Firefox revokes its exposed GPG key

Article by Nacata Security, 14/08/2026

Did you know that Firefox signs every download with a secret key to guarantee it is legitimate?

That key was accidentally exposed in a GitHub repository.

An unencrypted copy of Mozilla’s private GPG key appeared by mistake on GitHub. The repository was private, but the risk of a supply chain attack was too serious to ignore.

If someone had obtained that key before Mozilla acted, they could have signed malicious versions of Firefox or Thunderbird that would have appeared completely authentic to any user.

Image illustrating the mechanics of the incident: a GPG key accidentally exposed in a repository, represented as a digital key disintegrating upon being uncovered.
Exposed GPG key

A lost key can turn something secure into something dangerous.

The exposed GPG key signed Firefox and Thunderbird artifacts: Linux tarballs, RPM packages, and integrity verification files. That signature guarantees that what you download is exactly what Mozilla published. If an attacker had obtained the key, they could have distributed modified files through a compromised mirror or via social engineering, without anyone detecting anything out of the ordinary.

The repository was private, but that was not enough.

Mozilla reviewed the audit logs and found no evidence of unauthorized access. Only a small group of developers had access, and all of them already had the key through other means. Even so, Mozilla immediately revoked the compromised key and issued a new one without waiting to confirm an actual incident. In addition, it has implemented additional protections to prevent this from happening again.

Most users do not need to do anything, but there are important exceptions.

Image illustrating the pattern of supply chain attacks: a software distribution chain with a compromised link on the verge of breaking, representing the fragility of trust in digital signing.
Compromised link

This case is not an anomaly: it is a trend.

Organizations rotate signing keys at any sign of exposure because supply chain attacks have skyrocketed and the cost of inaction is devastating.

A single compromised key can contaminate millions of seemingly legitimate downloads without anyone detecting it.

The ChainDrop attack infected more than 400 NPM packages, demonstrating the real scale that supply chain attacks can reach.

Acting before the damage occurs is the new standard.

Mozilla has demonstrated that the response to a possible exposure does not wait for damage to be confirmed. Revoke, reissue, and protect: that is the protocol. And if you use Firefox with RPM packages or verify GPG signatures manually, there are specific steps you need to follow.

Supply chain attacks redefine what it means to trust.

When an attacker compromises the distribution chain, they do not need to breach your system directly: it is enough to infect the source. A package signed with a legitimate but stolen key would pass all standard checks. The Mozilla case is striking because the damage never materialized, but the infrastructure for it to occur was within reach of anyone who knew where to look.

Image illustrating a deeper look at supply chain attacks and trust in digital signing: a cracked trust certificate being carefully repaired, symbolizing the responsible response to an exposure.
Trust under repair

Trust in digital signing is the most fragile link.

When you verify the integrity of a download, you trust that the key that signed it has not been compromised. If it falls into the wrong hands, the entire chain of trust breaks. The file will appear clean because it will be signed with a valid key.

What you need to do right now is concrete.

If you use Firefox or Thunderbird on Linux with RPM packages, consult the instructions Mozilla has published to update your key configuration. If you verify GPG signatures manually, import the new key and the revocation of the old one. All other users can rest easy: Mozilla has managed the transition transparently.

Mozilla’s transparency sets the standard.

In an ecosystem where supply chain attacks grow every month, disclosing an exposure before there are any victims is exactly what is expected of a responsible organization.

What to do now

  • Import Mozilla’s new GPG key if you verify signatures manually.
  • Follow the official instructions if you use Firefox RPM packages.
  • Revoke the old key on your system to avoid future confusion.

How many signing keys from your trusted software could be exposed?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Tools

New versions and features of tools used in offensive and defensive cybersecurity: scanners, exploitation frameworks, auditing software.

For those who want to stay up to date on which tools to use and what has improved.



RATING


8.9



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.