Consensys infrastructure security incident contained; MetaMask wallets and customer funds unaffected, validator keys rotated as precaution.
Security & Exploits ·
Consensys experienced a security incident affecting part of its infrastructure, according to founder Joseph Lubin. Investigations indicate no compromise of MetaMask wallets or customer funds, and users' recovery phrases and private keys were not involved in the breach.
The incident's scope was limited by the architectural separation of validator and withdrawal keys. Lubin noted that his team does not hold clients' withdrawal keys, which prevented any unauthorized transfers of staked ETH. As a precautionary measure, validator keys were rotated by his team and partners.
The full scope of the infrastructure compromise and the specific attack vector remain unspecified. Lubin's statement covers only what investigations have shown so far, leaving open whether additional details about the incident's origin or affected systems will be disclosed.