top of page

MetaMask's Owner Let a North Korea-Linked Dev Touch Its Core Code for a Month

  • Writer: Gator
    Gator
  • 2 days ago
  • 2 min read
MetaMask's Owner Let a North Korea-Linked Dev Touch Its Core Code for a Month

Consensys, the company behind the MetaMask wallet that millions of people use to move on-chain, discovered that a developer linked to North Korea had been contributing to its core code for about a month before anyone caught it. The firm has since halted product releases, pulled in law enforcement, and started tearing apart how it vets outside engineers.

What Happened

According to internal communications reported by Drop Site News, the contractor operated under the alias "Tyler Knapp" and the GitHub handle "imyugioh." He began contributing to MetaMask on March 9 and stayed inside company systems until April, when Consensys revoked his access. That's roughly a month with hands on the codebase of one of crypto's most widely used self-custody wallets.

Public GitHub records and internal messages indicate the developer worked on MetaMask platform code, including features that connect users with third-party fiat payment providers — the on-ramps where real money meets the wallet. Once the firm realized what it was looking at, it suspended releases, contacted authorities, and told staff to cut all contact with the consultant.

Why It Matters

North Korea's IT-worker operations have become one of the most persistent threats in crypto, funneling salaries and stolen funds back to the regime by slipping operatives into remote engineering roles. When the target is a wallet that guards user keys and payment flows, even a month of quiet access is the kind of thing that keeps security teams up at night. Consensys says its internal review found no compromised assets or data, no malicious code deployed, and no user impact. That's the good news — but the exposure window alone underscores how thin the line can be.

What's Next

General Counsel Matt Corva said the developer was introduced through an existing relationship with what the firm considered a reputable third-party service provider — the loophole that let him through. Consensys says it's now applying the same vetting standards it uses for direct employees across its more complex contractor relationships. Expect the wider industry to take the hint: the weakest link in crypto security increasingly isn't the smart contract, it's the hiring pipeline.

☕₿

Comments


Subscribe to Our Newsletter

  • White Facebook Icon

© 2024 by Caffeine & Crypto. Powered and secured by Wix

bottom of page