Consensys cuts contractor tied to N. Korea after MetaMask access
Consensys cut off a contractor tied to North Korea after code contributions to MetaMask from March 9 until access was revoked in April; its investigation found no asset or data loss, malicious code or user impact.
Consensys terminated access for a contractor who contributed to MetaMask-related repositories from March 9 until the account was blocked in April. The worker was engaged through a third-party staffing provider, and Consensys later described the individual as linked to North Korea.
An internal April alert suspended product releases and instructed employees not to interact with the consultant while the company reviewed the access. Consensys reported it notified law enforcement as part of the response and blocked the account.
The company’s investigation found no misappropriation of assets or user data, no deployment of malicious code into production systems and no impact to users. In a statement, Consensys general counsel Matt Corva wrote: “We identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement.”
Consensys reviewed its vendor and contractor controls and identified gaps in repository permissions and continuous identity verification for outside contributors. The firm reported it has tightened oversight of third-party staffing, narrowed and logged repository privileges, extended identity checks beyond onboarding, required independent review for production-bound changes and implemented faster access revocation.
Federal cybersecurity guidance and agency warnings recommend verifying identity with original documents, conducting multiple interviews and reference checks, using hardware-backed authentication, checking IP and location consistency, applying least-privilege access, auditing staffing firms and monitoring remote connections and repository activity for unusual exfiltration.
Data for the first half of 2026 shows operational compromises involving keys, custody, signing and approval systems accounted for roughly 76% of the value stolen from crypto services, while smart-contract exploits occurred more often. Consensys paused releases in April to halt changes while the access was investigated and to allow rapid suspension of suspicious accounts.
Content on BlockPort is provided for informational purposes only and does not constitute financial guidance.
We strive to ensure the accuracy and relevance of the information we share, but we do not guarantee that all content is complete, error-free, or up to date. BlockPort disclaims any liability for losses, mistakes, or actions taken based on the material found on this site.
Always conduct your own research before making financial decisions and consider consulting with a licensed advisor.
For further details, please review our Terms of Use, Privacy Policy, and Disclaimer.








