
A state-sponsored North Korean developer using a fake identity worked on MetaMask's fiat gateway for a month before detection. No funds or data were compromised.
A state-sponsored North Korean operative infiltrated MetaMask's development team for roughly four weeks earlier this year, Consensys said. The individual, using the alias Tyler Knapp, never became a direct employee. They entered through a third-party human resources provider that supplies contract workers, bypassing standard verification checks.
Consensys said no user funds were lost and no malicious code was deployed. The company also said no sensitive data was compromised. It revoked all system access immediately after detecting the threat through automated monitoring of anomalous network connections and suspicious operational behavior.
The operative's GitHub profile, imyugioh, shows code submissions from March 9 until April 2026. Their work focused on MetaMask's fiat currency gateway infrastructure, the component that lets users move between traditional money and digital assets. That is one of the most security-critical parts of the wallet.
Consensys general counsel Matt Corva told personnel via internal communication that the company discovered the threat and launched a comprehensive investigation. "We confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security," Corva said.
Law enforcement has been notified. Consensys is now overhauling its contractor screening protocols.
This incident fits a broader pattern. North Korean agents routinely pose as remote software developers to land jobs at cryptocurrency firms, then try to steal funds or install backdoors. A recent probe by an Ethereum-supported initiative found 100 suspected North Korean affiliates working across 53 crypto organizations.
Blockchain intelligence firm TRM Labs said obtaining developer credentials has become the primary method attackers use to access systems that control crypto transaction approvals. Federal investigators reported that North Korean cyber criminals stole $1.5 billion from the Bybit platform last year. TRM Labs documented that the country accounted for more than half of the $2.7 billion taken through crypto exploits in 2025.
MetaMask currently serves more than 30 million active monthly users, making it one of the most targeted wallets in the ecosystem. American citizens have been prosecuted for helping North Korean operatives pose as domestic workers.
Several crypto firms have started sharing threat intelligence to catch these operatives earlier in the hiring process. Consensys said it will strengthen verification for all contract workers.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.