MetaMask code was open to a North Korea-linked contractor for a month before Consensys paused releases
·2 min read
Compiled by KHAO Editorial
— aggregated from 1 source + 4 references discovered via search.
See llms.txt for citation guidance.
◌ Single Source
A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April.
Key facts
CryptoSlate reported on July 5 that operational compromises around keys, custody, signing and approval systems accounted for roughly 76% of stolen value during the first half of 2026, even
The FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories
A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April
Drop Site reported that an internal April alert ordered all product releases suspended pending the investigation and told staff not to interact with the consultant
Summary
01 Contractor through a third-party provider made MetaMask-related code contributions from March 9 until access was terminated in April. 02 Consensys found no asset or data compromise, malicious code deployment, or user impact, but third-party access controls are now under scrutiny. 03 An April alert paused releases and barred staff from the consultant, and vendor practices were reviewed afterward. Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security.