A contractor linked to North Korea had access to MetaMask's codebase for about a month before Consensys cut off access in April. The company's investigation found no misappropriation of assets or data, no malicious code deployment, and no impact to user safety or security. But the incident — first reported by Drop Site — underscores how hard it is to keep bad actors out of crypto's software supply chain.
How the breach happened
The contractor was brought in through a third-party provider. Consensys later described the person as linked to North Korea. The access window ran from March 9 until the company terminated it in April. General counsel Matt Corva said Consensys identified the threat quickly, terminated access, launched a comprehensive investigation, and notified law enforcement. He called the service provider relationship reputable and said Consensys has since reviewed its third-party service practices to apply rigorous standards to outside relationships.
An internal April alert, obtained by Drop Site, ordered all product releases suspended pending the investigation and told staff not to interact with the consultant. That pause shows the value of having a predefined way to halt changes while suspicious access is investigated.
What was at risk
MetaMask's own security guidance warns that malicious workers can use false identities and forged documents to obtain remote roles. It recommends checks including document verification, multiple interviews, hardware authentication, IP/location verification, reference checks, and access limits. The FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories. The bureau recommends identity verification, audits of third-party staffing firms, least-privilege access, and monitoring for unusual connections or exfiltration.
In this case, none of that worst-case scenario materialized. Consensys said there was no indication that user accounts or wallet assets were compromised. Still, the access period — roughly a month — is long enough to cause concern.
Industry lessons
The incident fits a broader pattern. CryptoSlate reported that operational compromises around keys, custody, signing, and approval systems accounted for roughly 76% of stolen value during the first half of 2026, even though smart-contract exploits were more frequent. Wallet and protocol teams, the report recommends, should treat contractor access as continuously conditional, with identity checks, audits, narrow privileges, independent review, and quick revocation.
The UK National Cyber Security Center guidance recommends making repository activity attributable, reviewing every production-bound change, applying extra scrutiny to external contributions, and revoking access quickly when no longer required. Consensys's response — quick termination, a release pause, and a review of third-party practices — tracks with those recommendations.
The question now is whether other crypto firms are doing the same. The FBI and NCSC have been warning about North Korean IT infiltration for years. This incident shows the warnings aren't abstract.



