BTC
ETH
HTX
SOL
BNB
查看行情
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

That was close! An outsourced employee almost destroyed MetaMask

golem
Odaily资深作者
@web3_golem
2026-07-20 09:53
本文約2665字,閱讀全文需要約4分鐘
MetaMask has long warned about North Korean hackers, never expecting to be caught in its own net.
AI總結
展開
  • Core Takeaway: In March 2026, Consensys (MetaMask's parent company) accidentally hired a North Korean hacker, who participated in the development of MetaMask wallet core code and fiat on/off-ramp features, exposing serious security vulnerabilities in the hiring and third-party outsourcing review processes of major crypto companies.
  • Key Details:
    1. The North Korean hacker used a fake identity, "Tyler Knapp" (GitHub: imyugioh), and was hired by Consensys as a consultant in March 2026 through a third-party human resources provider, gaining access to MetaMask's core wallet code.
    2. The hacker was discovered by Consensys' internal security department one month after starting and had their access terminated, with no user assets lost; however, Consensys did not disclose how the identity was confirmed, and their GitHub account had already been publicly listed on a Lazarus Group hacker watchlist as early as September 2025.
    3. MetaMask Security Lead Taylor Monahan has long warned about North Korean hackers infiltrating hiring processes, with affected projects including SushiSwap, THORChain, Ronin, etc. This incident has now involved MetaMask itself.
    4. Social engineering attacks (such as infiltrating recruitment, posing as job applicants) are the most successful method for North Korean hackers, often resulting in the largest fund thefts, with low cost and high persistence, while corporate identity verification is costly.
    5. Recent cases: the Drift Protocol incident in 2026 (loss of ~$285 million due to fake hiring), the DMM exchange incident in 2024 (loss of ~$308 million), and the Ronin bridge hack in 2022 (loss of ~$620 million) were all linked to North Korean hackers infiltrating through recruitment.

Original | Odaily (@OdailyChina)

Author | Golem (@web3_golem)

Last week, just after MetaMask celebrated its 10th anniversary, the media reported a "security scandal" revealing that it had accidentally hired a North Korean hacker.

On July 17, according to internal Slack records from Consensys obtained by Drop Site News, a North Korean hacker using the fake identity "Tyler Knapp" (GitHub account imyugioh) was hired as a consultant on March 9, 2026, through a third-party HR provider with which Consensys had a long-standing partnership. Internal records show that this North Korean hacker was not involved in peripheral projects but had access to MetaMask's core wallet code and participated in the development of the wallet's fiat on-ramp/off-ramp features.

Imagine if this North Korean hacker had tampered with MetaMask's fiat on-ramp/off-ramp process; the assets of tens of millions of users would have been at risk. Fortunately, such a disaster did not occur. One month after the hacker joined the company, Consensys's internal security department detected an anomaly. Ultimately, after Consensys's investigation confirmed that Tyler Knapp's true identity was a North Korean hacker, they immediately terminated all his internal access and contacted law enforcement.

Matt Corva, General Counsel at Consensys, stated that after launching an investigation into Tyler Knapp company-wide, he ordered an immediate halt to all MetaMask product releases, implored everyone to keep the matter confidential, and to avoid contact with this individual.

Although this security incident resulted in no loss of user assets or data, Matt Corva never revealed exactly how they ultimately linked Tyler Knapp to the North Korean hacking group.

Has the Consensys recruitment process been infiltrated by hackers?

The question arises: why was a North Korean hacker able to so easily bypass Consensys's background checks during recruitment?

Matt Corva's explanation was, "We learned about 'Knapp' through an existing partnership with a reputable third-party service provider." However, this clearly cannot excuse Consensys from failing to conduct a detailed background check on the applicant. Even more absurdly, Consensys may not have performed even a simple review of Tyler Knapp during the hiring process, as the hacker's identity as a North Korean was not deeply hidden; an ordinary person asking an AI could have discovered it.

According to a post on X by DeFi researcher @Zun2025, the North Korean hacker's GitHub account is imyugioh, and since September 2025, he has been publicly listed on the Lazarus Group  hacker list, with his real name being Mauro Liu. (Odaily: The Lazarus Group is North Korea's largest hacking organization. The $1.5 billion theft from Bybit in 2025 was also attributed to the Lazarus Group.)

image

North Korean hacker imyugioh, real name Mauro Liu

Consensys's reluctance to disclose the real reason for linking Tyler Knapp to the North Korean hacking group might stem from a fear of exposing vulnerabilities in the company's recruitment process.

Matt Corva later defended the company, stating that it had initiated a review of its engineering and development outsourcing practices. "We reviewed all third-party services (including existing partnerships) to ensure that the strict standards applied to all employees are also applied to more complex third-party relationships."

Even more ironically, Taylor Monahan, MetaMask's Head of Security, had been closely monitoring the infiltration of Web3 company recruitment processes by North Korean hackers. She previously stated that North Korean IT specialists have been actively participating in DeFi projects and contributing to well-known protocols for at least seven years. Previously affected projects include SushiSwap, THORChain, Fantom, Shiba Inu, Yearn Finance, and Floki, and now their own company has been added to the list.

As MetaMask's Head of Security, who has long focused on North Korean hackers, Taylor Monahan did not comment on X about MetaMask's accidental hiring of one. Although this incident was a "successful infiltration of the recruitment process without a successful attack," it exposed an overall state of security negligence within MetaMask, starkly contrasting with the image they project externally—allowing an outsourced contractor to access the core code for developing such a critical product module as the wallet's fiat on-ramp/off-ramp.

Large crypto companies like Consensys, even with robust code audit systems, are often more vulnerable than smaller teams in recruitment and outsourcing review due to their size, especially during the hiring process, making them easier targets for hackers.

North Korean hackers using fake employee identities has become the easiest method of attack

In the past year, with the increasing capabilities of AI and code generation, many feared that hackers could use AI to find protocol vulnerabilities and successfully attack. Counterintuitively, historically, social engineering attacks have been the easiest and most lucrative method for North Korean hackers targeting large companies.

Compared to launching external technical attacks, infiltrating the recruitment chain or posing as job applicants is a lower-cost strategy for hacking groups. On-chain detective ZachXBT has noted that many infiltration methods of the Lazarus Group, North Korea's largest hacking organization, are surprisingly simple, such as posting job ads, contacting through LinkedIn, sending direct messages, and conducting Zoom calls and interviews. The advantage of this method is its persistence and ability to "cast a wide net."

Furthermore, this attack method has an asymmetric cost structure. North Korean hackers can assume new identities at almost zero cost. However, for large crypto companies supporting remote work, third-party outsourcing, and open-source collaboration, continuous identity verification and background checks are a high-cost endeavor requiring significant manpower and resources.

Many crypto companies have not been as fortunate as MetaMask in identifying the "insider" before a theft occurs.

In April 2026, North Korean hackers spent six months infiltrating Drift Protocol, obtaining internal permissions through fake recruitment/partnerships, resulting in the theft of approximately $285 million in user assets. In an earlier case, in 2024, North Korean hackers infiltrated the Bitcoin DMM exchange via recruitment, stealing approximately $308 million after gaining internal access. In 2022, North Korean hackers disguised as a blockchain game developer infiltrated Ronin Network, directly leading to the theft of approximately $620 million from the Ronin Bridge, one of the largest crypto hacks in history at the time.

MetaMask narrowly avoided one incident, but it cannot ignore the warning. For today's crypto industry, the greatest security risk may no longer be in the code, but beyond it. The security boundary of blockchain has long extended from on-chain to the real world. Code can be repeatedly audited, contracts can be continuously upgraded, but identities are difficult to verify. In the past, people always believed smart contracts were the weakest link in the crypto industry. Now, it seems that what is truly difficult to defend against is always the management process, and the people behind the process.

錢包
安全
區塊鏈
DeFi
歡迎加入Odaily官方社群