BTC
ETH
HTX
SOL
BNB
ดูตลาด
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

นี่คือผลลัพธ์การแปลตามที่คุณต้องการ: That was close! An outsourced employee nearly destroyed MetaMask

golem
Odaily资深作者
@web3_golem
2026-07-20 09:53
บทความนี้มีประมาณ 2665 คำ การอ่านทั้งหมดใช้เวลาประมาณ 4 นาที
MetaMask has long warned about North Korean hackers, never expecting to be the one caught in the crossfire.
สรุปโดย AI
ขยาย
  • Core Insight: Consensys (the parent company of MetaMask) accidentally hired a North Korean hacker in March 2026. This hacker participated in the development of the MetaMask wallet's core code and fiat on-ramp/off-ramp functions, exposing serious security vulnerabilities in the hiring and third-party outsourcing review processes of major crypto companies.
  • Key Elements:
    1. The North Korean hacker used the false identity "Tyler Knapp" (GitHub: imyugioh) and was hired by Consensys as a consultant through a third-party human resources vendor in March 2026, gaining access to the core MetaMask wallet code.
    2. One month after the hacker started, Consensys's internal security department discovered and terminated their access, with no loss of user assets. However, Consensys did not disclose how it identified the hacker, and the hacker's GitHub account had already been publicly listed on a Lazarus Group hacker watchlist as early as September 2025.
    3. MetaMask Security Lead Taylor Monahan has long warned about North Korean hackers infiltrating recruitment processes. Affected projects include SushiSwap, THORChain, Ronin, and this incident has now implicated MetaMask itself.
    4. Social engineering attacks (such as infiltrating recruitment, posing as job applicants) are the easiest method for North Korean hackers to execute and yield the largest stolen funds, characterized by low cost and high persistence, whereas company identity verification is expensive.
    5. Recent cases include Drift Protocol losing approximately $285 million in 2026 due to a fake hire, DMM exchange losing approximately $308 million in 2024, and the Ronin bridge hack in 2022 losing approximately $620 million, all linked to North Korean hackers infiltrating through recruitment.

Original |Odaily Planet Daily(@OdailyChina

Author|Golem(@web3_golem)

Last week, MetaMask just celebrated its 10th anniversary when media reported a "security scandal" involving the accidental hiring of a North Korean hacker.

On July 17, according to Consensys internal Slack records obtained by Drop Site News, a North Korean hacker using the fake identity "Tyler Knapp" (GitHub account imyugioh) was hired as a consultant on March 9, 2026, through a third-party HR provider that Consensys has long cooperated with. Internal records show that this North Korean hacker was not working on peripheral projects, but had access to MetaMask's core wallet code and participated in developing the fiat on/off ramp functionality for the wallet.

Imagine if this North Korean hacker had tampered with MetaMask's fiat on/off ramp process, the assets of tens of millions of users would have been under threat. Fortunately, such a disaster did not materialize. One month after the North Korean hacker joined the company, Consensys' internal security department detected the anomaly. Ultimately, Consensys' investigation determined that Tyler Knapp's true identity was a North Korean hacker, immediately terminated all his internal access permissions, and contacted law enforcement.

Matt Corva, Consensys' General Counsel, stated that after launching a company-wide investigation into Tyler Knapp, he ordered an immediate halt to all MetaMask product releases, pleaded with everyone to keep the matter confidential, and instructed them not to engage with this individual.

Although this security incident did not result in loss of user assets or data, Matt Corva never disclosed how they ultimately concluded that Tyler Knapp was linked to a North Korean hacking organization.

Has the Consensys Recruitment Process Been Infiltrated by Hackers?

The question arises: how could a North Korean hacker so easily bypass Consensys' background checks during recruitment?

Matt Corva's explanation was, "We learned about 'Knapp' through an existing relationship with a reputable third-party service provider," but this clearly does not excuse Consensys from conducting thorough due diligence on applicants. More absurdly, Consensys may not have even performed a simple review of Tyler Knapp during the hiring process, as Tyler Knapp did not hide his North Korean hacker identity very well—even an ordinary person asking an AI could have discovered it.

According to a post on X by DeFi researcher @Zun2025, this North Korean hacker's GitHub account is imyugioh, and he has been publicly listed on the Lazarus Group hacker list since September 2025, with his real name being Mauro Liu. (Odaily: Lazarus Group is North Korea's largest hacking organization, and the $1.5 billion theft from Bybit in 2025 was also attributed to the Lazarus Group.)

Image

North Korean hacker imyugioh, real name Mauro Liu

Consensys' unwillingness to disclose the real reason for identifying Tyler Knapp's connection to a North Korean hacking organization may be driven by a fear of exposing vulnerabilities in the company's recruitment process.

Matt Corva later defended the company by stating that it had initiated a review of its outsourcing practices for engineering and development work. "We reviewed all third-party services (including existing partnerships) to ensure that the strict standards we apply to all employees also apply to more complex third-party relationships."

More ironically, Taylor Monahan, MetaMask's Head of Security, has long been monitoring the infiltration of Web3 company recruitment processes by North Korean hackers. She has stated that North Korean IT experts have been actively participating in DeFi projects and contributing to well-known protocols for at least seven years. Affected projects previously included SushiSwap, THORChain, Fantom, Shiba Inu, Yearn Finance, and Floki—and now includes their own.

As a long-time observer of North Korean hackers, Taylor Monahan has not commented on this MetaMask incident on X. Although this event represents a "successful infiltration of the recruitment process without a successful attack execution," it still exposes an overall state of security negligence within MetaMask, starkly contrasting with the image they project externally—allowing an outsourced contractor to access the core code for a critical product module like the fiat on/off ramp feature.

Large crypto companies like Consensys, despite possessing comprehensive code audit systems, are often more vulnerable than smaller teams in terms of recruitment and outsourced personnel review due to their size, particularly making them more susceptible to breaches in the hiring process.

Hackers Disguising as Employees Has Become the Easiest Attack Vector

In the past year, with continuous improvements in AI intelligence and coding capabilities, many have feared that hackers could exploit protocol vulnerabilities using AI. However, counter-intuitively, social engineering attacks have historically been the easiest and most lucrative method for North Korean hackers targeting large companies.

Compared to launching external technical attacks, infiltrating the recruitment pipeline or posing as a job applicant is even lower cost for hacker organizations. On-chain detective ZachXBT has stated that many infiltration methods used by the Lazarus Group are surprisingly simple, such as posting job openings, connecting via LinkedIn, sending direct messages, conducting Zoom calls, and interviews. The advantage of this method is its persistence and the ability to "cast a wide net."

Furthermore, this attack vector also features cost asymmetry. North Korean hackers can create new identities at nearly zero cost, but for large crypto companies supporting remote work, third-party outsourcing, and open-source collaboration, continuous identity verification and background checks are a high-cost endeavor requiring significant manpower and resources.

Many crypto enterprises were not as fortunate as MetaMask in identifying the "insider threat" before a theft occurred.

In April 2026, North Korean hackers spent six months infiltrating Drift Protocol, securing internal permissions through fake recruitment/partnerships, resulting in the theft of approximately $285 million in user assets. In an earlier case, in 2024, a North Korean hacker entered the Bitcoin DMM exchange through recruitment, obtaining internal access and stealing around $308 million. In 2022, a North Korean hacker disguised as a blockchain game developer joined Ronin Network, ultimately leading to the theft of approximately $620 million from the Ronin Bridge, one of the largest crypto hacks in history at the time.

MetaMask narrowly escaped one incident, but failed to escape the warning it represents. For today's crypto industry, the greatest security risk may no longer lie in code, but outside of it. The security boundary of blockchain has long extended from on-chain to the real world. Code can be repeatedly audited, and contracts can be continuously upgraded, but identity remains difficult to verify. In the past, people often considered smart contracts the weakest link in the crypto industry. Now it seems that what is truly difficult to defend against is always the management process and the people within that process.

กระเป๋าสตางค์
ความปลอดภัย
บล็อกเชน
DeFi
ยินดีต้อนรับเข้าร่วมชุมชนทางการของ Odaily
กลุ่มสมาชิก
https://t.me/Odaily_News
กลุ่มสนทนา
https://t.me/Odaily_GoldenApe
บัญชีทางการ
https://twitter.com/OdailyChina
กลุ่มสนทนา
https://t.me/Odaily_CryptoPunk
ค้นหา
สารบัญบทความ
ดาวน์โหลดแอพ Odaily พลาเน็ตเดลี่
ให้คนบางกลุ่มเข้าใจ Web3.0 ก่อน
IOS
Android