawals may still be in progress after that date, and clearing the subsequent entry queue could leave assets idle for roughly 45 days, a stretch in which the position misses standard staking rewards and carries slashing risk if validators drop offline. Lido, a major staking protocol, has previously observed that shutting down machines protects staked coins but comes at a cost. Lubin also drew an architectural line: in Ethereum's staking design, the keys used for attestation are separate from the withdrawal keys that control exiting staked ETH, and ConsenSys does not hold customers' withdrawal keys. A compromise of validator infrastructure therefore cannot move staked ETH to another address without authorization. Key rotation, he said, was performed to reduce the remaining operational risk while the investigation runs.
Infrastructure Risk Recurs
Lubin's post on X remains the primary record here, and read against the second disclosure it traces one arc: the risk surface in crypto has shifted from smart contracts toward the corporate infrastructure behind them. The July 2026 episode makes the pattern hard to dismiss. A North Korea-linked developer, working under the alias Tyler Knapp, spent roughly a month inside MetaMask from March 9 until his dismissal in April, reaching code in features handling bridges before backend access was cut. ConsenSys said at the time that no assets or data were taken, notified federal law enforcement, and restructured its contractor screening. Blockchain-analytics firm TRM Labs has called developer environments the fastest route for adversaries to extract private keys. For now the record stands: no funds lost, validator exits complete by October 7, and detailed incident findings still undisclosed.
Primary sources
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

