A contractor linked to North Korea infiltrated MetaMask for a month— the real vulnerability in the crypto project isn’t in the code

robot
Abstract generation in progress

Author: Liam 'Akiba' Wright

Translated by: Deep Tide TechFlow

Deep Tide Brief: A North Korea-linked contractor entered the MetaMask codebase via a third-party supplier and kept working from March 9 until he was removed in April. Although Consensys said it found no stolen assets or malicious code, the incident revealed a fatal weakness in outsourcing management for crypto projects—76% of DeFi stolen funds came from operational-layer permission failures, not code vulnerabilities.

A contractor introduced by a third-party supplier to Consensys began working on the MetaMask code on March 9, and access was not cut off until April. Consensys later described the person as being related to North Korea.

Consensys said its investigation found no misuse of assets or data, no deployment of malicious code, and no impact on user security. Chief Legal Officer Matt Corva said the company rapidly identified the threat, terminated access, launched a comprehensive investigation, and notified law enforcement.

Drop Site reported that an internal alert in April ordered a halt to all product releases to support the investigation and told employees not to interact with the counsel. Corva said the vendor relationship was good; Consensys has since reviewed its third-party service practices, and the same strict standards applied to employees have also been extended to more complex external relationships.

Contractor review needs codebase access restrictions

There was no sign that user accounts or wallet assets were compromised. The existing relationship with the supplier still has a vulnerability: each contractor and account needs its own safeguards.

MetaMask’s general security guidance warns that malicious actors can obtain remote jobs using fake identities and forged documents. It recommends verifying with real documents, conducting multiple interviews, hardware authentication, IP and location verification, background checks, and limiting access to critical systems.

The FBI also warned that North Korean IT workers use company network access to replicate codebases. Its guidance requires identity verification during interviews, onboarding, and throughout employment, regular audits of third-party staffing firms, least-privilege access, and monitoring for unusual remote connections or codebase leaks.

Codebase access and review are core safeguards

After onboarding, codebase access and review become core safeguards. The UK National Cyber Security Centre’s guidance recommends making codebase activity traceable, reviewing every change in each production environment, adding extra scrutiny for external contributions, and quickly revoking access when it’s no longer needed. Hardware-backed credentials can protect accounts from stolen credentials, while tightly limited permissions and independent review can restrict what authorized accounts can change.

On July 5, CryptoSlate reported that in the first half of 2026, operational-layer attacks targeting key, custody, signing, and approval systems accounted for about 76% of the stolen funds, even though smart contract vulnerabilities occur more frequently. The gap shows why access and operational controls are crucial—these incidents may be fewer in number, but they have major impact.

Wallet and protocol teams should treat contractor access as continuously conditional. Identity checks should run throughout the entire employment period, third-party firms should be subject to audits, codebase access should remain narrow and observable, every change in each production environment should receive independent review, and access should be revoked immediately once it is no longer needed.

Consensys pausing releases in April also demonstrates the value of having predefined ways to pause changes so they can be used when investigating suspicious access.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned