
A North Korean operative accessed MetaMask's core code for a month before Consensys terminated him. The firm says no funds were stolen, but the breach raises questions about vendor screening.
Consensys, the blockchain firm behind the MetaMask crypto wallet, said it accidentally brought a North Korea-linked software developer onto its team. The developer worked on core wallet code for about a month before the company terminated access, internal Slack messages showed.
Consensys general counsel Matt Corva said the company discovered the threat quickly after the developer was hired. The firm followed its security protocols and cut off access immediately. A subsequent investigation found no misappropriation of assets or data, no malicious code pushed into production, and no impact on user safety, Corva said.
The developer worked under the alias “Tyler Knapp” and used the GitHub handle “imyugioh.” He was hired as a consultant through a third-party service provider with a long-standing relationship with Consensys. The company said the developer was not hired directly through its internal hiring pipeline, and the third-party agency may have been responsible for the breakdown in proper screening.
Internal Slack messages reviewed by the source show that Tyler Knapp worked on the core MetaMask platform code. He had access to the codebase that converts crypto to fiat currency via third-party payment providers and vice versa. He also contributed to MetaMask’s mobile wallet codebase on GitHub. Those contributions began on March 9 and stopped abruptly in April, the same month Consensys cut off his access.
In April, Corva sent a company-wide alert ordering all product releases suspended pending investigation and instructing staff not to interact with the individual. He also asked employees to keep the matter internal while the probe continued, a request that suggests Consensys was trying to control the narrative before the story became public this week.
North Korean operatives posing as remote software engineers have repeatedly landed real jobs at American companies. They achieve this with the help of US-based facilitators running laptop farms that make it appear the worker is logging in from within the country. One Arizona woman was sentenced last year for running such an operation, which prosecutors said generated more than $17 million for North Korea-linked entities. Earlier this year, two more American nationals were sentenced for facilitating similar schemes that the Department of Justice said touched close to 70 US companies.
Crypto firms are an especially attractive target because a developer’s ordinary access can extend beyond source code into transaction signing infrastructure, the layer where stolen funds actually move. Blockchain analytics firm TRM Labs has estimated that North Korea-linked actors were behind roughly two-thirds of all crypto stolen in hacks last year, a figure that includes the $1.5 billion Bybit theft widely attributed to Pyongyang.
Consensys said the incident is resolved. No further public disclosures are scheduled.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.