Consensys said it identified and removed a contractor linked to North Korea after the individual briefly worked on MetaMask-related code and had access to internal systems in spring 2026. The company said the developer remained inside its environment for about a month before access was terminated, and that an internal investigation found no evidence of stolen data, malicious code deployment, or harm to users.
How the contractor was hired
According to Consensys, the developer was engaged as a consultant after being introduced through an existing relationship with what the company described as a reputable third-party service provider. The individual allegedly operated under the alias Tyler Knapp and used the GitHub account imyugioh while contributing to MetaMask work.
Consensys general counsel Matt Corva said the company detected suspicious activity soon after the consultant was brought in. He said the company then followed its security procedures, cut off the person’s access immediately, and opened a broader review of the incident.
Access and code contributions
The contractor worked on parts of the MetaMask platform, including modules tied to converting crypto into fiat through third-party payment providers. Consensys said the person’s repository activity ended in April 2026, which is also when all access was revoked.
The company described the consultant as having worked on code for about a month during spring 2026. While the role involved access to internal systems and development work on MetaMask components, Consensys said its investigation did not uncover misappropriation of assets or data.
Company response
In a statement cited by the source report, Corva said Consensys “very quickly” recognized the threat after the introduction. He said the company’s review confirmed there was no malicious code deployed and no effect on user safety or security.
Consensys also said it notified law enforcement and later reassessed its procedures for working with outside contractors. The company framed the episode as a test of its internal controls, saying its security protocols enabled it to identify the issue and remove the consultant before any confirmed damage occurred.
Why the incident matters
The case highlights a broader concern for crypto companies, which security experts have long viewed as attractive targets for North Korean-linked actors. The risk is not limited to theft of funds: developer access can potentially open paths into source code and, in some cases, sensitive infrastructure connected to transaction signing.
In this instance, however, Consensys said its investigation found no evidence of a data leak, no malicious changes to code, and no impact on MetaMask users. The company’s account leaves the incident as a contained security breach involving a third-party hire rather than a confirmed compromise of customer assets or systems.
Source: incrypted.com