
According to reports from Drop Site News, Consensys, the maker of MetaMask, accidentally hired a North Korean developer linked to the Democratic People's Republic of Korea as a consultant. The developer, who used the fake name Tyler Knapp and GitHub handle imyugioh, was introduced through an existing relationship with a reputable third-party service provider. His code contributions ran from March 9 until April when the company detected and removed his access. As Drop Site News reports, the public GitHub profile associated with 'Knapp' also made contributions to MetaMask's mobile wallet platform, with his contributions abruptly stopping in April 2026.
As reported by Drop Site News, the North Korean developer helped write core platform code for the MetaMask wallet and contributed to parts of the platform related to conversion between crypto and fiat currency via third-party payment providers. General counsel Matt Corva issued a company-wide alert in April ordering 'All product releases are to be suspended immediately pending investigation' and instructing staff to 'Do not interact with this individual while we perform our investigation'. The company alerted law enforcement and provided them with all relevant information. According to Drop Site News, Consensys confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security. Corva emphasized that 'Very quickly after being introduced, we discovered the threat, followed our security protocols, immediately terminated any access and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security.'
According to Drop Site News, this incident reflects a pattern where North Korean nationals increasingly target American software companies, posing as engineers and securing software development roles to expropriate trade secrets or infiltrate supply chains. Cryptocurrency is a special area of interest for the North Korean government starved of foreign exchange, making it one of the biggest sources of crypto-related scams and heists globally. As reported by TRM Labs, nearly $700 million, or 66%, of all dollars stolen in crypto hacks can be attributed to North Korea-linked activity. One of the biggest crypto heists in history, the ByBit hack estimated to be worth $1.5 billion, was reportedly conducted by North Korean hackers last year. The stakes are huge, as TRM Labs reports that North Korea took more than half of the $2.7 billion lost to crypto hacks in 2025.
A comprehensive six-month investigation supported by the Ethereum Foundation's ETH Rangers Program reveals the extent of this threat across the crypto industry. The Ketman Project identified about 100 suspected North Korean IT workers using false identities across 53 crypto and Web3 projects, according to an ETH Rangers recap published in April. Ketman investigators also traced at least three suspected groups across 11 code repositories, where projects had merged 62 pull requests before detecting the activity. The project reported that some applicants used generated profile pictures, forged identity documents and false Japanese identities to pass screening checks. According to crypto.news, Opsek founder Pablo Sabbatella warned at Devconnect Buenos Aires that North Korean workers could be embedded in as many as one-fifth of crypto companies, with North Korean applicants accounting for roughly 30% to 40% of job applications received by crypto firms.
The incident has prompted Consensys to reassess how it outsources engineering and development work despite finding no financial losses. As reported by Drop Site News, some crypto firms are now sharing threat intelligence to catch these fake hires early. The incident highlights the vulnerability of developer setups as the fastest route to a crypto firm's keys, with attackers using them to reach withdrawal approval systems. According to TRM Labs, more than 30 exchanges and decentralized finance protocols now share rapid alerts through its Beacon Network when North Korea-linked funds reach participating platforms. The stakes are huge, as TRM Labs reports that North Korea took more than half of the $2.7 billion lost to crypto hacks in 2025.