Consensys halted all MetaMask product releases early this year after discovering a contractor linked to North Korea had access to key wallet code for about a month. The involvement came from a third-party contractor contributing to MetaMask code from March 9 until April, when Consensys revoked all access and suspended updates.
Contractor Access and Investigation Findings
Consensys engaged the contractor through an external staffing firm, not via direct hiring. This person worked on core MetaMask components, including critical sections connected to third-party fiat payment integrations. Despite initial concerns, Consensys reported no evidence of asset theft, data breaches, or insertion of malicious code during the contractor's tenure.
The company’s general counsel, Matt Corva, confirmed a rapid response: terminating the contract, investigating internally, and notifying law enforcement agencies. An internal alert in April prompted a freeze on all new product releases while the probe was active, also instructing employees to avoid communication with this external contractor.
Implications for Third-Party Staffing and Security Practices
While the third-party provider was considered reputable, Consensys reassessed its staffing policies, aiming to impose equivalent security standards on contractors as on direct employees. The incident underscored vulnerabilities in how complex outside relationships are managed, particularly with remote workers who may come from higher-risk jurisdictions.
This episode did not compromise user wallets or assets but highlighted the necessity for improved identity verification and stricter access controls throughout the development pipeline.
Part of Broader North Korean Cyber Operations
The contractor’s background fits a known pattern of North Korean cyber operatives infiltrating technology and cryptocurrency firms under false identities. The FBI has warned that such actors frequently gain network access to copy code repositories or conduct espionage. It urges companies to implement thorough identity checks, conduct audits of third-party staffing firms, and enforce least-privilege access principles.
According to TRM Labs, North Korea was responsible for approximately 64 percent of cryptocurrency thefts recorded in 2025, a year with losses exceeding $2.7 billion. This incident at Consensys reflects these ongoing risks in the crypto industry.
This material is for informational purposes and does not constitute financial advice.



