Mkt Cap$2.29T+0.16%
24h Vol$57.72B
BTC Dom56.5%
ETH Dom9.8%
F&G29Fear
BTC$64,638.00+0.51% ETH$1,872.72+0.36% USDT$0.999-0.02% BNB$568.54+0.28% USDC$0.9998-0.01% XRP$1.10+0.52% SOL$76.70+1.05% TRX$0.3257-0.39% FIGR_HELOC$1.02+0.00% HYPE$61.28+0.87% DOGE$0.0725+0.33% USDS$0.9998+0.00% RAIN$0.0142-1.91% ZEC$536.42-3.34% LEO$9.68-1.18% WBT$56.34+0.41% BTC$64,638.00+0.51% ETH$1,872.72+0.36% USDT$0.999-0.02% BNB$568.54+0.28% USDC$0.9998-0.01% XRP$1.10+0.52% SOL$76.70+1.05% TRX$0.3257-0.39% FIGR_HELOC$1.02+0.00% HYPE$61.28+0.87% DOGE$0.0725+0.33% USDS$0.9998+0.00% RAIN$0.0142-1.91% ZEC$536.42-3.34% LEO$9.68-1.18% WBT$56.34+0.41%
ETH+0.36% Market Analysis

Consensys Confirms North Korean DPRK Contractor Accessed MetaMask Code for a Month

A North Korea-linked contractor accessed MetaMask code for roughly one month in 2026 via a third-party vendor. Consensys found no exploit or user impact.

Consensys have downplayed an incident in which a North Korean contractor infiltrated MetaMask and reportedly had access to key code
Editorial disclosureRead more

All reviews, research, news and assessments of any kind on The Tokenist are compiled using a strict editorial review process by our editorial team. Neither our writers nor our editors receive direct compensation of any kind to publish information on tokenist.com. Our company, Tokenist Media LLC, is community supported and may receive a small commission when you purchase products or services through links on our website. Click here for a full list of our partners and an in-depth explanation on how we get paid.

Consensys has disclosed that a North Korea-linked contractor operating under an alias had access to MetaMask-related code contributions from March 9 until access was terminated in April 2026, a window of roughly one month, after being introduced to Consensys through a third-party service provider with an existing relationship with the company.

Consensys general counsel Matt Corva described the individual as linked to North Korea and confirmed that an internal alert suspended all product releases and barred staff from interacting with the consultant pending a full investigation.

The investigation, Corva stated, found no misappropriation of assets or data, no malicious code deployed to production, and no impact to user safety or security.

Consensys notified law enforcement and provided all relevant information. The outcome means MetaMask users were not directly affected, but the one-month access window to the core wallet and mobile code remains the structural concern the disclosure leaves unresolved.

Access Window and Code Scope: What the Contractor Touched and What Consensys’s Investigation Covered

The contractor worked on MetaMask code from March 9 until Consensys cut off access in April 2026. The code contributions involved MetaMask-related code, but no other systems or codebases have been publicly identified as within scope.

Consensys’s statement confirmed that the company quickly identified the threat, followed established security protocols, and immediately terminated access before launching a comprehensive review.

The internal April alert that suspended product releases also demonstrates Consensys retained a predefined mechanism to halt changes while suspicious access was under investigation, a procedural detail relevant to any wallet or protocol team evaluating incident-response design.

Consensys has since reviewed its third-party service practices so that the vetting standards applied to direct employees now extend to more complex outside relationships.

DPRK IT Worker Infiltration Pattern: How the MetaMask Incident Fits a Documented Threat Category

The MetaMask case highlights a growing trend of North Korean IT workers infiltrating crypto development teams using false identities through remote contractors.

The FBI’s advisory PSA250123 warns that DPRK operatives exploit company access to copy code repositories, urging strict identity verification, limited access controls, and regular audits of staffing firms. DPRK actors rely on contractor channels due to inconsistent background checks.

The scale of DPRK’s crypto operations underscores why wallet infrastructure is a prime target, with TRM Labs estimating that the DPRK was involved in a considerable portion of crypto thefts in the past year.

An Ethereum-funded project identified suspected DPRK workers across various crypto projects, and U.S. authorities have prosecuted cases where DPRK operatives accessed nearly 70 American companies, generating over $1.2M for North Korea.

CryptoSlate reported that operational compromises, such as issues with keys and approval systems, accounted for about 76% of stolen crypto value in early 2026.

This gap illustrates the importance of access and identity controls over contract-level audits, as a contractor with access to a wallet used by 30 million addresses poses a significant risk.

Alias Construction and Contractor Vetting Failure: What ‘Tyler Knapp’ Reveals About Third-Party Access Risk

The contractor was introduced to Consensys via a reputable third-party relationship. Corva linked the individual to North Korea and noted their GitHub handle ‘imyugioh’.

This highlights a tactic used by DPRK IT workers: exploiting hiring pipelines rather than brute-force credential theft. MetaMask’s security guidance warns that malicious workers can impersonate identities and forge documents for remote roles, advising measures such as hardware authentication and reference checks.

The incident underscores the supply chain security gap created by third-party relationships. Consensys has not disclosed the vetting process for the contractor prior to March 9, nor whether the third-party provider conducted background checks.

EXPLORE: SpaceX Drops to $132.75 All-Time Low as Lockup Overhang and AI Repricing Weigh on SpaceX Stock

The author does not hold or have a position in any securities discussed in the article.

Tim Baker

Tim Baker

Author · Tokenist

Tim Baker is a Senior Market Analyst at Tokenist with over a decade of experience educating readers about traditional finance, crypto and DeFi. A former equity researcher turned on-chain analyst, Tim specializes in regulatory framework shifts and institutional DeFi adoption. His work focuses on distilling complex liquidity cycles and the macro environment into actionable intelligence for the modern DIY investor.

Related Stories