BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Consensys Confirms North Korean DPRK Contractor Accessed MetaMask Code for a Month

Consensys has disclosed that a North Korea-linked contractor operating under an alias had access to MetaMask-related code contributions from March 9 until access was terminated in April 2026,

AnonymousCryptoCompass newsroom
July 20, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Consensys has disclosed that a North Korea-linked contractor operating under an alias had access to MetaMask-related code contributions from March 9 until access was terminated in April 2026, a window of roughly one month, after being introduced to Consensys through a third-party service provider with an existing relationship with the company.

Consensys general counsel Matt Corva described the individual as linked to North Korea and confirmed that an internal alert suspended all product releases and barred staff from interacting with the consultant pending a full investigation.

The investigation, Corva stated, found no misappropriation of assets or data, no malicious code deployed to production, and no impact to user safety or security.

Consensys notified law enforcement and provided all relevant information. The outcome means MetaMask users were not directly affected, but the one-month access window to the core wallet and mobile code remains the structural concern the disclosure leaves unresolved.

Access Window and Code Scope: What the Contractor Touched and What Consensys’s Investigation Covered

The contractor worked on MetaMask code from March 9 until Consensys cut off access in April 2026. The code contributions involved MetaMask-related code, but no other systems or codebases have been publicly identified as within scope.

Consensys’s statement confirmed that the company quickly identified the threat, followed established security protocols, and immediately terminated access before launching a comprehensive review.

The internal April alert that suspended product releases also demonstrates Consensys retained a predefined mechanism to halt changes while suspicious access was under investigation, a procedural detail relevant to any wallet or protocol team evaluating incident-response design.

Consensys has since reviewed its third-party service practices so that the vetting standards applied to direct employees now extend to more complex outside relationships.

DPRK IT Worker Infiltration Pattern: How the MetaMask Incident Fits a Documented Threat Category

The MetaMask case highlights a growing trend of North Korean IT workers infiltrating crypto development teams using false identities through remote contractors.

The FBI’s advisory PSA250123 warns that DPRK operatives exploit company access to copy code repositories, urging strict identity verification, limited access controls, and regular audits of staffing firms. DPRK actors rely on contractor channels due to inconsistent background checks.

The scale of DPRK’s crypto operations underscores why wallet infrastructure is a prime target, with TRM Labs estimating that the DPRK was involved in a considerable portion of crypto thefts in the past year.

An Ethereum-funded project identified suspected DPRK workers across various crypto projects, and U.S. authorities have prosecuted cases where DPRK operatives accessed nearly 70 American companies, generating over $1.2M for North Korea.

CryptoSlate reported that operational compromises, such as issues with keys and approval systems, accounted for about 76% of stolen crypto value in early 2026.

This gap illustrates the importance of access and identity controls over contract-level audits, as a contractor with access to a wallet used by 30 million addresses poses a significant risk.

Alias Construction and Contractor Vetting Failure: What ‘Tyler Knapp’ Reveals About Third-Party Access Risk

The contractor was introduced to Consensys via a reputable third-party relationship. Corva linked the individual to North Korea and noted their GitHub handle ‘imyugioh’.

This highlights a tactic used by DPRK IT workers: exploiting hiring pipelines rather than brute-force credential theft. MetaMask’s security guidance warns that malicious workers can impersonate identities and forge documents for remote roles, advising measures such as hardware authentication and reference checks.

The incident underscores the supply chain security gap created by third-party relationships. Consensys has not disclosed the vetting process for the contractor prior to March 9, nor whether the third-party provider conducted background checks.

EXPLORE: SpaceX Drops to $132.75 All-Time Low as Lockup Overhang and AI Repricing Weigh on SpaceX Stock

The author does not hold or have a position in any securities discussed in the article.

The post Consensys Confirms North Korean DPRK Contractor Accessed MetaMask Code for a Month appeared first on Tokenist.