Consensys Security Incident: No Indication of Unauthorized Access to Wallets or Funds
Consensys, the company behind MetaMask, has faced a security incident that affected part of its infrastructure. However, according to Joseph Lubin, Ethereum co-founder and Consensys founder, there is no indication that MetaMask wallets or customer funds were impacted.
Lubin explained that the company's investigation so far shows no signs of unauthorized access to users' recovery phrases or private keys. The incident was related to validator keys, which are separate from withdrawal keys.
As a precaution, Consensys and its partners rotated validator keys. This process is operationally inconvenient and requires validators to exit the staking queue and re-enter it to restake. However, Lubin emphasized that this step reduced residual operational risk and ensured the integrity of Ethereum's validator architecture.
Lubin reiterated the importance of self-custody in the Ethereum ecosystem, stating that Consensys does not hold withdrawal keys for its clients. This approach aligns with the Ethereum principle of self-custody and ensures that users maintain control over their assets.