Joseph Lubin, Ethereum co-founder and founder of Consensys, has moved to reassure MetaMask users after a security incident affecting part of the company’s infrastructure came to light. In statements published on October 3, 2026, Lubin said investigators had found no evidence that MetaMask wallets, user funds, Secret Recovery Phrases, or private keys were affected.
The incident was first disclosed on September 30, when MetaMask said part of its infrastructure had been impacted. The company had already temporarily shut down some Ethereum staking machines operated on behalf of clients, while saying at the time there was no immediate threat to customer wallets. Lubin explained that MetaMask limits public commentary during open investigations, but notifies core partners and relevant stakeholders after a diagnosis is complete.
“Your Secret Recovery Phrase, your keys, and the assets in your wallet were not part of this incident because they CANNOT be. You custody and control your own keys. That is how self custody works,” Lubin said on X.
Consensys and its partners rotated validator keys as a precaution. The downside is that validators must exit the staking queue and rejoin to resume staking, a process that can be time-consuming. Lido, the staking protocol, noted that MetaMask-operated validators have begun leaving the system and the remaining validators are expected to stop staking by October 7. Withdrawing the staked ETH could take about 45 days, while clearing the subsequent Ethereum entry queue could leave assets dormant for an extended period, missing standard yields and risking penalties if validators are knocked offline.
Lubin also stressed that Ethereum’s staking architecture separates verification keys from withdrawal keys, and Consensys does not hold customer withdrawal keys. The security incident therefore could not lead to unauthorized transfer of staked ETH to another address.
The infrastructure breach follows another security issue disclosed earlier in 2026. In July 2026, Consensys revealed that a North Korea-linked software developer had worked within the MetaMask team for about a month using the alias “Tyler Knapp.” The operative integrated code into wallet features handling cash-to-crypto bridging before backend access was severed. Consensys general counsel Matt Corva said an investigation confirmed no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security.
MetaMask has warned users to watch for phishing attempts following the incident and to never share Secret Recovery Phrases or private keys with anyone claiming to offer support.