EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

MetaMask identifies North Korean spies who infiltrated development team

2026-07-20 00:32:07
Bookmark

Key Points

Contents

Points

Consensus's Response Agreement

Part of a Systematic North Korean (DPRK) Operation

Access to three free stock e-books

A North Korean (DPRK) agent named Tyler Knapp entered MetaMask's development environment through contractor channels.

This person participated in coding related to the wallet fiat tender integrated system within approximately 30 days.

Consensus identified the threat through abnormal network traffic patterns and immediately terminated its access.

The company confirms that no user assets or sensitive information has been compromised and that no malicious code has been introduced.

Hackers associated with North Korea stole more than $1.5 billion from Bybit in 2025 and accounted for more than 50% of the total number of cryptocurrency thefts that year.

A state-backed agent from North Korea successfully penetrated MetaMask development operations for about four weeks. Parent company Consensus publicly stated that the incident did not lead to the loss of user funds or the disclosure of sensitive data.

METAMASK was almost hacked by North Korean hackers. Agresys unknowingly hired a North Korean developer named "Tyler Knapp", who contributed to MetaMask's core code for nearly a month. The company immediately revoked all access rights after detecting the threat. Product launch has been... pic.twitter.com/uTEmOFwIJo- Coin Bureau (@coinbureau) July 19, 2026

This person uses the pseudonym Tyler Knapp and has never been a direct employee of Consensus sys. Instead, they entered the organization through a third-party human resources agency that provided contract workers, bypassing regular verification procedures.

The agent's GitHub profile showed the user name imyugioh. Records show that its code submission time lasted from March 9, 2026 to April, after which Consensys terminated its system permissions.

Their task focuses on developing the wallet's fiat currency gateway infrastructure-a key feature that enables users to convert traditional currencies into digital assets. This is one of the most security-important components in the application.

The intrusion was exposed when Consensys's security infrastructure identified abnormal network connection patterns and suspicious operating behaviors through an automated monitoring system.

Consensus Protocol

After identifying the security threat, Consensus immediately disabled all system credentials associated with the contractor. In April, General Counsel Matt Corva instructed the development team to suspend any product deployments involving the person's contribution.

The company subsequently notified relevant law enforcement agencies and initiated a comprehensive audit of the contractor selection process.

Corva said: "We identified the threat and launched a comprehensive investigation to confirm that no assets or data were embezzled, no malicious code was deployed, and there was no impact on user security."

Corva notified company employees before the news was reported by Drop Site News, so the security breach was made public.

Part of a systemic North Korea (DPRK) operation

This incident is just one example of a broader operational strategy. North Korean agents often disguise themselves as remote software developers, seek positions at cryptocurrency companies, and then attempt to steal digital assets or install malicious access points.

A recent investigation by the Ethereum-backed program found that 100 people suspected of having ties to North Korea worked in 53 different cryptocurrency organizations.

According to blockchain intelligence company TRM Labs, obtaining developer credentials has become the main means for attackers to access and control cryptocurrency transaction approval systems.

U.S. citizens have faced federal prosecution and imprisonment for assisting North Korean agents disguised as their own workers.

The economic impact of this incident is huge. Federal investigators report that North Korean cybercriminals stole $1.5 billion from the Bybit platform last year. TRM Labs records show that the country accounted for more than half of the $2.7 billion stolen through cryptocurrency vulnerabilities throughout 2025.

Multiple cryptocurrency organizations have begun cooperating on threat intelligence sharing programs to identify these agents early in recruitment.

MetaMask serves more than 30 million active users every month, making it a major target in the cryptocurrency wallet ecosystem.

Following the Tyler Knapp incident, Consensus announced that it would strengthen its contractor verification process to prevent similar penetration incidents.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP