Key Points
Contents
Points
Consensus's Response Agreement
Part of a Systematic North Korean (DPRK) Operation
Access to three free stock e-books
A North Korean (DPRK) agent named Tyler Knapp entered MetaMask's development environment through contractor channels.
This person participated in coding related to the wallet fiat tender integrated system within approximately 30 days.
Consensus identified the threat through abnormal network traffic patterns and immediately terminated its access.
The company confirms that no user assets or sensitive information has been compromised and that no malicious code has been introduced.
Hackers associated with North Korea stole more than $1.5 billion from Bybit in 2025 and accounted for more than 50% of the total number of cryptocurrency thefts that year.
A state-backed agent from North Korea successfully penetrated MetaMask development operations for about four weeks. Parent company Consensus publicly stated that the incident did not lead to the loss of user funds or the disclosure of sensitive data.
METAMASK was almost hacked by North Korean hackers. Agresys unknowingly hired a North Korean developer named "Tyler Knapp", who contributed to MetaMask's core code for nearly a month. The company immediately revoked all access rights after detecting the threat. Product launch has been... pic.twitter.com/uTEmOFwIJo- Coin Bureau (@coinbureau) July 19, 2026
This person uses the pseudonym Tyler Knapp and has never been a direct employee of Consensus sys. Instead, they entered the organization through a third-party human resources agency that provided contract workers, bypassing regular verification procedures.
The agent's GitHub profile showed the user name imyugioh. Records show that its code submission time lasted from March 9, 2026 to April, after which Consensys terminated its system permissions.
Their task focuses on developing the wallet's fiat currency gateway infrastructure-a key feature that enables users to convert traditional currencies into digital assets. This is one of the most security-important components in the application.
The intrusion was exposed when Consensys's security infrastructure identified abnormal network connection patterns and suspicious operating behaviors through an automated monitoring system.
Consensus Protocol
After identifying the security threat, Consensus immediately disabled all system credentials associated with the contractor. In April, General Counsel Matt Corva instructed the development team to suspend any product deployments involving the person's contribution.
The company subsequently notified relevant law enforcement agencies and initiated a comprehensive audit of the contractor selection process.
Corva said: "We identified the threat and launched a comprehensive investigation to confirm that no assets or data were embezzled, no malicious code was deployed, and there was no impact on user security."
Corva notified company employees before the news was reported by Drop Site News, so the security breach was made public.
Part of a systemic North Korea (DPRK) operation
This incident is just one example of a broader operational strategy. North Korean agents often disguise themselves as remote software developers, seek positions at cryptocurrency companies, and then attempt to steal digital assets or install malicious access points.
A recent investigation by the Ethereum-backed program found that 100 people suspected of having ties to North Korea worked in 53 different cryptocurrency organizations.
According to blockchain intelligence company TRM Labs, obtaining developer credentials has become the main means for attackers to access and control cryptocurrency transaction approval systems.
U.S. citizens have faced federal prosecution and imprisonment for assisting North Korean agents disguised as their own workers.
The economic impact of this incident is huge. Federal investigators report that North Korean cybercriminals stole $1.5 billion from the Bybit platform last year. TRM Labs records show that the country accounted for more than half of the $2.7 billion stolen through cryptocurrency vulnerabilities throughout 2025.
Multiple cryptocurrency organizations have begun cooperating on threat intelligence sharing programs to identify these agents early in recruitment.
MetaMask serves more than 30 million active users every month, making it a major target in the cryptocurrency wallet ecosystem.
Following the Tyler Knapp incident, Consensus announced that it would strengthen its contractor verification process to prevent similar penetration incidents.


Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following