
A suspected North Korean operative worked inside MetaMask's core wallet code for a month under a fake alias. The developer was flagged on a public database in September 2025 but kept committing code until April.
A suspected North Korean operative worked inside MetaMask's core wallet code for roughly a month before getting caught. The developer, hired under the alias "Tyler Knapp," made real contributions to MetaMask's GitHub repository until April, when he was finally ousted after being flagged as a security threat.
Consensys, the parent company behind MetaMask, said Knapp was brought in through a reputable third-party service provider. Someone vouched for him. And yet security analyst Zun said the alias had already appeared on a public database tracking North Korean IT workers back in September 2025. Months passed. The developer kept committing code.
The database, run by the Security Alliance, exists to help crypto and tech companies avoid hiring operatives linked to the Democratic People's Republic of Korea. Knapp was listed there not just as "Tyler Knapp" but also under the name "Mauro Liu." Both names tied back to the same person, the same threat, Zun said.
The GitHub username "imyugioh" connected the developer directly to MetaMask's codebase. MetaMask was not his only stop. The Security Alliance's tracking site linked him to MagicCraft, a Web3 gaming company, back in 2022. Then Napier Finance, a DeFi product firm, in 2023. His name also appeared alongside Ankr, Pickle Finance, and Clover Network. That is a wide footprint for someone operating under a fake identity. It looks deliberate – a slow crawl through different corners of the crypto industry, picking up access and income along the way.
Zun was blunt. He criticized MetaMask and Consensys for not running a thorough background check, saying basic vetting could have stopped the hire before it started. The developer's involvement in converting cryptocurrencies and fiat currencies for third-party payment firms added another layer of concern, he said. That kind of financial access, in the wrong hands, can expose sensitive operations fast.
Consensys pushed back on the severity, at least in terms of damage. After terminating Knapp's access, the company ran an internal investigation. Their conclusion: no assets stolen, no malicious code deployed, no user data compromised. MetaMask's systems, they said, stayed clean. Whether you take that at face value depends on how much you trust internal investigations to catch everything.
Knapp's case is not isolated. Before him, another suspected North Korean operative surfaced in the space – someone identified first as "Moo" and later revealed as Keisuke Watanabe. That person worked at a Solana-based decentralized exchange before getting fired. Two cases, two different projects, two different fake identities. The method is the same each time: build a plausible work history, get introduced through a trusted channel, contribute enough to seem legitimate, and stay quiet.
The crypto industry runs heavily on remote work and pseudonymous contributors. That is baked into its culture – open-source development, GitHub handles, no passport scan before merging a pull request. The structure works well for decentralization. It works just as well for someone trying to slip in undetected.
The Security Alliance's database can only do so much if companies are not actively checking it before every hire. Knapp was flagged in September 2025. He kept working until April. That gap is worth examining.
Once the identification came through, Consensys moved fast. Access terminated, investigation launched, results published. The company leaned on the fact that its security protocols held – no malicious code made it into production, no user funds were touched. For a wallet handling billions in assets across millions of users, that is the outcome that matters most. The fact that someone got in at all, someone already flagged on a public list, is the part that is hard to spin away.
Zun's criticism did not soften after the investigation results came out. The analyst's position is straightforward: if the database exists and the name is on it, you check before you hire. Full stop.
The broader industry is likely to feel this one. North Korean operatives using fake identities to infiltrate crypto projects is not new. It has been a documented concern for years, tied to state-level efforts to generate hard currency through illicit means. Each new case adds pressure on companies to tighten hiring pipelines, especially for roles touching core infrastructure like wallet code.
Consensys said the developer was introduced through a reputable third-party service. That service has not been named publicly.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.