Consensys founder says MetaMask wallets safe after security incident

- Consensys founder Joseph Lubin says user wallets and private keys are safe.
- He claimed they rotated validator keys as a precaution.
- Metamask reported a high security scare in July
ConsenSys founder Joseph Lubin has reassured MetaMask users that there is no indication that the company’s recent cyberattack is affecting part of the MetaMask system. Lubin has confirmed that user wallets and private keys are completely safe.
The update comes after MetaMask disclosed on September 30 that part of its infrastructure had been impacted by a security incident.
The executive assured customers on X: “Your Secret Recovery Phrase, your keys, and the assets in your wallet were not part of this incident because they CANNOT be. You custody and control your own keys. That is how self custody works.”
When the breach was first discovered on Thursday, Metamask temporarily shut down some Ethereum staking machines operated on behalf of clients. Though at the time, it also indicated they had seen no “immediate threat” to customer wallets.
Lubin says they rotated validator keys
In his X post, Lubin explained why it took him some time to respond to the incident. He noted that Metamask limits public commentary during open investigations but alerts core partners and relevant stakeholders once the issue is fully diagnosed.
Overall, he maintained that clients’ funds remained secure because the company uses self-custody, meaning users retain complete control of their money.
Lubin noted that the company also rotated its validator keys, but there is a downside: validators have to exit the staking queue and rejoin to stake again. A process that could take a lot of time.
The firm also shut down some of its staking machines. Lido, a major staking protocol, had previously noted that while the shutdown helps protect the staked coins, it also comes with a cost. Validators operated by MetaMask have begun leaving the system, and the remaining validators are expected to stop staking by Oct. 7.
Their ETH, however, may still be being withdrawn.MetaMask validators have begun an exit process that finishes on October 7. Withdrawing ETH could take about 45 days. However, clearing the subsequent 45-day Ethereum entry queue means the assets face prolonged dormancy, miss out on standard yields, and risk penalties if knocked offline.
What the incident means for MetaMask users
The distinction between MetaMask’s infrastructure and users’ self-custodied wallets is crucial to assessing the impact of the incident. MetaMask lets users control their own private keys and Secret Recovery Phrases, instead of having them in their hands.
So an attack on part of ConsenSys’ infrastructure does not automatically give an attacker access to the funds stored in users’ wallets.
But the attack has again highlighted the risks to the infrastructure that supports crypto services. MetaMask works with Ethereum validators and other blockchain infrastructure, meaning a compromise can disrupt operations even when customer keys and assets remain outside the attacker’s reach.
MetaMask has also warned users to watch for phishing attempts following the incident. Users should never share their Secret Recovery Phrase or private keys with anyone claiming to offer support.
Metamask had faced another security risk earlier in the year
The infrastructure incident follows closely on the heels of another high-profile security scare for Consensys; in July 2026, it was revealed that a North Korea-linked software developer spent roughly a month working within the MetaMask.
Consensys was entirely unaware of the developer’s true identity. He used the alias ‘Tyler Knapp’ to secure a consulting role. Though he successfully integrated code into critical wallet features handling cash-to-crypto bridging, Consensys severed his backend access upon discovery and confirmed that no funds had been stolen.
The operative’s access spanned from March 9 until his termination in April, a multi-week window that raised alarms among cybersecurity analysts. According to blockchain intelligence firm TRM Labs, targeting developer environments has become the fastest method for adversaries to harvest a crypto firm’s private keys and infiltrate withdrawal approval pipelines.
Upon discovering the breach in April, Consensys immediately notified federal law enforcement and initiated a comprehensive overhaul of its contractor background-check protocols. “We discovered the threat… and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security,” Matt Corva, Consensys general counsel, noted.
The breach is far from an isolated incident. State-sponsored North Korean operatives routinely masquerade as qualified engineers to secure remote roles, using their access to exfiltrate proprietary data or establish backdoors.
Researchers from the Ethereum-funded Ketman Project had flagged 100 suspected North Korean IT workers who had successfully penetrated 53 different crypto platforms. These operatives generally use false identity documents and fake recruiter profiles to bypass HR vetting, occasionally using U.S. citizens who have since been jailed for laundering the workers’ physical and digital locations.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
Are MetaMask wallets affected by the ConsenSys security incident?
ConsenSys founder Joseph Lubin said there is no indication that MetaMask user wallets, private keys, Secret Recovery Phrases, or customer assets were affected by the incident.
Why did MetaMask shut down some Ethereum validators?
MetaMask shut down some staking machines and rotated validator keys as a precaution following the security incident. The move requires affected validators to exit and later rejoin Ethereum’s staking queue.
What should MetaMask users do after the security incident?
Users should remain alert for phishing attempts and never share their Secret Recovery Phrase or private keys with anyone claiming to provide MetaMask support.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Nellius Irene
Nellius is a Business Management and IT graduate with five years of experience in the cryptocurrency industry. She is also a graduate of Bitcoin Dada. Nellius has contributed to leading media publications, including BanklessTimes, Cryptobasic, and Riseup Media.
















