Particle.news
Download on the App Store

North Korea‑Linked Contractor Worked Inside MetaMask for a Month

Consensys halted releases to investigate gaps in contractor vetting after finding a North Korea‑linked developer in MetaMask.

Overview

  • A contractor using the alias “Tyler Knapp” and GitHub handle imyugioh began contributing to MetaMask on March 9 and kept development access until Consensys revoked credentials in April 2026.
  • Consensys flagged unusual IP addresses and behavioral signals, immediately terminated the contractor’s access, suspended related product releases, notified law enforcement, and opened an internal investigation.
  • The contractor worked on MetaMask’s fiat on‑ and off‑ramp code, the component that moves money between traditional currencies and crypto and is therefore highly security sensitive.
  • Consensys’s review so far found no stolen funds, no malicious code pushed to production, and no impact to user security, and the company says it will strengthen third‑party vetting and repository access controls.
  • Security firms say the case fits a wider North Korean tactic of posing as remote developers to gain repository and signing access, a threat linked to major 2025 losses such as the FBI‑attributed $1.5 billion Bybit theft and to calls for tighter identity checks and least‑privilege controls across the industry.