Author: Liam 'Akiba' Wright
Translation: Deep Tide TechFlow
Deep Tide Overview: A contractor linked to North Korea accessed the MetaMask codebase through a third-party vendor from March 9 until April when they were removed. Although Consensys stated that no assets were stolen or malicious code found, this incident exposed a critical flaw in the management of outsourced cryptocurrency projects—76% of stolen funds in DeFi come from operational permission failures, not code vulnerabilities.
A contractor introduced by Consensys through a third-party vendor began working on the MetaMask code from March 9 until access was cut off in April. Consensys later described this individual as associated with North Korea.
Consensys stated that the investigation found no stolen assets or data, no deployment of malicious code, and no impact on user security. Chief Legal Counsel Matt Corva stated the company quickly identified the threat, terminated access, initiated a comprehensive investigation, and notified law enforcement.
Drop Site reported that an internal alert in April requested a halt to all product releases to assist in the investigation and instructed employees not to interact with the contractor. Corva noted that the service provider had a good relationship with Consensys, which has since reviewed its third-party service practices and extended strict standards applicable to employees to more complex external relationships.
Contractor Review Requires Codebase Access Restrictions
The incident showed no signs of harm to user accounts or wallet assets. The existing relationship between Consensys and the vendor still has vulnerabilities: each contractor and account needs its own safeguards.
MetaMask's general security guidelines warn that malicious actors can obtain remote positions using false identities and forged documents. It recommends verifying actual documents, conducting multiple interviews, hardware authentication, IP and location verification, background checks, and restricting access to critical systems.
The FBI additionally warned that North Korean IT workers are leveraging company network access to copy codebases. Their guidelines require identity verification during interviews, onboarding, and throughout employment, regular audits of third-party staffing agencies, least privilege access, and monitoring for anomalous remote connections or codebase leaks.
Codebase Access and Review are Core Safeguards
Once hired, codebase access and review become core safeguards. Guidance from the UK National Cyber Security Centre recommends making codebase activities traceable, reviewing every change in production environments, conducting additional reviews of external contributions, and quickly revoking access when no longer needed. Hardware-backed credentials can protect accounts from credential theft, while strictly limited permissions and independent reviews can limit changes authorized accounts can make.
CryptoSlate reported on July 5 that during the first half of 2026, operational-level attacks related to keys, custody, signing, and approval systems accounted for about 76% of stolen funds, despite the more frequent occurrence of smart contract vulnerabilities. This gap illustrates why access and operational controls are crucial, even if they result in fewer incidents.
Wallet and protocol teams should view contractor access as an ongoing conditional privilege. Identity checks should be in place throughout the employment period, third-party companies should be subject to audits, codebase permissions should remain narrow and observable, changes in each production environment should undergo independent review, and access should be revoked immediately when no longer needed.
Consensys’s suspension of releases in April also demonstrates the value of retaining predefined methods to pause changes for use when investigating suspicious access.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。