Skip to content
North Korean Hacker Infiltrates MetaMask Team as Contractor

North Korean Hacker Infiltrates MetaMask Team as Contractor

First seen 19 Jul 2026, 08:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 20, 2026 at 08:04 UTC
  • A North Korean hacker infiltrated MetaMask as a contractor for one month.
  • No data or funds were compromised during the incident.
  • The company is reviewing its contractor background verification processes.

A North Korean hacker named Tyler Knapp infiltrated MetaMask's parent company, ConsenSys, posing as a contractor for a month. He bypassed background checks through an external staffing agency and contributed to the development of fiat deposit and withdrawal features. The infiltration was discovered due to abnormal IP activity and behavior, prompting immediate revocation of his access and a halt to product releases he was involved in. Fortunately, no data or funds were compromised during this incident. ConsenSys is now reviewing its contractor verification processes to prevent future breaches. The hacker's presence raised concerns about security vulnerabilities in outsourced development roles.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 63d ago How this analysis works

Timeline

2026-07-19
Hacker infiltrated MetaMask team
Tyler Knapp posed as a contractor, bypassing checks and contributing to core wallet code.
Kucoin
2026-07-19
Discovery of infiltration
Abnormal IP activity led to the discovery of the hacker's infiltration and immediate action was taken.
Kucoin
2026-07-19
Company response initiated
Consensys revoked the hacker's access and suspended all product releases he was involved in.
Weex

More articles in this cluster (14)

Following this threat?

Track Consensys in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed