Friday, August 7, 2026 Today's news About Live prices →
£ PoundToken
Crypto, covered properly · Est. 2026
Regulation

Consensys halts MetaMask releases after North Korea-linked coder joins team

A DPRK-linked developer using a false identity worked on MetaMask's core code for a month, exposing hiring risks across crypto firms.

By Rajesh Patel · ·3 min read
Consensys halts MetaMask releases after North Korea-linked coder joins team

Consensys, the software firm behind the MetaMask crypto wallet, has confirmed that it unknowingly hired a developer linked to North Korea, who gained access to core wallet code for roughly a month before being detected and cut off. The disclosure has forced the company to suspend product releases while it investigates, and adds fresh weight to warnings from Western regulators about state-sponsored infiltration of the crypto industry’s workforce.

According to internal Slack messages reviewed by Drop Site News and corroborated across multiple outlets, the individual operated under the alias “Tyler Knapp” and used the GitHub handle “imyugioh.” The consultant began contributing to MetaMask’s codebase on 9 March and remained inside Consensys’s systems until access was terminated in April, a period of roughly one month.

Access to core wallet features

Internal records and public GitHub history indicate the developer worked on platform code within MetaMask, including features that connect users to third-party fiat payment providers — a sensitive area given the wallet’s role as one of the world’s most widely used gateways between conventional currency and crypto assets. Consensys General Counsel Matt Corva said the individual had been introduced through an existing relationship with a third-party service provider that the firm regarded as reputable.

Corva said the company detected the threat, removed the individual’s system access and opened an internal investigation once suspicions were raised. Consensys has stated that it found no evidence that user funds or data were taken, that malicious code was deployed, or that wallet security was compromised. The firm said it has notified law enforcement and shared information relevant to the case.

Releases frozen, staff told to stay silent

Internal communications show Corva ordered an immediate suspension of all product releases while the investigation was under way. Employees were instructed not to communicate with the individual and to keep the inquiry confidential, underlining how seriously the firm treated the potential exposure of core wallet infrastructure to an unvetted, state-linked actor.

Consensys is one of the most significant infrastructure providers in the Ethereum ecosystem, and MetaMask remains a dominant retail and institutional wallet across the UK and Europe. Even a contained breach of trust in its development pipeline carries reputational stakes that extend well beyond a single incident, particularly as banks, exchanges and fintechs increasingly rely on third-party wallet infrastructure to serve retail clients.

Part of a wider infiltration pattern

The episode fits a pattern that US authorities, including the FBI and Treasury’s Office of Foreign Assets Control, have flagged repeatedly: North Korean operatives posing as freelance developers or contractors to secure remote positions at technology and crypto firms, often through intermediaries or staffing arrangements that obscure their true identity and location. Such schemes have historically served both as a source of hard-currency income for Pyongyang under international sanctions and, in some cases, as a foothold for deeper compromise of crypto infrastructure, an asset class North Korea-linked groups such as Lazarus have targeted for large-scale theft in the past.

For European regulators pursuing tighter oversight of crypto-asset service providers under frameworks such as MiCA, the case underscores a governance gap that sits outside conventional financial-conduct rules: the vetting of software contributors with privileged access to code underpinning wallets and payment rails used by millions of retail customers. No sanctions body or supervisory authority is known to have commented publicly on this specific incident.

Read more: Taiwan jails BitShine founder for 22 years over $75m stablecoin laundering scheme

Sources

More Regulation