Original |Odaily Planet Daily(@OdailyChina)
Author|Golem(@web3_golem)

Last week, MetaMask just celebrated its 10th anniversary, and a "security scandal" was exposed by the media that involved the accidental hiring of a North Korean hacker.
On July 17, according to internal Slack records from Consensys obtained by Drop Site News, a North Korean hacker using the fake identity "Tyler Knapp" (GitHub account imyugioh) was hired as a consultant through a third-party human resource provider long partnered with Consensys on March 9, 2026. The internal records show that this North Korean hacker was not involved in marginal projects, but had access to the core wallet code of MetaMask and participated in the development of the wallet's fiat deposit and withdrawal functions.
Imagine if this North Korean hacker had tampered with the deposit and withdrawal operations of MetaMask, then the assets of tens of millions of users would be under threat. Fortunately, this disaster was not discovered. Just one month after the North Korean hacker started working at the company, the internal security department of Consensys detected anomalies. Ultimately, after the investigation verified that Tyler Knapp's true identity was a North Korean hacker, all his internal access rights were immediately terminated, and law enforcement was contacted.
Consensys' General Counsel Matt Corva stated that after announcing an investigation into Tyler Knapp throughout the company, he ordered an immediate suspension of all product releases for MetaMask and urged everyone to keep this matter confidential and not to contact this individual.
Although this security incident did not result in the loss of user assets or data, Matt Corva has not disclosed how they ultimately determined that Tyler Knapp was connected to the North Korean hacker organization.
Has the Consensys recruitment process been infiltrated by hackers?
The question arises, why was the North Korean hacker able to easily bypass Consensys’s background checks during recruitment?
Matt Corva's explanation was, "We learned about 'Knapp' through our existing relationship with a reputable third-party service provider," but this clearly does not justify Consensys's failure to conduct detailed background checks on applicants. What’s even more absurd is that Consensys may not have conducted even a simple check on Tyler Knapp during the recruitment process, as Tyler Knapp did not hide his North Korean hacker identity very deeply, and an ordinary person could discover it simply by asking an AI.
According to DeFi researcher @Zun2025 on the X platform, the North Korean hacker's GitHub account is imyugioh, and since September 2025, he has been publicly listed on the Lazarus Group hacker list, with the real name Mauro Liu. (Odaily: Lazarus Group is North Korea's largest hacking organization, and the 1.5 billion USD theft from Bybit in 2025 was also attributed to Lazarus Group)

The North Korean hacker imyugioh, real name Mauro Liu
Consensys is unwilling to disclose how it determined Tyler Knapp's connection to the North Korean hacker organization, perhaps out of fear of exposing flaws in the company’s recruitment process.
Afterward, Matt Corva defended himself by stating that the company has initiated a review of its engineering and development outsourcing practices, saying, "We reviewed all third-party services (including existing relationships) to ensure that the strict standards applicable to all employees also apply to more complex third-party relationships."
Ironically, MetaMask's security chief Taylor Monahan had previously been paying attention to the infiltration of North Korean hackers into the recruitment processes of Web3 companies. She had stated that North Korean IT specialists had been actively involved in DeFi projects and contributing to well-known protocols, and their entry into DeFi/Web3 companies was not an isolated case but had been ongoing for at least seven years, with previously affected projects including SushiSwap, THORChain, Fantom, Shiba Inu, Yearn Finance, and Floki, and now also including their own.
As MetaMask's security chief who has long been focused on North Korean hackers, Taylor Monahan did not express any opinions on the accidental hiring of a North Korean hacker by MateMask on the X platform. Although this incident falls under "successful penetration of the recruitment process, but unsuccessful in executing an attack," it still exposed the overall state of negligence in MetaMask's internal security, which is completely inconsistent with the image they project externally—such an important product module for developing the fiat deposit and withdrawal functions of the wallet, yet MetaMask allowed an outsourced personnel to access the core code.
Even large crypto companies like Consensys, despite having a well-established code auditing system, can often be more vulnerable in recruitment and outsourcing reviews due to their size, particularly in the hiring process, where they can be more easily breached by hackers.
North Korean hackers disguising as employees for attacks has become the easiest method
In the past year, with improvements in AI capabilities and coding, many are concerned that hackers could exploit AI to find protocol vulnerabilities and execute attacks. However, contrary to common sense, historical data shows that for large companies, social engineering attacks have proven to be the easiest way for North Korean hackers to gain access and steal funds.
Compared to launching external technical attacks, infiltrating recruitment chains or disguising as company applicants is even less costly for hacker organizations. On-chain detective ZachXBT once stated that many of the infiltration methods used by North Korea's largest hacking organization, Lazarus Group, are surprisingly simple, such as posting job advertisements, contacting via LinkedIn, sending direct messages, and conducting Zoom calls and interviews. The advantage of this method is its persistence and ability to "cast a wide net."
Moreover, this attack method displays a cost asymmetry; North Korean hackers can almost change their identity at zero cost, while for large crypto companies that support remote work, third-party outsourcing, and open-source collaboration, continuous identity verification and reviews are a high-cost expenditure requiring substantial human and material resources.
Many crypto enterprises are not as fortunate as MetaMask, which managed to identify an "insider" before a theft occurred.
In April 2026, North Korean hackers spent six months infiltrating Drift Protocol, acquiring internal permissions through false recruitment/cooperation, resulting in the theft of approximately $285 million of user assets; an earlier case saw North Korean hackers gaining access to Bitcoin DMM exchange through recruitment, stealing approximately $308 million after obtaining internal access; in 2022, North Korean hackers masqueraded as blockchain game developers and entered Ronin Network, leading to the direct theft of approximately $620 million from the Ronin bridge, making it one of the largest crypto hacking events in history at that time.
MetaMask narrowly escaped one incident but did not avoid a warning. For today's crypto industry, the greatest security risk may no longer lie in the code but beyond it. The security boundaries of blockchain have long extended from on-chain to the real world; code can be audited repeatedly, contracts can be upgraded constantly, but identities are exceptionally difficult to verify. In the past, it was believed that smart contracts were the weakest link in the crypto industry; nowadays, it appears that the truly difficult-to-defend aspects are management processes and the people behind those processes.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。