How Access Was Gained
Published 7/18/2026, 6:49:38 PM
ConsenSys, the developer of the MetaMask wallet, inadvertently hired a North Korean-linked software developer who maintained access to internal systems for approximately one month in early 2026. The individual, operating under the alias "Tyler Knapp" (GitHub handle: imyugioh), was onboarded as a consultant and contributed to core MetaMask infrastructure before the threat was identified and neutralized.
How Access Was Gained
The hacker bypassed standard vetting procedures by leveraging a "supply-chain" social engineering vector. Rather than applying directly, the individual was introduced through an existing relationship with a reputable third-party service provider already used by ConsenSys [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker].
By using fabricated identity documents, the developer secured a consulting position, which allowed them to bypass the more rigorous background checks typically reserved for full-time employees [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker].
Duration and Scope of Access
The breach lasted for approximately four weeks during the spring of 2026.
| Metric | Details |
|---|---|
| Start Date | March 9, 2026 [Source: https://beincrypto.com/consensys-metamask-north-korean-hacker/] |
| End Date | April 2026 (Terminated upon discovery) [Source: https://beincrypto.com/consensys-metamask-north-korean-hacker/] |
| Primary Alias | Tyler Knapp (GitHub: imyugioh) [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker] |
| Systems Accessed | Core MetaMask codebase, Mobile platform, Fiat-to-crypto features [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker] |
During this period, the developer made direct contributions to the primary MetaMask wallet codebase and the mobile platform. They also worked on sensitive features involving third-party payment providers for currency conversion [Source: https://www.dropsitenews.com/p/consensys-metamask-north-korea-hacker].
Impact and Investigation
Following the discovery in April 2026, ConsenSys suspended all product releases to conduct a forensic audit. According to ConsenSys General Counsel Matt Corva, the investigation concluded that:
- No assets or data were misappropriated. [Verified: https://cryptorank.io/news/feed/112345-consensys-metamask-north-korean-hacker]
- No malicious code reached production environments. [Verified: https://cryptorank.io/news/feed/112345-consensys-metamask-north-korean-hacker]
- User safety remained intact, as the developer's access was revoked before any harmful logic could be deployed to the public.
Broader Context
This incident is part of a wider trend of North Korean IT workers infiltrating Western crypto firms. Reports indicate that North Korean-linked groups were responsible for approximately 66% of all crypto assets stolen in the first half of 2026, amounting to roughly $643 million [Verified: Multiple sources including UPI and TRM Labs]. These operatives often seek to expropriate trade secrets or gain "sleeper" access to transaction-signing infrastructure for future exploits.
While the ConsenSys breach resulted in $0 in stolen funds, it highlighted significant vulnerabilities in how major crypto firms vet third-party consultants and service providers.