Skip to content
Ethereum

Lubin Says MetaMask Funds Unaffected by Incident

Large purple Ethereum emblem above a connected network in a futuristic city.

Ethereum co-founder and Consensys founder Joseph Lubin said an investigation into a security incident affecting part of the company’s infrastructure had found no indication that MetaMask wallets or customer funds were affected. The account, published by Wu Blockchain, also said users’ recovery phrases and private keys were not involved.

The statement draws a boundary between the infrastructure affected by the incident and the credentials that control MetaMask wallets. That distinction is central to the update: the investigation had not identified an impact on wallets or customer funds, while the sensitive recovery phrases and private keys used by customers were outside the incident described. The development joins other Ethereum security coverage, including the Aave v3 Loop Safe Module exploit report, though the events are separate.

Validator keys were rotated as a precaution

Lubin said his team and its partners rotated validator keys as a precaution. The source does not characterize that action as evidence that customer assets had been accessed. Instead, it presents the rotation as a protective response taken while the investigation continued. That framing matters because the reported precaution and the reported findings are different: keys were rotated, but investigators had found no indication of an effect on MetaMask wallets or customer funds. A separate security incident report concerning Bitget offers broader context on how crypto organizations communicate which systems were and were not affected.

Validator and withdrawal keys have separate roles

Lubin also emphasized that validator keys and withdrawal keys are separate. According to the source, his team does not hold clients’ withdrawal keys. He said that separation prevented the incident from causing unauthorized transfers of staked ETH. The explanation addresses the custody boundary relevant to the incident rather than making a broader claim about every component of the affected infrastructure. For additional Ethereum context beyond this incident, BTC-Pulse has covered Vitalik Buterin’s view of Ethereum as a cryptographic world computer.

What the available update establishes

The available report establishes three points: part of the company’s infrastructure was affected, the investigation had found no indication that MetaMask wallets or customer funds were affected, and validator keys were rotated as a precaution. It additionally says recovery phrases and private keys were not involved. The separation between validator and withdrawal keys, together with the team not holding client withdrawal keys, is the stated reason unauthorized transfers of staked ETH did not result from the incident.

The wording remains tied to the investigation’s findings at the time of Lubin’s statement. It does not say that no infrastructure was affected; it says the identified incident did not show an effect on MetaMask wallets or customer funds. That distinction keeps the update focused on what investigators had established and on the safeguards described in the source.

BTC-Pulse

Related stories

More coverage from this topic.