North Korean Developer Spent a Month Inside MetaMask's Code

iEXExchanger
North Korean Developer Spent a Month Inside MetaMask's Code

Consensys, the company behind MetaMask, unknowingly brought on a developer with alleged North Korean ties. For a month he worked on payment code — the exact layer where users' money moves through the wallet.

A developer with alleged ties to North Korea spent roughly a month with access to parts of MetaMask's code — the world's most widely used crypto wallet. Drop Site News broke the story, and Consensys, the company behind the wallet, has confirmed the outline.

The person went by the name Tyler Knapp and joined through a third-party contractor Consensys already worked with. He was brought on as a consultant rather than a direct hire, which meant lighter vetting than a standard employee would get, according to general counsel Matt Corva. The first commit under the GitHub handle imyugioh landed on March 9.

By April, Consensys' security team spotted something off and cut off access. In that window, "Knapp" had touched code tied to converting crypto into fiat through third-party payment providers — the exact layer where users' real money moves.

Consensys paused product releases, opened an internal investigation and looped in law enforcement. Its conclusion: no funds or user data were taken, and no malicious code was planted. That finding comes from the company's own review — there's no independent audit to check it against yet.

The pattern isn't new. US and UN officials have warned for years that Pyongyang funnels IT workers under fake identities into remote jobs at Western tech and crypto firms, both to earn hard currency for the regime and to get a foot inside internal systems. Similar cases have surfaced at exchanges and blockchain infrastructure companies before. Consensys isn't a small shop — MetaMask counts its users in the tens of millions, which is why a month of unnoticed access to payment code is unsettling even without an apparent loss this time.

The company says it's rethinking how it vets contractors. Whether that stops the next attempt is something no crypto firm can promise yet.

Questions and answers

Frequently asked questions about this article

What happened with MetaMask?

Consensys, the company behind the MetaMask wallet, unknowingly hired someone with alleged North Korean ties through a contractor. He had access to parts of the wallet's code for about a month before being detected and cut off.

Who is Tyler Knapp?

That's the name used by the developer with alleged North Korean ties who worked with Consensys. He operated under the GitHub handle imyugioh and was brought on as a consultant through a third-party contractor rather than as a direct employee.

Were MetaMask users' funds or data affected?

According to Consensys, the investigation found no missing user funds or data and no malicious code. That said, this is the result of the company's own internal review — no independent audit has been conducted yet.

Why does North Korea go after this kind of access?

US and UN officials have documented for years a scheme where North Korean IT workers use fake identities to land remote jobs at Western tech and crypto companies. It earns the regime hard currency despite sanctions and gives them a foothold inside internal systems, including code tied to users' money.

What will Consensys change about its hiring?

The company said it will review how it vets third-party contractors and consultants who get access to internal systems. It hasn't disclosed specific new rules yet, and no firm in the industry can guarantee this won't happen again.