MetaMask contractor linked to North Korea worked for a month

From March 9 to April 2026, a contractor tied to North Korea contributed MetaMask code before Consensys cut access and paused releases; its probe found no asset or user compromise.

A contractor engaged through an external vendor contributed MetaMask-related code from March 9 until Consensys revoked access in April 2026. Consensys suspended product releases and opened an investigation when it identified the contributor.

Consensys’ investigation concluded there was no misappropriation of assets or data, no deployment of malicious code and no impact to user security or wallet accounts. Consensys notified law enforcement after terminating the contributor’s access.

Consensys’ general counsel, Matt Corva, wrote that the company identified the worker quickly, cut access and launched a comprehensive inquiry. An internal alert in April ordered a pause on releases and instructed staff not to interact with the consultant while the probe continued.

The contributor’s access had been provided through a third-party provider. Following the incident, Consensys reviewed vendor practices and extended the same access and onboarding standards it applies to employees to more complex outside relationships.

The company said repository permissions and contractor account safeguards required tightening. Consensys reviewed onboarding, access controls and vendor management to narrow repository permissions and increase oversight of external contributors.

Security guidance for MetaMask and national cyber authorities list methods that malicious insiders can use to obtain remote roles, including false identities and forged documents. Recommended countermeasures include verifying identity documents during hiring, conducting multiple interviews and reference checks, using hardware-backed authentication, checking IP and location, and limiting access to critical systems.

Authorities have warned that some overseas IT workers have used network access to copy code repositories. Their guidance calls for continuous identity verification, routine audits of staffing firms, least-privilege access, and monitoring for unusual remote connections or repository exfiltration.

After onboarding, making repository activity attributable and subjecting every production-bound change to independent review are listed as core controls. Guidance also recommends applying extra scrutiny to external contributions and revoking access immediately when it is no longer required. Hardware-backed credentials and narrowly scoped permissions are cited as measures that restrict what an authorized account can change.

Data from the first half of 2026 show that operational compromises involving keys, custody, signing and approval systems accounted for roughly 76% of stolen value, while smart-contract exploits occurred more frequently. Consensys paused releases during its investigation to limit potential exposure while access questions were resolved.

Security teams for wallets and protocols are advised to treat contractor access as conditional throughout an engagement, audit third-party firms, keep repository privileges narrow and observable, require independent review for production changes, and revoke access promptly when it is no longer needed.

Articles by this author