MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases
A contractor introduced in by way of a third-party supplier labored on MetaMask code from March 9 till Consensys minimize off entry in April. Consensys later described the individual as linked to North Korea.
Consensys mentioned its investigation discovered no misappropriation of belongings or information, no malicious code deployment and no affect to person security or safety. General counsel Matt Corva mentioned the corporate recognized the risk shortly, terminated entry, launched a complete investigation and notified legislation enforcement.
Drop Site reported that an inside April alert ordered all product releases suspended pending the investigation and advised employees not to work together with the guide. Corva referred to as the service supplier relationship respected and mentioned Consensys has since reviewed its third-party service practices, so the rigorous requirements utilized to staff additionally cowl extra advanced outdoors relationships.
Contractor checks want repository limits
The incident provides no indication that person accounts or pockets belongings had been compromised. Consensys’ present relationship with the seller nonetheless left a hole: each contractor and account wanted its personal safeguards.
MetaMask’s basic safety guidance warns that malicious employees can use false identities and solid paperwork to get hold of distant roles. It recommends checks utilizing precise paperwork, a number of interviews, {hardware} authentication, IP and site verification, reference checks, and limits on entry to important techniques.
The FBI has separately warned that North Korean IT employees have used company-network entry to copy code repositories. Its steering calls for id verification throughout interviews, onboarding and all through employment, routine audits of third-party staffing companies, least-privilege entry and monitoring for uncommon distant connections or repository exfiltration.
After onboarding, repository permissions and evaluation turn into the core safeguards. UK National Cyber Security Center guidance recommends making repository exercise attributable, reviewing each production-bound change, making use of additional scrutiny to exterior contributions, and revoking entry shortly when it’s now not required. Hardware-backed credentials can shield an account from credential theft, whereas tightly scoped permissions and unbiased evaluation restrict what a certified account can change.
CryptoSlate reported on July 5 that operational compromises round keys, custody, signing and approval techniques accounted for roughly 76% of stolen worth through the first half of 2026, despite the fact that smart-contract exploits had been extra frequent. That hole exhibits why entry and operational controls matter even once they account for fewer incidents.
Wallet and protocol groups ought to deal with contractor entry as constantly conditional. Identity checks ought to prolong by way of employment, third-party companies needs to be audited, repository privileges ought to stay slim and observable, each production-bound change ought to obtain unbiased evaluation, and entry needs to be revoked as quickly as it’s now not required.
Consensys’s April launch pause additionally exhibits the worth of retaining a predefined method to halt adjustments whereas suspicious entry is investigated.
The put up MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases appeared first on CryptoSlate.

