Consensys hired a developer linked to North Korea for MetaMask, and he had access to internal systems and wallet code for almost a month. The incident took place in spring 2026, and the company says it quickly cut off access and saw no data leak.
According to Drop Site, the contractor worked under the name Tyler Knapp and the GitHub account imyugioh. He was brought in to work on MetaMask components, including modules that help convert cryptocurrency into fiat through third-party payment providers. Contributions from this account to the repository stopped in April 2026, and that was when the company revoked all access.
The story matters not only for Consensys. MetaMask has more than 30 million MAU, and for a product like this, even brief access by an outside developer to code and internal systems already creates a risk for millions of users. That is why this news hits wallet security, not just the reputation of one company.
Why did this case hit MetaMask so hard?
Because MetaMask давно works not as a small service, but as one of the main gateways into the crypto market for everyday users. According to Consensys materials, the number of active users grew from 19 million in September 2023 to 30+ million in January 2024. And when a person with a suspicious background gets access to such a product, the stakes are no longer abstract security, but very concrete things: code, access rights, transaction signing.
Drop Site also reported that in April Matt Corva ordered all product releases to be paused during the investigation and banned employees from contacting “Tyler Knapp.” The first contributions from this account to MetaMask began on March 9, 2026. That is why the company reacted so quickly: in stories like this, the worst-case scenario is not always a smart contract hack, but a quiet intrusion into development and code delivery processes.
The company’s response and what it said
Consensys general counsel Matt Corva said the company detected the threat quickly, immediately cut off access, and carried out an investigation. According to him, no assets or data were compromised, malicious code was not deployed, and user security was not affected. The company also passed the information to law enforcement.
“Knapp” was introduced to us through existing relationships with a reputable third-party service provider. Very quickly after that, we identified the threat, followed all security protocols, immediately terminated access, and conducted a comprehensive investigation.
After that, Consensys reviewed its procedures for working with third-party contractors. That is a logical step. The story shows that risk often comes not through a complex exploit, but through a person who was let inside because of trust in an intermediary. Against this backdrop, it is also worth remembering how important it is not to keep all assets in one place, and when needed, to quickly sell Bitcoin on Monobank.
What do the numbers say about the risk for crypto companies?
The picture here is harsh. According to TRM Labs, there were 207 crypto hacks in the first six months of 2026, and losses totaled $972 million. Separately, TRM estimates losses from North Korea-linked attacks at $643 million, or 66% of all stolen funds in the half-year. Two April attacks, Drift Protocol at about $285 million and KelpDAO at about $292 million, together accounted for roughly $577 million.
There is another important detail: according to TRM, infrastructure and operational compromises made up only about 15% of incidents, but accounted for about 76% of losses. In simple terms, the most dangerous things are often not the smart contracts themselves, but access rights, accounts, and internal processes. That is exactly why the MetaMask case drew so much market attention.
the incident took place in spring 2026;
access to internal systems lasted almost a month;
the first repository contributions began on March 9, 2026;
in April 2026, the company revoked access;
MetaMask has more than 30 million MAU;
TRM Labs estimates losses from North Korea-linked attacks at $643 million for H1 2026.
These figures explain well why the market reacts so nervously to any insider-access story. From there, the question is no longer just about MetaMask, but about how contractors are vetted across the entire industry.
What does this mean for investors?
For cryptocurrency holders, this is a reminder of a simple thing: wallet security depends not only on a password or seed phrase. If a major service has a weak point at the level of hiring, contractors, or code access, the risk can affect even those who did nothing themselves. In 2024, Consensys said it had more than 30 million MAU, which means one process failure can affect a very broad audience.
For companies, the conclusion is even harsher. The FBI warned as far back as January 23, 2025, that North Korean IT workers may blackmail companies, copy GitHub repositories, steal cookies and credentials, and use AI face-swapping in video interviews. And on March 12, 2026, OFAC imposed sanctions on 6 individuals and 2 companies over schemes to employ North Korean IT specialists. In other words, this is not an isolated failure, but a long-running, well-practiced scheme.
It is also worth noting that on April 15, 2026, the DOJ announced sentences in the “laptop farm” case, where the scheme affected 100+ U.S. companies and brought North Korea more than $5 million. Against that backdrop, Consensys’ response looks correct, but the incident itself shows that candidate and vendor screening is no longer a formality, but basic defense.
If you need to quickly convert assets into hryvnia, you can sell USDT TRC20 on Monobank without extra steps and in a convenient way for everyday operations.
Frequently asked questions
Were MetaMask users affected after this incident?
Consensys said no. The company says there was no data leak, no malicious code was deployed, and user assets were not affected. But the very fact of nearly a month of access to internal systems shows why such cases cannot be ignored.
Why is North Korea so often linked to crypto hacks?
Because this is already a systemic scheme. According to TRM Labs, North Korea-linked attacks accounted for 66% of all stolen funds in the first half of 2026, or $643 million. Crypto companies attract such attackers because of access to code, infrastructure, and money.
What should crypto companies check after this story?
First of all, contractors, repository access, and internal communications. The FBI separately advises not to limit checks to the candidate directly, but also to look at the staffing firms through which they enter the team. This is no longer a minor technical detail, but a product security issue.
The MetaMask story showed that in crypto, the weak point is often not in the code, but in people and processes. For those who follow the market and work with tokens every day, this is another reason to pay closer attention to how assets are stored and exchanged, and when needed, to quickly sell USDT TRC20 on PrivatBank.
This material is not financial advice. Cryptocurrency trading involves significant risks. Part of this text was prepared with the help of artificial intelligence based on public sources and reviewed by our editorial team.