Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
Stock CFD Derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
3.8%
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
A contractor linked to North Korea infiltrated MetaMask for a month— the real vulnerability in the crypto project isn’t in the code
Author: Liam 'Akiba' Wright
Translated by: Deep Tide TechFlow
Deep Tide Brief: A North Korea-linked contractor entered the MetaMask codebase via a third-party supplier and kept working from March 9 until he was removed in April. Although Consensys said it found no stolen assets or malicious code, the incident revealed a fatal weakness in outsourcing management for crypto projects—76% of DeFi stolen funds came from operational-layer permission failures, not code vulnerabilities.
A contractor introduced by a third-party supplier to Consensys began working on the MetaMask code on March 9, and access was not cut off until April. Consensys later described the person as being related to North Korea.
Consensys said its investigation found no misuse of assets or data, no deployment of malicious code, and no impact on user security. Chief Legal Officer Matt Corva said the company rapidly identified the threat, terminated access, launched a comprehensive investigation, and notified law enforcement.
Drop Site reported that an internal alert in April ordered a halt to all product releases to support the investigation and told employees not to interact with the counsel. Corva said the vendor relationship was good; Consensys has since reviewed its third-party service practices, and the same strict standards applied to employees have also been extended to more complex external relationships.
Contractor review needs codebase access restrictions
There was no sign that user accounts or wallet assets were compromised. The existing relationship with the supplier still has a vulnerability: each contractor and account needs its own safeguards.
MetaMask’s general security guidance warns that malicious actors can obtain remote jobs using fake identities and forged documents. It recommends verifying with real documents, conducting multiple interviews, hardware authentication, IP and location verification, background checks, and limiting access to critical systems.
The FBI also warned that North Korean IT workers use company network access to replicate codebases. Its guidance requires identity verification during interviews, onboarding, and throughout employment, regular audits of third-party staffing firms, least-privilege access, and monitoring for unusual remote connections or codebase leaks.
Codebase access and review are core safeguards
After onboarding, codebase access and review become core safeguards. The UK National Cyber Security Centre’s guidance recommends making codebase activity traceable, reviewing every change in each production environment, adding extra scrutiny for external contributions, and quickly revoking access when it’s no longer needed. Hardware-backed credentials can protect accounts from stolen credentials, while tightly limited permissions and independent review can restrict what authorized accounts can change.
On July 5, CryptoSlate reported that in the first half of 2026, operational-layer attacks targeting key, custody, signing, and approval systems accounted for about 76% of the stolen funds, even though smart contract vulnerabilities occur more frequently. The gap shows why access and operational controls are crucial—these incidents may be fewer in number, but they have major impact.
Wallet and protocol teams should treat contractor access as continuously conditional. Identity checks should run throughout the entire employment period, third-party firms should be subject to audits, codebase access should remain narrow and observable, every change in each production environment should receive independent review, and access should be revoked immediately once it is no longer needed.
Consensys pausing releases in April also demonstrates the value of having predefined ways to pause changes so they can be used when investigating suspicious access.