Back Kucoin MetaMask developer accidentally hired a North Korean hacker for one month
According to ME News, on July 19 (UTC+8), ConsenSys, the developer of MetaMask, discovered that a North Korean hacker had infiltrated the MetaMask team under a false identity for approximately one month and participated in the development of core wallet code. The individual used the name "Tyler Knapp," joined as a contractor in an advisory role, and operated under the GitHub username imyugioh, with code commits spanning from March 9 to April. Some of the code contributed by this individual involved transfers between crypto assets and fiat currencies. Upon identifying the risk, ConsenSys immediately revoked the individual’s access, instructed staff to halt product releases and avoid all with the individual, and reported the incident to law enforcement. Matt Corva, ConsenSys’s General Counsel, stated that investigations confirmed no assets or data were compromised, no malicious code was deployed, and user funds and security remained unaffected. The company is currently reviewing its contractor background verification processes. TRM Labs noted that developers’ work environments have become a critical entry point for attackers seeking to obtain encryption keys and withdrawal approval systems from crypto companies. Previously, an Ethereum-funded project identified 100 suspected North Korean IT professionals across 53 crypto projects. (Source: BlockBeats)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
