
A contractor brought in through a third-party provider worked on MetaMask code from March until Consensys cut off access in April and paused product releases. The company says it found no stolen assets, exposed data or malicious code.
Ethereum software firm Consensys suspended MetaMask product releases earlier this year after discovering that a contractor with links to North Korea had access to the wallet’s code for roughly a month.
The contractor, brought in through a third-party service provider rather than Consensys’ direct hiring channel, made MetaMask-related code contributions from March 9 until the company terminated access in April, according to reporting by Drop Site News and statements from Consensys. The work touched core MetaMask code, including sections used to connect users with third-party fiat payment providers.
Consensys said its investigation found no misappropriation of assets or data, no deployment of malicious code, and no impact to user safety or security. General counsel Matt Corva said the company identified the threat quickly, terminated the access, launched an investigation and notified law enforcement.
An Internal Alert and a Release Freeze
Drop Site reported that an internal alert in April ordered all product releases suspended pending the investigation and instructed staff not to interact with the consultant.
Corva described the service provider relationship as “reputable” and said Consensys has since reviewed its third-party staffing practices so that the standards applied to employees also extend to more complex outside relationships. The company said the episode gave no indication that user accounts or wallet assets were compromised.
Part of a Wider Infiltration Campaign
The incident reflects a documented pattern of North Korean IT workers seeking remote roles at technology and crypto firms under false identities. The FBI has warned that such operatives have used company-network access to copy code repositories, and has urged identity verification throughout employment, audits of third-party staffing firms, and least-privilege access controls.
North Korea accounted for an estimated 64% of the value stolen in crypto hacks in 2025, a year in which total losses exceeded $2.7 billion, according to TRM Labs.