Mechanism of Access
Published 7/21/2026, 2:04:55 AM
A North Korean-linked operative, using the alias "Tyler Knapp" (suspected real name Mauro Liu), successfully infiltrated Consensys and gained access to MetaMask's core code repositories for approximately one month between March 9 and April 2026. The infiltration was facilitated through a third-party service provider, which allowed the operative to bypass Consensys's direct internal vetting and background check processes [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
Mechanism of Access
The operative utilized sophisticated social engineering and identity masking techniques common to Democratic People's Republic of Korea (DPRK) IT worker schemes:
- Third-Party Staffing: The operative was hired as a consultant through a "reputable" third-party staffing agency. This provided a layer of perceived legitimacy that bypassed standard internal HR screening [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
- Established Developer Persona: Using the GitHub handle "imyugioh", the operative maintained a plausible public commit history to build credibility. Investigations later revealed this identity had been active in the ecosystem for years [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
- Prior Exploitation History: The consultant had previously worked at five protocols that were subsequently exploited: Ankr, Blueberry Protocol, DEPO, Pickle Finance, and Harmony. Notably, the name "Mauro Liu" had been listed on a Lazarus Group tracking site since September 2025, months before the Consensys engagement began [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
Scope of Repository Access
During the engagement, the consultant had access to sensitive areas of the MetaMask ecosystem:
| Metric | Detail |
|---|---|
| Duration of Access | March 9, 2026 – April 2026 |
| Code Contributions | 3,401 contributions [Note: not independently confirmed] |
| Affected Repositories | Core MetaMask platform, Mobile wallet, Crypto-to-fiat conversion features |
| Potential Reach | ~30 million wallets were running versions from repositories accessed during this period |
Consensys Response and Security Audit
Upon discovering the operative's links to the DPRK in April 2026, Consensys General Counsel Matt Corva issued a company-wide alert to freeze all product releases and revoke the consultant's access.
A comprehensive internal investigation concluded that:
- No malicious code was successfully deployed to production.
- No assets or user data were misappropriated.
- User safety remained intact throughout the incident [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
Consensys subsequently notified law enforcement and shared evidence with relevant authorities. The incident highlights a growing trend identified in a January 2025 FBI Advisory regarding North Korean operatives exploiting remote contractor channels to gain repository access [Source: https://dropsitenews.com/p/consensys-north-korean-consultant].
While Consensys successfully mitigated the threat before a breach occurred, the incident remains a significant example of the "supply chain" risks posed by DPRK-linked actors in the decentralized finance (DeFi) sector.