MetaMask hired suspected North Korean dev flagged months earlier
A North Korean dev and suspected mole who worked on MetaMask’s core wallet code for a whole month was reportedly flagged by a Lazarus Group security page almost a year ago. The developer was reportedly hired by MetaMask’...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
A North Korean dev and suspected mole who worked on MetaMask’s core wallet code for a whole month was reportedly flagged by a Lazarus Group security page almost a year ago.
The developer was reportedly hired by MetaMask’s parent firm, Consensys, as a consultant while posing under the alias “Tyler Knapp.” He reportedly made GitHub contributions to MetaMask’s wallet until he was ousted by the company in April.
However, DeFi security analyst Zun claims that Knapp had already been flagged on a public Lazarus Group operative tracking site back in September 2025.
The page, run by the Security Alliance, creates profiles for known remote Democratic People’s Republic of Korea (DPRK) IT workers in the hopes that it will help companies to identify them before they’re hired.
MetaMask’s North Korean developer is listed on the Lazarus Group site.Read more: Crypto has become Kim Jong-Un’s lifeline — and Russia’s secret weapon
On the Lazarus Group site, Knapp appears under the name “Mauro Liu.” He also appears to have worked for Web3 game firm MagicCraft in 2022, and DeFi product firm Napier Finance in 2023.
His other listed firms include Ankr, Pickle Finance, Harmoney, Gamerse, Clover Network, DEPO, Sifu Vision, Oxytocin, Tomodachi, and Blueberry.
He’s linked to MetaMask through the GitHub username “imyugioh.”
Zun claims MetaMask hired him as a developer without a “proper background check that would have caught him.”
Consensys says North Korea dev didn’t steal any assetsDropSite reports, based on internal Slack messages, that Knapp was also contributing to code involving the conversion of crypto and fiat currency by third-party payment firms.
Consensys’s General Counsel, Matt Corva, told DropSite, that Knapp “was introduced to us through an existing relationship with a reputable third-party service provider.”
They said, “Very quickly after being introduced, we discovered the threat, followed our security protocols, immediately terminated any access and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security.”
Last April, a North Korean mole called “Moo” was named by crypto sleuth ZachXBT and was fired from Solana-based DEX Stabble.
The firm subsequently encouraged all of its users to withdraw all their funds.
Moo, real name Keisuke Watanabe, was, by its own admission, employed by Stabble for a whole year.
Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.
The post MetaMask hired suspected North Korean dev flagged months earlier appeared first on Protos.
Why this matters
MetaMask is showing up inside the DeFi theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on ProtosRelated market context
Bitcoin Price Prediction: Is the BTC Correction Over as It Defies September’s Red Trend?
Bitcoin price is near $83,100, a stable 24-hour movement after retreating from $87,400, and with its prediction still leaning bull...
DeFi Development Corp Adds 47,706 SOL As Treasury Passes 2.5M Tokens
TL;DR DeFi Development Corp added approximately 47,706 SOL and SOL equivalents since September 21. Total holdings have reached rou...
Quantum Security Startup Project Eleven Acquires Riva Labs, Adding Post-Quantum Wallet Tech
Project Eleven, a startup preparing crypto networks for the arrival of powerful quantum computers, has acquired Riva Labs, a crypt...
Chainlink Launches CCIP 2.0 With Extra Security Controls For Tokenized Assets
TL;DR Chainlink has launched CCIP 2.0, a major upgrade to its Cross-Chain Interoperability Protocol. The new version adds optional...
BTCS Prepares DeFi Business To Provide Liquidity For Tokenized Stocks
TL;DR BTCS says its Imperium DeFi unit has completed preparatory compliance steps for potential use of the SEC’s Covered Firm exem...
Maryland cybersecurity consultant goes on trial for $55M crypto theft
The trial highlights the evolving legal landscape for DeFi security, emphasizing the potential for blockchain forensics in prosecu...