Consensys discovered a North Korea-linked developer had contributed to MetaMask code before access was revoked; no compromise or malicious code confirmed.
Regulation & Gov ·
Consensys identified and removed access for a developer with alleged North Korea ties who had contributed code to MetaMask through a third-party hiring intermediary. The individual, operating under the alias "Tyler Knapp," had worked on components related to cryptocurrency-to-fiat conversion functionality. According to reporting, the firm stated it detected the security concern, terminated the arrangement, and found no evidence of compromised systems, malicious insertions, or user impact.
The incident highlights risks in outsourced development pipelines, particularly when vetting mechanisms fail to catch geopolitical red flags during onboarding. Consensys's swift remediation and public acknowledgment suggest the breach was discovered before any harmful code reached production or user wallets.
Questions remain about how the developer initially passed background checks, what portions of the MetaMask codebase were touched, and whether the code review process flagged anything suspicious in hindsight. The firm has not disclosed the timeline between hiring and discovery.