tradingkey.logo
tradingkey.logo
Search

North Korean operative accessed MetaMask code before being caught

CryptopolitanJul 18, 2026 10:11 AM
facebooktwitterlinkedin
View all comments0

Consensys, the blockchain firm behind MetaMask crypto wallet, has confirmed it accidentally brought a North Korea-linked software developer onto its team. The firm confirmed that they gave the operative access to the core wallet code before the company caught on and shut him down after a month. 

Internal Slack messages revealed that the North Korea-linked operative worked on core MetaMask code for approximately one month before being terminated. Although Consensys confirmed that the infiltrator was stopped before any damage was done, the market remains skeptical of MetaMask’s ability to guarantee the safety of its users’ funds. 

North Korean developer spent a month inside MetaMask

According to the report, the North Korean software engineer worked under the alias “Tyler Knapp” and used the GitHub handle “imyugioh.” He was hired as a consultant through a third-party service provider with a long-standing relationship with Consensys. Consensys confirmed that the software engineer was not hired directly through its internal hiring pipeline, insisting that the third-party hiring agency may have been responsible for the breakdown in proper screening. 

Internal Slack messages reviewed show that Tyler Knapp worked on the core MetaMask platform code. He had access to the core MetaMask codebase that converts crypto to fiat currency via third-party payment providers and vice versa. Tyler also contributed to MetaMask’s mobile wallet codebase on GitHub.

Those contributions began on March 9 and abruptly stopped in April, the same month Consensys cut off his access, meaning the operative had roughly a month of activity within the company’s systems.

Consensys general counsel Matt Corva revealed that the company discovered the threat quickly after Tyler was hired. The company followed its security protocols and terminated access immediately upon identifying the threat. He said a subsequent investigation found no misappropriation of assets or data, no malicious code pushed into production, and no impact on user safety.

In April, Corva sent a company-wide alert ordering all product releases suspended pending investigation and instructing staff not to interact with the individual. He also asked employees to keep the matter internal while the probe continued, a request that suggests Consensys was trying to control the narrative well before the story became public this week.

Crypto remains a favorite target for Pyongyang

North Korean operatives posing as remote software engineers have repeatedly landed real jobs at American companies. These companies achieve this with the help of US-based facilitators running laptop farms that make it appear the worker is logging in from within the country.

One Arizona woman was sentenced last year for running such an operation, which prosecutors say generated more than $17 million for North Korea-linked entities, according to reporting from The Guardian.

Earlier this year, two more American nationals were sentenced for facilitating similar schemes that the Department of Justice says touched close to 70 US companies.

Crypto firms are an especially attractive target because a developer’s ordinary access can extend well beyond source code into transaction signing infrastructure, the layer where stolen funds actually move. 

Blockchain analytics firm TRM Labs has estimated that North Korea-linked actors were behind roughly two-thirds of all crypto stolen in hacks last year, a figure that includes the $1.5 billion Bybit theft widely attributed to Pyongyang.

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: The information provided on this website is for educational and informational purposes only and should not be considered financial or investment advice.

Comments (0)

Click the $ button, enter the symbol, and select to link a stock, ETF, or other ticker.

0/500
Commenting Guidelines
Loading...

Recommended Articles

tradingkey.logo
* References, analysis, and trading strategies are provided by the third-party provider, Trading Central, and the point of view is based on the independent assessment and judgement of the analyst, without considering the investment objectives and financial situation of the investors.
Risk Warning: Our Website and Mobile App provides only general information on certain investment products. Finsights does not provide, and the provision of such information must not be construed as Finsights providing, financial advice or recommendation for any investment product.
Investment products are subject to significant investment risks, including the possible loss of the principal amount invested and may not be suitable for everyone. Past performance of investment products is not indicative of their future performance.
Finsights may allow third party advertisers or affiliates to place or deliver advertisements on our Website or Mobile App or any part thereof and may be compensated by them based on your interaction with the advertisements.
© Copyright: FINSIGHTS MEDIA PTE. LTD. All Rights Reserved.