Incident Overview and Timeline
Published 7/20/2026, 4:35:44 PM
Consensys did not intentionally hire a North Korean developer; rather, the company unknowingly engaged a contractor operating under a sophisticated false identity. The individual, using the alias "Tyler Knapp," was hired through a third-party staffing provider and contributed to MetaMask's codebase for approximately one month in early 2026 before being detected by internal security protocols.
Incident Overview and Timeline
The developer began contributing to MetaMask on March 9, 2026. By April 2026, Consensys security teams identified the threat and immediately revoked all access. The incident became public on July 17, 2026, following a report by Drop Site News.
| Date | Event |
|---|---|
| March 9, 2026 | "Tyler Knapp" begins contributing code to MetaMask repositories. |
| April 2026 | Consensys security protocols detect the threat; access is terminated. |
| April 2026 | Internal investigation begins; product releases are temporarily suspended. |
| July 17, 2026 | Drop Site News reports the incident based on internal communications. |
| July 20, 2026 | Official company acknowledgments and industry-wide reporting. |
Verified Facts of the Case
- Identity and Alias: The developer used the name "Tyler Knapp" and the GitHub handle
imyugioh. Post-incident analysis linked this persona to "Mauro Liu," an identity previously associated with several high-profile DeFi exploits, including those at Ankr, Harmony One, and Pickle Finance. - Hiring Method: The individual was not a direct full-time hire. According to Consensys General Counsel Matt Corva, the developer was introduced through an "existing relationship with a reputable third-party service provider."
- Scope of Work: The contractor worked on MetaMask’s core platform, mobile wallet development, and modules for third-party fiat payment providers.
- Security Impact: A comprehensive internal audit concluded that no malicious code was deployed, no user data was compromised, and no assets were misappropriated.
Consensys's Response
Upon discovering the developer's true nature, Consensys took several corrective actions:
- Immediate Revocation: All system access was cut, and active product releases were halted to ensure no compromised code reached users.
- Full Audit: The company conducted a deep-dive code review which confirmed the safety of the MetaMask platform.
- Law Enforcement Cooperation: Findings were shared with relevant authorities to assist in tracking DPRK-linked cyber activities.
- Vetting Reform: Consensys has since updated its contractor vetting standards to match the rigorous background checks used for full-time employees.
Context: The DPRK IT Worker Threat
This incident is part of a broader, documented campaign by the Democratic People's Republic of Korea (DPRK) to infiltrate global tech firms. These operatives use stolen or fabricated identities and high-quality resumes to secure remote positions. Their goals typically include generating revenue for the regime or establishing long-term access for future exploits. In this instance, the developer bypassed standard direct-hire scrutiny by utilizing a third-party vendor relationship.
Note on Data Gaps: While Consensys has confirmed the incident and the lack of impact on user funds, the specific third-party staffing vendor has not been publicly named. Additionally, while the developer is linked to previous hacks (Ankr, Harmony), a formal government indictment specifically naming "Tyler Knapp" as a DPRK state actor for this specific MetaMask incident has not yet been released.