Go to app

Mechanism of Access

Published 7/21/2026, 2:04:55 AM

A North Korean-linked operative, using the alias "Tyler Knapp" (suspected real name Mauro Liu), successfully infiltrated Consensys and gained access to MetaMask's core code repositories for approximately one month between March 9 and April 2026. The infiltration was facilitated through a third-party service provider, which allowed the operative to bypass Consensys's direct internal vetting and background check processes [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].

Mechanism of Access

The operative utilized sophisticated social engineering and identity masking techniques common to Democratic People's Republic of Korea (DPRK) IT worker schemes:

  • Third-Party Staffing: The operative was hired as a consultant through a "reputable" third-party staffing agency. This provided a layer of perceived legitimacy that bypassed standard internal HR screening [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
  • Established Developer Persona: Using the GitHub handle "imyugioh", the operative maintained a plausible public commit history to build credibility. Investigations later revealed this identity had been active in the ecosystem for years [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
  • Prior Exploitation History: The consultant had previously worked at five protocols that were subsequently exploited: Ankr, Blueberry Protocol, DEPO, Pickle Finance, and Harmony. Notably, the name "Mauro Liu" had been listed on a Lazarus Group tracking site since September 2025, months before the Consensys engagement began [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].

Scope of Repository Access

During the engagement, the consultant had access to sensitive areas of the MetaMask ecosystem:

MetricDetail
Duration of AccessMarch 9, 2026 – April 2026
Code Contributions3,401 contributions [Note: not independently confirmed]
Affected RepositoriesCore MetaMask platform, Mobile wallet, Crypto-to-fiat conversion features
Potential Reach~30 million wallets were running versions from repositories accessed during this period

Consensys Response and Security Audit

Upon discovering the operative's links to the DPRK in April 2026, Consensys General Counsel Matt Corva issued a company-wide alert to freeze all product releases and revoke the consultant's access.

A comprehensive internal investigation concluded that:

Consensys subsequently notified law enforcement and shared evidence with relevant authorities. The incident highlights a growing trend identified in a January 2025 FBI Advisory regarding North Korean operatives exploiting remote contractor channels to gain repository access [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].

While Consensys successfully mitigated the threat before a breach occurred, the incident remains a significant example of the "supply chain" risks posed by DPRK-linked actors in the decentralized finance (DeFi) sector.