Go to app

How Access Was Gained

Published 7/18/2026, 6:49:38 PM

ConsenSys, the developer of the MetaMask wallet, inadvertently hired a North Korean-linked software developer who maintained access to internal systems for approximately one month in early 2026. The individual, operating under the alias "Tyler Knapp" (GitHub handle: imyugioh), was onboarded as a consultant and contributed to core MetaMask infrastructure before the threat was identified and neutralized.

How Access Was Gained

The hacker bypassed standard vetting procedures by leveraging a "supply-chain" social engineering vector. Rather than applying directly, the individual was introduced through an existing relationship with a reputable third-party service provider already used by ConsenSys [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker].

By using fabricated identity documents, the developer secured a consulting position, which allowed them to bypass the more rigorous background checks typically reserved for full-time employees [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker].

Duration and Scope of Access

The breach lasted for approximately four weeks during the spring of 2026.

MetricDetails
Start DateMarch 9, 2026 [Source: https://beincrypto.com/consensys-metamask-north-korean-hacker/]
End DateApril 2026 (Terminated upon discovery) [Source: https://beincrypto.com/consensys-metamask-north-korean-hacker/]
Primary AliasTyler Knapp (GitHub: imyugioh) [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker]
Systems AccessedCore MetaMask codebase, Mobile platform, Fiat-to-crypto features [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker]

During this period, the developer made direct contributions to the primary MetaMask wallet codebase and the mobile platform. They also worked on sensitive features involving third-party payment providers for currency conversion [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker].

Impact and Investigation

Following the discovery in April 2026, ConsenSys suspended all product releases to conduct a forensic audit. According to ConsenSys General Counsel Matt Corva, the investigation concluded that:

Broader Context

This incident is part of a wider trend of North Korean IT workers infiltrating Western crypto firms. Reports indicate that North Korean-linked groups were responsible for approximately 66% of all crypto assets stolen in the first half of 2026, amounting to roughly $643 million [Verified: Multiple sources including UPI and TRM Labs]. These operatives often seek to expropriate trade secrets or gain "sleeper" access to transaction-signing infrastructure for future exploits.

While the ConsenSys breach resulted in $0 in stolen funds, it highlighted significant vulnerabilities in how major crypto firms vet third-party consultants and service providers.