A developer with alleged ties to North Korea spent roughly a month with access to parts of MetaMask's code — the world's most widely used crypto wallet. Drop Site News broke the story, and Consensys, the company behind the wallet, has confirmed the outline.
The person went by the name Tyler Knapp and joined through a third-party contractor Consensys already worked with. He was brought on as a consultant rather than a direct hire, which meant lighter vetting than a standard employee would get, according to general counsel Matt Corva. The first commit under the GitHub handle imyugioh landed on March 9.
By April, Consensys' security team spotted something off and cut off access. In that window, "Knapp" had touched code tied to converting crypto into fiat through third-party payment providers — the exact layer where users' real money moves.
Consensys paused product releases, opened an internal investigation and looped in law enforcement. Its conclusion: no funds or user data were taken, and no malicious code was planted. That finding comes from the company's own review — there's no independent audit to check it against yet.
The pattern isn't new. US and UN officials have warned for years that Pyongyang funnels IT workers under fake identities into remote jobs at Western tech and crypto firms, both to earn hard currency for the regime and to get a foot inside internal systems. Similar cases have surfaced at exchanges and blockchain infrastructure companies before. Consensys isn't a small shop — MetaMask counts its users in the tens of millions, which is why a month of unnoticed access to payment code is unsettling even without an apparent loss this time.
The company says it's rethinking how it vets contractors. Whether that stops the next attempt is something no crypto firm can promise yet.



