Loading market data...

Consensys Halts MetaMask Releases After Contractor With North Korea Ties Accessed Code

Consensys Halts MetaMask Releases After Contractor With North Korea Ties Accessed Code

Consensys suspended all MetaMask product releases earlier this year after discovering that a contractor with links to North Korea had access to the wallet's source code for roughly a month. The contractor was brought in through a third-party service provider, not through Consensys' direct hiring process.

The access window

The contractor's access to MetaMask's code lasted about a month. Consensys did not say when exactly the access occurred or what parts of the code the contractor could view or modify. The company declined to describe the specific work the contractor was hired to do.

How the contractor got in

Instead of vetting workers directly, Consensys relied on a third-party service provider to bring in the contractor. That arrangement meant the company's own security checks didn't catch the individual's ties to North Korea before access was granted. It's not clear whether the third-party provider performed any background checks at all.

The fallout

MetaMask is one of the most widely used crypto wallets, with millions of active users. The suspension of product releases means no new features, updates, or bug fixes have been shipped to MetaMask users since the discovery. Consensys has not said when it will resume releases or what security changes it has made in response.

The company has also not disclosed whether the contractor actually exfiltrated any code, introduced backdoors, or tampered with the wallet's software. Investigations are ongoing, but no public findings have been released.

Consensys is now reviewing its third-party contractor vetting procedures. The company has not set a timeline for reinstating MetaMask product updates. Users are left with the current version of the wallet, and the question of whether the contractor's access led to any compromise of the code remains unanswered.