Consensys halted MetaMask product releases after discovering that a contractor linked to North Korea had obtained access to MetaMask code for roughly a month in March and April through a third-party staffing provider. Reporting said the individual worked on MetaMask-related code, including core components used to connect users to third-party fiat payment providers, and the case was described as an accidental hire under a false identity tied to the broader North Korean remote IT worker scheme targeting crypto and technology firms.
Consensys said it terminated the contractor's access, opened an internal investigation, and notified law enforcement. The company stated that its review found no evidence of stolen assets, exposed user data, malicious code deployment, or impact to user safety, but the incident still forced a temporary release freeze and renewed scrutiny of hiring controls and supply-chain exposure in cryptocurrency development environments.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
After discovering the contractor's North Korea link, Consensys suspended MetaMask product releases, terminated the contractor's access, opened an investigation, and notified law enforcement. The company said its investigation found no stolen assets, exposed data, malicious code deployment, or impact to user safety.
Consensys said a contractor later linked to North Korea had access to MetaMask code for about a month during March and April through a third-party provider. The contractor contributed to MetaMask-related code, including core components used to connect users to third-party fiat payment providers.
Drop Site News reported that blockchain firm Consensys had accidentally hired a North Korean hacker, bringing the incident into public view. A later Bluesky post amplified the same headline-level claim without adding new operational details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
nknews.org
Open sourcexakep.ru
Open sourcebsky.app
Open sourcethedefiant.io
Open sourcedropsitenews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.