
A consultant linked to North Korea accessed Consensys systems for a month, working on core MetaMask code. The company halted releases and is reviewing hiring controls. The incident mirrors a wider pattern of IT worker fraud across crypto.
NEWS CORP currently carries an Alpha Score of n/a, giving AlphaScala's model a neutral read on the setup.
Consensys has paused product releases after a consultant linked to North Korea gained access to its systems for roughly one month.
According to Drop Site News, the developer joined the Ethereum software firm under the alias “Tyler Knapp” with the GitHub handle “imyugioh.” Public GitHub records show the consultant began contributing code on March 9 before access was cut in April.
Internal messages obtained by Drop Site indicate Knapp worked on core MetaMask platform code, including sections that connect crypto users with third-party fiat payment providers. Consensys halted product releases while it investigated and told staff not to contact the consultant, the outlet reported.
Consensys general counsel Matt Corva told Drop Site that an established third-party service provider had introduced Knapp to the company. Corva stressed that Consensys treated him as a consultant, not a direct employee.
“Very quickly after being introduced, we discovered the threat, followed our security protocols, immediately terminated any access and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security,” Corva said.
The company disclosed no financial losses. Corva said Consensys would review how it outsources engineering work and has notified law enforcement, providing information about the incident.
Developer access opens a direct route to sensitive infrastructure. TRM Labs said developer environments have become one of the fastest ways for attackers to reach systems holding private keys or approving crypto withdrawals.
The Consensys case is not isolated. The Ketman Project, backed by the Ethereum Foundation’s ETH Rangers Program, identified roughly 100 suspected North Korean IT workers using fake identities across 53 crypto and Web3 projects, according to an April recap.
Ketman investigators traced at least three suspected groups across 11 code repositories. Those projects had merged 62 pull requests before spotting the activity. Some applicants used generated profile pictures, forged identity documents and false Japanese identities to pass screening, the project reported.
Pablo Sabbatella, founder of Opsek and a Security Alliance member, warned at Devconnect Buenos Aires last November that North Korean workers could be embedded in one-fifth of crypto companies. He estimated North Korean applicants account for 30% to 40% of job applications crypto firms receive.
Crypto companies face heightened risk because employees and contractors can access code, wallets and transaction systems. TRM Labs estimated that North Korean groups were behind 64% of crypto hack losses in 2025, when total theft exceeded $2.7 billion.
The biggest single loss came in February, when the FBI attributed the $1.5 billion Bybit hack to North Korea’s TraderTraitor group. TRM Labs said more than 30 exchanges and DeFi platforms now share rapid alerts through its Beacon Network when North Korean-linked funds land on participating platforms.
For Consensys, the consultant’s removal prevented any known user loss. The company has promised a broader review of third-party hiring controls. No date has been set for a public post-mortem.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.