Ethereum co‑founder and Consensys founder Joseph Lubin addressed a recent security incident that affected part of the company's infrastructure. In a post on X, Lubin said the investigation so far shows no indication that MetaMask wallets or customer funds were compromised.
Scope of the incident
Lubin clarified that users' secret recovery phrases and private keys were not involved and cannot be affected by the incident. He emphasized that Consensys follows the Ethereum principle of self‑custody, meaning users retain control of their own keys.
Response actions
Consensys and its partners rotated validator keys as a precautionary measure. The rotation required validators to exit the staking queue and re‑enter, a process described as operationally inconvenient but necessary to reduce residual risk.
Validator architecture
The Ethereum validator design separates the validator key, which proposes and attests to blocks, from the withdrawal key, which can move staked ETH. Lubin noted that because these keys are distinct, the incident could not result in unauthorized transfers of staked ETH. Consensys does not hold withdrawal keys for its clients.
Ongoing security posture
Lubin acknowledged that Consensys, like other providers, faces attempted attacks from various threat actors and periodically encounters security issues. The company disclosed the incident to partners and relevant stakeholders once sufficient understanding was achieved, then made a public announcement.
Conclusion
According to Lubin, the incident did not affect user assets, and the precautionary key rotation aims to maintain the security and decentralization principles central to Consensys' services.


