🔥BTC/USDT

North Korean hacker accesses MetaMask codebase temporarily

Consensys, the company behind MetaMask, confirmed that an external consultant later identified as a North Korean hacker gained temporary access to MetaMask’s core codebase in March 2026, exposing another serious weakness in the digital-asset industry’s hiring and software supply chain controls.

The company said no user assets or personal data were affected. It also said all MetaMask product updates were paused while its security team reviewed the incident, revoked the contractor’s access, and checked whether any malicious code had been introduced into the wallet’s systems.

Internal company records show the contractor was hired through a third-party human resources provider under the false identity “Tyler Knapp.” The person worked on MetaMask’s fiat on-ramp and off-ramp features, which help users move between traditional money and digital assets. The access lasted for about one month before Consensys detected the activity and removed the consultant from its systems.

According to internal messages, Consensys security staff concluded that “Knapp” matched profiles linked to a North Korean entity. After that assessment, the company revoked all system permissions and notified law enforcement. Consensys has not publicly explained how it verified the person’s real identity, though internal records indicate the discovery came through internal monitoring.

The episode adds to mounting concerns that state-backed hacking groups are moving beyond direct attacks on wallets, bridges, and platforms. Instead, they are increasingly attempting to enter companies through hiring pipelines, contractor networks, and software development workflows.

Consensys says no user funds were affected

Consensys said its review found no impact on MetaMask users’ funds or data. That statement is central to the company’s response, because MetaMask is one of the most widely used self-custody wallets in the digital-asset market.

The company’s decision to pause product updates during the review suggests the incident was treated as a possible software supply chain risk. In such attacks, the danger is not always immediate theft. A contractor with access to internal systems may attempt to insert hidden code into a future update, create a backdoor, collect internal credentials, or map a company’s infrastructure for a later attack.

MetaMask’s role in the broader cryptocurrency ecosystem makes any codebase access sensitive. The wallet is commonly used to connect to decentralized finance platforms, NFT marketplaces, token applications, and blockchain networks. Even limited access to development systems can raise concerns if it is not quickly contained.

Consensys has said that the consultant’s permissions were revoked after the discovery. The company also notified law enforcement, a step often taken when a suspected state-linked actor is involved. It remains unclear whether any government agency has opened a formal public case connected to the incident.

False identity used in contractor hiring process

The contractor entered Consensys through an external partner that already had an agreement with the company. Internal records show the person used the name “Tyler Knapp” while working on MetaMask.

The compromised hiring process is now a key focus of the internal response. Corva, Consensys’ general counsel, ordered an immediate audit of all external engagements after the incident, according to company records. The review also required contractors to face the same vetting standards as internal employees.

That change reflects a wider problem across technology companies. Remote software work, global contractor hiring, and fast product cycles have made it easier for skilled developers to work across borders. Those same conditions have also created openings for false identities, manipulated employment histories, and outsourced interview processes.

In the blockchain sector, the risk is especially high. A developer may not need direct access to customer funds to cause serious damage. Access to code repositories, deployment tools, internal chat systems, test environments, or documentation can provide a path toward a future compromise.

Human resources providers and staffing partners are increasingly part of the security perimeter. If a third party fails to properly verify a contractor, the hiring company may inherit the risk. The Consensys case shows how deeply that risk can reach when an outside worker is placed on a core product.

GitHub handle had prior public links to Lazarus Group

Public research shows that the hacker’s GitHub handle, “imyugioh,” had been listed in 2025 under the Lazarus Group, a North Korean hacking collective accused by governments and cybersecurity researchers of major cyber intrusions.

Lazarus Group has long been associated with attacks on financial infrastructure, cryptocurrency platforms, and software companies. The group is widely described by security researchers as one of the most active state-linked cyber units targeting digital assets.

The connection between the GitHub handle and Lazarus-linked research has drawn attention because software development activity often leaves a long trail across public platforms. GitHub profiles, code contributions, commits, and reused aliases can help security teams identify patterns. At the same time, attribution remains difficult because hackers can borrow names, reuse tools, or plant misleading signals.

Consensys has not disclosed the full process used to identify the contractor. Internal messages only confirm that internal monitoring led to the discovery. That leaves unanswered questions about whether the company identified suspicious code behavior, account activity, login patterns, identity inconsistencies, or external intelligence linking the contractor to a known threat profile.

Prior warnings about recruitment infiltration

Monahan, who leads MetaMask’s security operations, has previously warned about recruitment-based infiltration attempts by North Korean-linked actors in decentralized finance. Her earlier warnings referred to attempts involving platforms such as SushiSwap, THORChain, and others.

She did not issue a public statement following this specific incident, according to the available record. However, her prior comments have described social engineering as a common entry point for attacks. In many cases, the target is not a firewall or a smart contract but a person, a recruiter, a hiring manager, or a developer with access.

Recruitment infiltration can take several forms. A threat actor may apply for a job using stolen or synthetic identity documents. They may use a real person as a front while a different person performs the work. They may pass technical interviews with outside help. They may accept lower pay or flexible contract terms to gain access quickly. Once inside, they may behave like any other contributor until they find a useful opening.

This strategy is difficult to stop because it does not always look like an attack at first. A contractor may log in during normal work hours, submit working code, attend meetings, and communicate professionally. Suspicious behavior may only appear later through unusual access requests, inconsistent identity details, abnormal login locations, or attempts to reach systems unrelated to assigned tasks.

Employment-based attacks have caused major losses

Cybersecurity specialists have increasingly warned that employment-based infiltration can lead to some of the largest losses in digital-asset history. The Consensys incident did not result in reported user losses, but it fits a pattern that has already caused significant damage elsewhere.

Documented cases include the 2026 Drift Protocol theft of about $285 million, the 2024 DMM platform breach valued at $308 million, and the 2022 Ronin Network exploit that caused losses of roughly $620 million. These incidents have been cited as examples of how human access, compromised credentials, and operational weaknesses can be just as dangerous as flawed code.

The Ronin exploit remains one of the best-known examples. It showed how attackers could compromise validator access and drain large amounts of digital assets in a short period. Other platform breaches have shown how trusted access points can become the weakest link, especially when systems rely on small groups of people or underprotected internal tools.

For traders, the lesson is clear: a platform can pass code audits and still remain exposed if its hiring, vendor, and access-control systems are weak. Smart contracts may be reviewed line by line, but a malicious insider or compromised contractor can still target deployment systems, administrative controls, signing keys, or future software updates.

The threat is moving inside the software pipeline

The Consensys incident highlights a broader shift in attack methods. Instead of only trying to break through external defenses, attackers are trying to enter the software pipeline itself.

This is more dangerous than many basic phishing attempts because it can place malicious code closer to trusted products. If hidden code is inserted into an ordinary update, users may install it without suspicion. The update may come from the official application, use the correct branding, and appear no different from any routine release.

Security teams call this a supply chain risk. In traditional terms, a company is not only responsible for its own systems but also for the outside services, contractors, tools, and libraries that feed into its products. In digital assets, that supply chain includes open-source code, wallet software, browser extensions, mobile apps, cloud services, node providers, bridges, and human contributors.

Naftali, a system security expert, recently noted that many company leaders remain unprepared to handle insider-style attacks without major delays. That warning reflects a growing reality: when a suspected malicious developer is discovered, a company must review code, freeze releases, check logs, rotate credentials, audit permissions, and determine whether any update has been compromised. Those steps can slow development and disrupt users, even when no funds are lost.

State-backed groups dominate platform losses

A July 2026 data report showed that state-backed groups stole $643 million between January and June of this year. That accounted for more than two-thirds of the $972 million lost to platform attacks globally during the six-month period.

Those figures show that the threat is no longer limited to isolated criminal groups looking for quick profits. State-backed cyber units can operate patiently, use long-term planning, and combine technical skill with social engineering. They may spend weeks or months building a false identity before attempting to access a target.

For digital-asset companies, this creates a difficult balance. The industry moves quickly and relies heavily on remote talent. Many projects hire contributors from around the world. Open-source development is often viewed as a strength. But speed and openness can become weaknesses if companies do not apply strict identity checks and access limits.

Outer defenses such as firewalls, password rules, and basic malware scans are no longer enough. Companies must assume that attackers may already be trying to enter through employment systems, vendor agreements, support tools, and collaboration platforms.

Stronger identity checks become a business necessity

The Consensys response points to one of the most important changes now spreading across the sector: contractors are being treated more like full employees for security purposes.

That means stronger identity verification, deeper background reviews, device controls, access logging, and limits on what outside workers can see or modify. It also means companies must monitor behavior after hiring, not only at the start of a contract.

A practical security model requires workers to receive only the access needed for their role. Access should expire automatically when a project ends. Sensitive code changes should require review from trusted internal staff. Releases should be signed, tested, and monitored before reaching users. Unusual login behavior should trigger alerts.

Vendor management is also becoming more important. When a company uses an outside hiring partner, that partner’s screening process becomes part of the company’s own security. If the vendor’s checks are weak, the final product may be exposed.

What traders can do now

The main responsibility for preventing these attacks rests with companies that build and maintain digital-asset products. Still, traders can reduce personal risk by changing how they store funds and manage software updates.

Large digital-asset balances should not be kept in live wallets connected to the internet unless they are needed for active use. Hardware wallets and offline storage can reduce exposure if a browser extension, mobile app, or platform interface is later compromised.

Traders should also be careful with software updates. Waiting a short period before installing a non-urgent update can give independent security researchers time to review new releases and flag suspicious behavior. This does not mean ignoring critical security patches, but it does mean avoiding unnecessary speed when an update is not urgent.

App permissions also deserve regular review. Many users connect wallets to third-party tools and then forget about those approvals. Removing access for services that are no longer used can reduce the damage if one of those tools is compromised.

Spreading funds across different storage methods can also limit losses from a single failure. No setup is risk-free, but concentration creates obvious danger. If all assets depend on one wallet, one device, one platform, or one set of approvals, a single breach can become catastrophic.

A warning for the wider digital-asset sector

The temporary access to MetaMask’s codebase appears to have been contained before causing reported user losses. Even so, the incident is significant because it shows how close a suspected state-linked actor came to one of the most important wallet products in the market.

The case also shows that digital-asset security is no longer only about audited smart contracts or strong encryption. It is about hiring systems, contractor oversight, vendor controls, internal monitoring, and release management.

As remote work and outsourcing continue to expand, identity verification may become one of the most expensive and complex parts of digital risk control. The companies that fail to adapt may find that attackers no longer need to break through the front door. They can apply for access, get hired, and wait.


Worried about human-focused crypto attacks like MetaMask’s breach? Strengthen your defenses with this crypto security breaches guide today.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up