20 Jul 202616:00
Analytics
MetaMask Catches North Korea-Linked Consultant in Core Code Work

MetaMask Catches North Korea-Linked Consultant in Core Code Work

Consensys, the firm behind the MetaMask wallet, unknowingly hired a software developer with alleged ties to North Korea, who spent roughly a month working on core platform code before being terminated.


The individual used the alias "Tyler Knapp" and GitHub handle "imyugioh", was brought on as a consultant through an existing third-party service provider relationship. He contributed to core MetaMask code, including components for crypto-to-fiat conversion via third-party payment providers and parts of the mobile wallet platform. His contributions began March 9 and stopped abruptly in April 2026, coinciding with the termination of his access.


Consensys general counsel Matt Corva confirmed the company discovered the threat shortly after the consultant was introduced, immediately cut off access, and launched an investigation that found no misappropriated assets or data, no malicious code deployed, and no impact to user security. Consensys notified law enforcement and has since reviewed its practices around outsourced engineering work.


Notably, the same GitHub identity had prior contributions to several other crypto projects, including Ankr, Blueberry Protocol, DEPO, Pickle Finance, and Harmony.


The incident fits a broader pattern: North Korean operatives have increasingly infiltrated crypto and software firms by posing as remote engineers, given that developer access can extend beyond source code to transaction-signing infrastructure, a direct pipeline for moving stolen assets across chains.


TRM Labs estimates North Korea-linked activity accounts for nearly 66% of all funds stolen in crypto hacks, including last year's $1.5B Bybit hack, one of the largest crypto heists on record.