星球日报
星球日报|Jul 20, 2026 05:30
[MetaMask Team Infiltrated by North Korean Hacker Follow-Up: Hacker's Identity Publicly Disclosed in September 2025, Yet Circumvented Background Checks via Outsourcing to Join MetaMask in March This Year] Odaily Planet Daily News — According to DeFi researcher @Zun2025's post on the X platform, 'MetaMask hired a hacker associated with DPRK as a developer without conducting proper background checks. They could have uncovered his identity. The hacker's GitHub account is imyugioh, and he has been publicly listed on the Lazarus Group website since September 2025. Yet, MetaMask still hired this individual in March 2026. Source: lazarus.group/team/mauro-liu. Imagine, one of the largest wallet providers granting access to its core code repository to someone already publicly listed on a DPRK hacker roster. Now think about what could happen to smaller protocols without any security teams at all.' Earlier reports revealed that the MetaMask team was infiltrated by a North Korean hacker named Tyler Knapp, who joined MetaMask via a long-term HR supplier in an outsourcing arrangement, bypassing the company's direct recruitment background checks. He worked at the company for a month and participated in the development of the wallet's fiat on/off-ramp functionality. During this period, abnormal IP activity and behavior flagged by the company's security monitoring led to the discovery of his identity. The company immediately revoked all his access permissions and suspended all product releases he was involved in. No substantial data or financial losses have occurred as of now.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads