MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases
A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April. Consensys later described the person as linked to North Korea. Consensys said its inves...
Archive context
Published within the last day. A tracked entity is involved.
A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April. Consensys later described the person as linked to North Korea.
Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security. General counsel Matt Corva said the company identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement.
Drop Site reported that an internal April alert ordered all product releases suspended pending the investigation and told staff not to interact with the consultant. Corva called the service provider relationship reputable and said Consensys has since reviewed its third-party service practices, so the rigorous standards applied to employees also cover more complex outside relationships.
Related Reading Compromised developers lying dormant within crypto projects risks next major crypto exploit The bigger risk after Drift may be the access attackers gain before a protocol knows it has a problem. Apr 8, 2026 · Gino Matos Contractor checks need repository limitsThe incident gives no indication that user accounts or wallet assets were compromised. Consensys’ existing relationship with the vendor still left a gap: every contractor and account needed its own safeguards.
MetaMask's general security guidance warns that malicious workers can use false identities and forged documents to obtain remote roles. It recommends checks using actual documents, multiple interviews, hardware authentication, IP and location verification, reference checks, and limits on access to critical systems.
Related Reading Secret laptop footage exposes North Korean spies infiltrating US companies Researchers watched in real-time as the Famous Chollima division used this common remote work setup to bypass firewalls. Dec 3, 2025 · Oluwapelumi AdejumoThe FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories. Its guidance calls for identity verification during interviews, onboarding and throughout employment, routine audits of third-party staffing firms, least-privilege access and monitoring for unusual remote connections or repository exfiltration.
After onboarding, repository permissions and review become the core safeguards. UK National Cyber Security Center guidance recommends making repository activity attributable, reviewing every production-bound change, applying extra scrutiny to external contributions, and revoking access quickly when it is no longer required. Hardware-backed credentials can protect an account from credential theft, while tightly scoped permissions and independent review limit what an authorized account can change.
Related Reading The next big DeFi exploit will start before the code is deployed A new malware campaign targeting crypto developers shows how attackers can move upstream, stealing GitHub tokens, SSH keys, cloud credentials, wallets, and environment variables before a protocol ever ships vulnerable code. May 26, 2026 · Gino MatosCryptoSlate reported on July 5 that operational compromises around keys, custody, signing and approval systems accounted for roughly 76% of stolen value during the first half of 2026, even though smart-contract exploits were more frequent. That gap shows why access and operational controls matter even when they account for fewer incidents.
Wallet and protocol teams should treat contractor access as continuously conditional. Identity checks should extend through employment, third-party firms should be audited, repository privileges should remain narrow and observable, every production-bound change should receive independent review, and access should be revoked as soon as it is no longer required.
Consensys's April release pause also shows the value of retaining a predefined way to halt changes while suspicious access is investigated.
The post MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases appeared first on CryptoSlate.
Why this matters
MetaMask is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
ConsenSys inadvertently hired North Korean operative who accessed MetaMask’s core code
ConsenSys inadvertently hired a North Korean operative as a developer consultant who accessed MetaMask's core code before being de...
Trusted Volumes Hacker Returns 1,122 ETH, Keeps $2M Bounty
A hacker tied to the Trusted Volumes exploit has returned 1,122 ETH to the protocol, closing part of a security incident that bega...
Jamie Dimon warns Anthropic’s Mythos access debate signals AI risks for finance and crypto
Jamie Dimon warns Anthropic's Mythos AI model poses cybersecurity risks for finance and crypto, comparing broad access to giving b...
Bot traffic now outnumbers human traffic online, and crypto markets should pay attention
Cloudflare data shows bots now account for 57.4% of web traffic. Here's what that means for crypto markets, AI trading, and blockc...
Argentina Freezes 25 Crypto Accounts: Investigation of LIBRA Memecoin
Key Takeaways: Argentine authorities froze 25 crypto wallets linked to the LIBRA token and requested user data from major exchange...
AZ-COM Maruwa rolls out JPYC stablecoin for 2,300 subcontractors
AZ-COM Maruwa Holdings invests 1 billion in JPYC, Japan's first regulated yen stablecoin, to pay 2,300 subcontractors and delivery...