Mozilla has removed the cryptographic key used for downloading Firefox and Thunderbird on Linux due to an accidental commit of it to one of their own private code repositories This article explores key removed revoked. . The action incurs costs for those checking their downloaded files; signatures using the old key no longer validate when users import a revocation list.
However, two groups require action. OpenPGP allows a key's owner to attach a machine-readable reason for revocation, and RFC 4880 explains why this matters: keys superseded or retired retain past signatures, while revoked due to compromise render every signature suspect.
ZeroOwl decoded the revocation certificate accompanying the new key and found reason code 2, "key material compromised," generated on August 6, 2026 at 11:14 UTC with the note "We no longer trust this key." Mozilla’s account of the incident does not explicitly state that the key was removed. The revoked subkey, identified by the hexadecimal sequence 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256, was set to expire in March 2027 but must have been activated until April 2025.
The release comes just one week after hackers exploited vulnerabilities by hijacking the GitHub account behind the keyv and cacheable npm packages, subsequently publishing a malicious worm designed to steal repository, registry, cloud, and private-key data from developer machines and CI pipelines.












