So scary! MetaMask’s parent company’s core code was infiltrated for 1 month through a “mistaken hire” of a North Korean engineer, and an emergency investigation was launched.

Blockchain software company Consensys confirmed that earlier this year, without its knowledge, it hired a software engineer affiliated with the North Korean government. The engineer, using the alias “Tyler Knapp,” infiltrated the company’s systems for as long as 1 month. After the incident came to light, the company urgently suspended all product releases and launched an investigation.
(Background: North Korea’s infiltration tactics in crypto exposed — more than 10 Web3 companies including Sushi mis-hired a North Korean undercover agent)
(Additional context: A North Korean engineer infiltrated the crypto space for seven years, victimizing 40 DeFi protocols: Lazarus outsourced to non-North Korean personnel, and its defense strategy had expired)

Table of Contents

Toggle

  • Core wallet code was tampered with
  • Consensys: No assets or data were stolen or misused
  • This North Korea fake-hiring infiltration tactic is not the first case

Consensys, an important Ethereum infrastructure provider, confirmed that earlier this year it hired a software engineer affiliated with the North Korean government completely without knowing it. The engineer, using the alias “Tyler Knapp,” infiltrated the company’s systems for as long as 1 month, and at one point even accessed MetaMask wallet’s core code.

Core wallet code was tampered with

Internal Slack messages show that “Knapp” was actually involved in developing core platform code for the MetaMask wallet, and contributed features related to converting cryptocurrencies and fiat through third-party payment providers. In other words, this unidentified engineer was once able to touch the key infrastructure behind the wallets of millions of users.

After discovering something abnormal, Consensys’s general counsel issued an alert to the entire company in April, ordering that “all product releases be immediately paused while awaiting the results of the investigation,” and the company promptly initiated its security investigation program.

Consensys: No assets or data were stolen or misused

Consensys general counsel Matt Corva told CoinTelegraph: “‘Knapp’ was introduced to us through an existing relationship with a reputable third-party services provider, and he worked with Consensys in an advisory capacity. He was never hired as an official Consensys employee.”

Corva added: “Shortly after he was introduced, we discovered this threat. We immediately terminated all of his access privileges in accordance with our security procedures and launched a comprehensive investigation. The investigation confirmed that no assets or data were stolen or misused, no malicious code was deployed, and there was no impact on user security.” He also said Consensys will re-evaluate the relevant operating procedures for outsourced engineering and development work.

This North Korea fake-hiring infiltration tactic is not the first case

This case is not the first time North Korean hacker organizations have infiltrated crypto firms using fake hiring schemes. In recent years, North Korea–linked hacker groups have frequently used methods such as sending fake job offers or proactively applying for development roles, in order to obtain access to a company’s original source code and then plant backdoors or steal assets. According to statistics, the amount of losses caused by North Korea’s hacker groups in 2025 increased by 51% compared with the previous year, showing that these infiltration tactics are still expanding in scale.

Although Consensys did not cause any real asset losses this time, its core wallet code was exposed to an unidentified engineer for a period of time. This once again highlights vulnerabilities in the crypto industry’s outsourcing and remote hiring review processes, and makes the entire industry even more alert to the question of “who is writing your code.”

SUSHI-4.70%
ETH0.08%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned