North Korean hackers infiltrate MetaMask: Outsourcing becomes the biggest vulnerability.

CN
23 hours ago

In March 2026, a developer claiming to be a consultant quietly entered the core code repository of MetaMask. Later confirmed, this developer, Tyler Knapp, is a North Korean national, and his GitHub account is imyugioh. He did not join the team through a public recruitment process but instead gained access via a long-term human resources provider working with Consensys, participating directly in the development of this non-custodial wallet serving millions of users as an outsourced/contracted consultant. According to public code records, around March 9, he began submitting code related to the fiat deposit and withdrawal features and continued to participate for about a month. After detecting abnormalities internally, Consensys legal chief Matt Corva disclosed this incident and emphasized that no user data leaks or fund losses have been found, and that the involved code audit did not reveal any clear signs of attack. Whether this developer attempted to submit malicious code remains unknown. In the eyes of the industry, this has evolved from a simple question of whether there was any loss into a wake-up call directly pointing to supply chain security and social engineering: when hackers stop trying to breach the wallet itself and instead disguise themselves as trusted developers entering the codebase, the narrative that "self-custody is safer" for wallets is being forced to confront a new dimension of risk.

Outsourcing Path Breached: North Korean Hackers Infiltrated as Fake Outsourcers

Following this thread of "social engineering + supply chain" back, Tyler Knapp did not enter the team through Consensys’s formal recruitment process but rather through a more obscure side door into the MetaMask code repository. He was recommended by a human resources provider that has long partnered with Consensys, taking on specific module development work as a consultant and contracted developer. It is this supplier's long-accumulated cooperation history and trust foundation that allow "outsourced developers" to be regarded as part of regular business, with background checks and identity verification relying more on the supplier's credit endorsement rather than strict scrutiny from scratch.

According to public code records, starting around March 9, 2026, Tyler Knapp participated in the development of the MetaMask modules related to fiat deposit and withdrawal functions as an outsourced consultant, continuing for about a month. This access model, predicated on “recommendations from reliable partners,” aligns perfectly with the infiltration paths typically used by North Korean hacker organizations: rather than directly breaking through technical defenses, they disguise themselves as compliant outsourced engineers, utilizing intermediaries and long-term cooperation relationships to bypass the most sensitive identity verification checks. For Web3 companies that are accustomed to focusing security attention on protocols, encryption algorithms, and front-end vulnerabilities, this incident clearly exposes another level of reality—when the talent and service supply chain itself is compromised by social engineering, the completeness of technical systems does not automatically translate into overall defense completeness.

The Invisible Risks of Compromised Fiat Deposit and Withdrawal Code

In a wallet product like MetaMask, which serves millions of users, the fiat deposit and withdrawal module is not a peripheral feature but rather the gateway of the entire system. One end connects to users’ bank accounts, while the other points to on-chain addresses and assets, serving as the common pathway for individuals entering the crypto world for the first time from traditional finance. The developer involved participated in the development and maintenance of this part of the code for about a month, meaning the core logic that determines “where the money comes from and where it goes” was affected, rather than trivial user interface tweaks.

If this critical pathway is implanted with backdoors or malicious logic, the potential impacts can affect both asset security and compliance risk lines: theoretically, the backdoor could alter the deposit or withdrawal pointers without the user easily noticing, redirecting funds that should flow to the user's own address to an on-chain account controlled by the attacker, and it could also secretly gather and misuse identity and bank information meant for compliance during the process. Past major attacks targeting exchanges and cross-chain bridges (including cases like Ronin) have proven that as long as attackers control this entrance or exit, it is possible to trigger large-scale asset transfers after a latency period. Consensys’s current public conclusion is “no user data leaks or fund losses have been found,” but since they have not disclosed internal code review details nor clarified whether this developer tried to submit malicious modifications, the incident remains at the stage of “no direct losses have occurred” in results, while structurally exposing a more challenging reality: as long as critical deposit and withdrawal code has once been breached by a suspicious identity, the entire system's risk evaluation must shift from “after-the-fact checks for issues” to “preventing who has the chance to alter these logics beforehand.”

Web3 Recruitment Battlefield: Supply Chain Defense and Offense Upgrades

In this incident, what has truly been torn is not the code defense line of MetaMask, but rather the employment chain of Consensys: Tyler Knapp was not directly employed by Consensys, but entered core code work as an outsourced/contract consultant through a long-term cooperating human resources provider. Public records show he began participating in the development of the fiat deposit and withdrawal feature modules around March 9, 2026. For a globally distributed Web3 company accustomed to remote collaboration, this model is nearly the norm—layer upon layer of recruitment, headhunting, and outsourcing companies enhance project advancement efficiency, but who actually alters critical logic often remains checked only at the contractual and labor hour system levels rather than from a security perspective.

In the face of such a multilayered outsourcing structure and cross-border identity camouflage, traditional background checks appear inadequate. North Korean-affiliated hacker organizations have repeatedly entered crypto enterprises through methods such as fabricating identity resumes, registering outsourcing companies, and using headhunters. Although this time there was no user data leakage or funds loss, it again shows that as long as the talent and service supply chain is compromised, even the most stringent internal access control and code reviews can only serve as reactive remedies. The software industry has already witnessed the power of “supply chain attacks” in cases like SolarWinds, and today, Web3 has merely expanded the same risks from dependent technological components to recruitment channels and service providers; any talent source involved in critical wallet code must be considered part of the security boundary, rather than just variables of cost and efficiency.

How Consensys Stops Losses

From publicly available information, Consensys is not passively responding under external disclosure pressure but has identified abnormalities internally through continuous monitoring of related activities before triggering investigations and external disclosures. Details on specific monitoring content and technical specifics have not been disclosed, but it is confirmed that the involved outsourced developer participated in the modules related to fiat deposit and withdrawal, and legal chief Matt Corva chose to address the situation in the company’s capacity upon noticing this risk, rather than allowing the technical team to issue a vague “version update statement,” which elevates the issue from an engineering level to a compliance and trust level.

In Corva’s statement, “no user data leaks or fund losses” is repeatedly emphasized, which serves to reassure the millions of wallet users and convey a key signal to regulators and partners: the nature of the incident is defined as an exposure of security risk rather than the consequences of an attack that has already occurred. Meanwhile, Consensys has not rushed to publish detailed investigation timelines or audit measures, nor has it indicated whether it has reported to authorities or pursued the whereabouts of the involved developer, choosing to preserve some leeway, which is not uncommon in legal and law enforcement cooperation. The outside world can currently only gauge its loss mitigation attitude through results—on the one hand, explicitly stating that the risk stems from the talent and service supply chain and prompting the industry to reflect on outsourcing and remote recruitment processes; on the other hand, they undertake public relations responsibility with a conclusion of “no losses occurred,” indicating that even if the attack remains at the infiltration stage, critical wallet projects must shift their defensive standards forward to the recruitment phase, completing self-correction before users' trust is truly undermined.

Insights on Wallet Security's New Red Lines from the MetaMask Incident

This infiltration reveals that the security boundaries of leading wallets are being forced to shift forward: it is no longer just about “whether the code has vulnerabilities” or “if the on-chain permissions are small enough,” but the entire chain from recruitment, outsourcing, and human resource providers to identity verification is being included in the defense landscape. Even if no fund losses or large-scale data breaches have been reported as of now, the supply chain and social engineering risks exposed by MetaMask in March 2026 are already sufficient to serve as a new demonstration case for the industry. In past years, attacks related to North Korea were mostly concentrated on exchanges, cross-chain bridges, and crypto enterprises; now, infiltration has directly touched the wallet codebase, compelling all projects to reevaluate: should the management of outsourcing shift from “price and delivery cycles” to “verifiable identities and security responsibilities,” should the background checks and continuous monitoring of remote consultants become standard practice, and should stricter permission levels and submission reviews be implemented in the core code repository? It will be worth observing whether more companies choose to publicly disclose similar supply chain infiltration events rather than bury risks in compliance reports, whether wallet and infrastructure projects will push for industry-level outsourcing security standard upgrades, and whether regulators will further focus on risks that circumvent technical defenses and strike directly at talent and service chains. These subsequent variables will determine whether this infiltration incident is merely an isolated alarm or the starting point for a genuine rewriting of the industry security landscape.

Join our community to discuss and grow stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink