That was close! A hired third-party contractor nearly destroyed MetaMask
- Core Insight: In March 2026, Consensys (the parent company of MetaMask) unknowingly hired a North Korean hacker. This hacker was involved in the development of MetaMask wallet’s core code and fiat on/off ramp functions, exposing serious security vulnerabilities in the recruitment and third-party contractor review processes of large crypto companies.
- Key Elements:
- The North Korean hacker used the fake identity “Tyler Knapp” (GitHub: imyugioh) and was hired by Consensys through a third-party HR provider in March 2026 as a consultant, gaining access to the core code of the MetaMask wallet.
- One month after starting, the hacker was discovered by Consensys’ internal security team and their access was revoked. No user funds were lost. However, Consensys has not disclosed how it identified the hacker, and the hacker’s GitHub account had been publicly listed on a Lazarus Group hacker watchlist as early as September 2025.
- MetaMask’s Head of Security, Taylor Monahan, has long warned about North Korean hackers infiltrating recruitment processes. Affected projects include SushiSwap, THORChain, Ronin, and now, this incident also involves MetaMask itself.
- Social engineering attacks (such as infiltrating recruitment and posing as job applicants) are the easiest and most lucrative method for North Korean hackers. These attacks are low-cost, highly persistent, while company identity verification is expensive.
- Recent cases: In 2026, Drift Protocol lost approximately $285 million due to a fake job offer; in 2024, DMM Exchange lost approximately $308 million; and in 2022, the Ronin bridge was hacked for approximately $620 million. All of these incidents were linked to North Korean hackers infiltrating via recruitment processes.
Original by Odaily (`@OdailyChina`)
Author: Golem (`@web3_golem`)

Last week, just after MetaMask celebrated its 10th anniversary, the media broke a "security scandal" about the company accidentally hiring a North Korean hacker.
On July 17, according to internal Slack records from Consensys obtained by Drop Site News, a North Korean hacker using the fake identity "Tyler Knapp" (GitHub account imyugioh) was hired as a consultant on March 9, 2026, through a third-party HR vendor that Consensys has a long-term partnership with. Internal records show that this North Korean hacker was not involved in a peripheral project but had access to the core MetaMask wallet code and participated in developing the wallet's fiat on-ramp and off-ramp functionality.
Imagine if this North Korean hacker had tampered with MetaMask's fiat gateway, the assets of tens of millions of users would have been threatened. Fortunately, this disaster did not occur. One month after the hacker joined the company, Consensys's internal security department detected the anomaly. After Consensys's investigation concluded that Tyler Knapp’s true identity was a North Korean hacker, it immediately revoked all his internal access and contacted law enforcement.
Matt Corva, General Counsel at Consensys, stated that after initiating a company-wide investigation into Tyler Knapp, he ordered an immediate halt to all MetaMask product releases, pleaded with everyone to keep the matter confidential, and instructed them not to contact this individual.
Although this security incident did not result in user asset or data loss, Matt Corva never disclosed how they ultimately determined Tyler Knapp's connection to the North Korean hacker group.
Has the Consensys Recruitment Process Been Infiltrated by Hackers?
The question remains: how could a North Korean hacker so easily bypass Consensys’s recruitment background checks?
Matt Corva’s explanation was, "We became aware of 'Knapp' through an existing relationship with a reputable third-party service provider." However, this clearly cannot justify Consensys’s failure to conduct a thorough background check on the applicant. More absurdly, Consensys may not have performed even a simple review of Tyler Knapp during the recruitment process, as Knapp did not go to great lengths to conceal his North Korean hacker identity. An ordinary person could have discovered it by asking an AI.
According to a post on X by DeFi researcher @Zun2025, the North Korean hacker's GitHub account is imyugioh. He has been publicly listed on the Lazarus Group hacker roster since September 2025, under his real name, Mauro Liu. (Odaily: Lazarus Group is North Korea's largest hacking group. The $1.5 billion theft from Bybit in 2025 was also attributed to Lazarus Group.)

North Korean hacker imyugioh, real name Mauro Liu
Consensys is reluctant to reveal the true reasons for identifying Tyler Knapp's connection to the North Korean hacker group, likely fearing it would expose vulnerabilities in the company's recruitment process.
Matt Corva later defended the company, stating that it had initiated a review of its engineering and development outsourcing practices. "We are reviewing all third-party services, including existing relationships, to ensure the same rigorous standards we apply to all employees are also applied to our more complex third-party partnerships."
More ironically, MetaMask's Head of Security, Taylor Monahan, had been focusing on North Korean hackers' infiltration of Web3 company recruitment processes. She previously stated that North Korean IT professionals have been actively participating in DeFi projects and contributing to well-known protocols for at least seven years. Affected projects include SushiSwap, THORChain, Fantom, Shiba Inu, Yearn Finance, and Floki, now adding MetaMask itself to the list.
As a long-time observer of North Korean hackers, Taylor Monahan has not commented on X about MetaMask accidentally hiring one. Although this incident was a "successful infiltration of the recruitment process without a successful attack," it still exposed the overall state of security negligence within MetaMask, which starkly contrasts with the image it projects externally—allowing an outsourced contractor to access core code for such a critical product module as the wallet's fiat gateway.
Even large crypto companies like Consensys, possessing comprehensive code audit systems, are often more vulnerable than smaller teams in recruitment and outsourcing checks due to their size, making the recruitment link particularly susceptible to hackers.
North Korean Hackers Disguising as Employees Has Become the Easiest Attack Vector
Over the past year, with the continuous improvement of AI intelligence and coding capabilities, many worry that hackers could use AI to find protocol vulnerabilities and execute attacks. Counter-intuitively, however, history shows that for large companies, social engineering attacks are the easiest and most lucrative method for North Korean hackers.
Compared to launching external technical attacks, infiltrating the recruitment pipeline or posing as job applicants is a lower-cost strategy for hacker groups. On-chain detective ZachXBT has noted that many infiltration methods used by Lazarus Group, the largest North Korean hacking group, are surprisingly simple. Examples include posting job openings, contacting targets via LinkedIn, sending direct messages, holding Zoom calls, and conducting interviews. This method offers persistence and allows for a "broad net" approach.
Furthermore, this attack method presents a cost asymmetry. North Korean hackers can create new identities with almost zero cost, whereas for large crypto companies supporting remote work, third-party outsourcing, and open-source collaboration, maintaining continuous identity verification and background checks is a high-cost endeavor requiring significant manpower and resources.
Many crypto enterprises were not as fortunate as MetaMask and managed to identify the "insider" before any theft occurred.
In April 2026, a North Korean hacker spent six months infiltrating Drift Protocol, obtaining internal permissions through fake recruitment/partnerships, resulting in the theft of approximately $285 million in user assets. In an earlier case in 2024, a North Korean hacker infiltrated the Bitcoin DMM exchange through recruitment, gaining internal access and stealing approximately $308 million. In 2022, a North Korean hacker disguised as a blockchain game developer entered the Ronin Network company, directly leading to the theft of approximately $620 million from the Ronin bridge, one of the largest crypto hacks in history at that time.
MetaMask narrowly avoided an incident, but it did not miss a warning. For today's crypto industry, the greatest security risk may no longer lie in the code, but beyond it. The security boundary of blockchain has long extended from on-chain to the real world. Code can be repeatedly audited, contracts can be continuously upgraded, but identity remains difficult to verify. In the past, people thought smart contracts were the weakest link in the crypto industry. Now, it seems that what is truly difficult to defend against is always the management process, and the people behind it.


