Firefox and Thunderbird Switch to New GPG Signing Key After Key Leak

Updated GPG Key for Signing Firefox and Thunderbird Releases

Mozilla has rotated the GPG signing key used for Firefox and Thunderbird artifacts after an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository. An audit found no evidence of unauthorized access, but the old key has been revoked. Most users need no action, but those who manually verify signatures or use RPM packages on certain distributions must update their keyring. The new key's fingerprint is 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3.

Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository.

More from this day

2026-08-11