An Outsider in the Repository: How Consensys Let a North Korea-Linked Contractor Into MetaMask's Code for a Month
Security·7 min read

An Outsider in the Repository: How Consensys Let a North Korea-Linked Contractor Into MetaMask's Code for a Month

Consensys, the wallet's developer, has disclosed an alarming incident: for nearly a month, a contractor linked to North Korea had access to the code of the popular crypto wallet. The investigation found no stolen funds and no malicious code, but the story exposed a weak spot in how outside workers are controlled.

What Exactly Happened

A contractor hired through a third-party provider made changes to the wallet-related code starting March 9. Access was only terminated in April, when the company spotted the threat. Consensys later described the person as linked to the DPRK.

In effect, an outsider had the ability to work with the repository for almost a month, while the wallet itself remained in the hands of millions of users the whole time. It was precisely the length of that window that raised the main question about the company's processes.

The Consensys Response

According to the company's general counsel, Matt Corva, the threat was identified quickly: access was revoked, a comprehensive investigation was launched, and law enforcement was notified. The company stresses that it acted according to its standard response procedure.

An internal April alert ordered all product releases suspended until the review was complete and barred staff from any interaction with the consultant. The pause in updates was a direct consequence of the incident.

What the Investigation Showed

The main takeaway is reassuring: the investigation found no misappropriation of funds or data, no deployment of malicious code, and no harm to user security. The funds in clients' wallets were not affected. The wallet itself kept working normally, and the project's official website reported no disruptions.

Even so, the mere fact of the access prompted Consensys to review how it works with outside contractors. The company stated that the strict standards applied to full-time employees now extend to more complex external relationships as well.

Why This Matters for Users

The Consensys crypto wallet is non-custodial, meaning the keys are stored by the user rather than the company. Even if a backdoor had made it into the code, the funds in a wallet are protected by a private key that stays with the owner alone.

And yet trust in the product rests on the flawlessness of its code. A wallet is only as valuable as its source code is clean. Any theoretical vulnerability in the wallet's client is a potential risk to millions of addresses, which is why the response to incidents like this matters so much. It is also important that the wallet is distributed both as a browser extension and as a mobile app, with installation files served through the official website - spoofing such a website would be a separate threat.

The Danger of a Spoofed Wallet Client

A separate scenario the industry fears is not the theft of keys directly, but the quiet modification of the client. If an attacker embeds malicious code in a wallet, it could, for example, swap the recipient's address at the moment funds are sent.

The user sees the familiar interface, visits the project's usual website, and confirms a transfer without suspecting that the money is going elsewhere. That is exactly why the integrity of the wallet's code and the authenticity of the website it is downloaded from are critical to security.

The North Korean Trail in Crypto

This case is not unique. IT specialists from the DPRK have long tried to infiltrate Western companies while posing as ordinary remote workers, using forged documents and stolen identities.

The FBI has separately warned that North Korean IT workers have used access to corporate networks to copy code repositories. The goal is not only earning money in circumvention of sanctions, but also industrial espionage - and sometimes the groundwork for future attacks.

How Such Contractors Disguise Themselves

The scheme usually rests on social engineering. A candidate goes through an interview under a cover story, provides a fake résumé and documents, and then lands a remote role with access to sensitive systems.

That is exactly why the developer's official guidance advises verifying real documents, conducting multiple interviews, using hardware authentication, checking IP and geolocation, requesting references, and limiting access to critical systems.

Lesson One: Identity Verification

The first barrier is thorough verification. Per the FBI's guidance, a worker's identity must be confirmed not only at the interview stage but also during onboarding and throughout their employment.

A one-time check at the entry point no longer works: an attacker can pass it once and then remain in the system for years. Regular audits of intermediary staffing agencies reduce this risk.

Lesson Two: Least Privilege

The second principle is minimal access. Every contractor and every account needs its own restrictions, and privileges should be granted exactly for the task and no broader.

After onboarding, the key barriers become repository permissions and mandatory code review. The UK's NCSC advises making all repository activity traceable and reviewing every change bound for production.

Lesson Three: Controlling External Code

External code demands separate attention. Any outside changes should undergo enhanced review, and access should be revoked quickly as soon as it is no longer needed.

Hardware keys protect an account from credential theft, while narrow privileges and independent review limit what even a legitimate account is able to change. It is precisely the combination of these measures that keeps a single person from quietly harming the product.

How a User Can Stay Safe

While companies build out their internal processes, some things depend on the user as well. In this sense a wallet is a zone of shared responsibility. You should download the app only from the official website, and verify the website address by hand rather than following links from emails and ads.

An extra barrier is a hardware wallet for large sums: even a compromised client will not gain access to keys that are stored offline. And before confirming a transfer, it is worth checking the recipient's address in full, since it is precisely address swapping that attacks on a wallet most often target.

The Broader Industry Problem

This incident is part of a larger trend. According to industry reports, it was operational compromises around keys, custody, and signing systems that accounted for roughly 76% of stolen value in the first half of 2026.

Tellingly, smart-contract vulnerabilities occurred more often, but less was stolen through them. This proves that access control and operational discipline matter more than they seem, even if such gaps account for fewer incidents.

What Teams Should Adopt

Experts advise developers of wallets and protocols to treat contractor access as continuously conditional. Verify identity throughout the entire engagement, audit agencies, and keep repository privileges narrow and observable.

Every change bound for production should receive independent review, and access should be revoked immediately once the task is complete. Consensys's April pause also showed the value of having a predefined mechanism ready in advance to instantly halt releases during a review.

Why These Attacks Will Keep Happening

The reason is simple: remote work has erased borders, and hiring someone from the other side of the world has become routine. For malicious actors in sanctioned countries, this is a convenient channel for both earning money and gaining access to others' systems.

The crypto market is especially vulnerable here: many startups, fast hiring, open repositories, and huge sums at stake. As long as this combination persists, hunters for other people's code will keep trying again and again, and companies will have to constantly raise the bar for vetting.

The Bottom Line

The story of the DPRK-linked contractor ended relatively well: the ordinary user's wallet was not harmed, and no malicious code made it into the product. But this is more the result of luck and a fast response than of perfectly built defenses.

The main takeaway is simple: in the crypto industry, a person and their access to code are often more dangerous than any technical vulnerability. And until companies start treating outside workers as strictly as they treat their own systems, stories like this will keep repeating.

FAQ
What happened at Consensys and MetaMask?

Consensys, the developer of the MetaMask wallet, disclosed that a contractor hired through a third-party provider - later described by the company as linked to North Korea - made changes to wallet-related code starting March 9. Access was only terminated in April, when the company spotted the threat, meaning an outsider could work with the repository for almost a month.

Were MetaMask user funds or data affected?

No. The investigation found no misappropriation of funds or data, no deployment of malicious code, and no harm to user security. The wallet is also non-custodial: keys are stored by the user, not the company, so even a hypothetical backdoor would not by itself expose funds protected by a private key that stays with the owner alone.

How did Consensys respond to the incident?

According to general counsel Matt Corva, access was revoked quickly, a comprehensive investigation was launched, and law enforcement was notified. An internal April alert suspended all product releases until the review was complete and barred staff from any interaction with the consultant.

How do North Korea-linked IT workers infiltrate companies?

The scheme usually rests on social engineering: a candidate passes interviews under a cover story with a fake resume, forged documents, or a stolen identity, then lands a remote role with access to sensitive systems. The FBI has warned that North Korean IT workers have used corporate access to copy code repositories - for income in circumvention of sanctions, espionage, and groundwork for future attacks.

How can a crypto wallet user stay safe?

Download the app only from the official website and verify the address by hand rather than following links from emails and ads. Keep large sums on a hardware wallet, since keys stored offline stay out of reach even for a compromised client, and check the recipient's address in full before confirming a transfer - address swapping is what attacks on a wallet most often target.

About the author
Crypto Markets Expert & Head of Content and Marketing

Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading - turning on-chain data and market shifts into clear, actionable research for traders.

Share this articleTelegramX
An Outsider in the Repository: MetaMask's DPRK Contractor | EIDEX