For about a month, a contractor tied to North Korea quietly made commits to MetaMask's core code. Nobody at Consensys had hired him directly. He came through a third-party staffing provider the company describes as "reputable," and he had access from March 9 until Consensys pulled the plug in April.
The sections he touched included code that connects MetaMask users to fiat payment providers. That detail matters: payment rails are a natural target for anyone looking to intercept funds or harvest credentials at scale. Still, Consensys says its investigation found no stolen assets, no exposed user data, and no malicious code deployed. General counsel Matt Corva confirmed the company identified the threat, terminated access, and notified law enforcement.
The freeze nobody talked about publicly
Drop Site News, which first reported the story, obtained an internal April alert ordering all MetaMask product releases suspended while the investigation ran. Staff were instructed not to interact with the consultant. So for a period this spring, one of the most widely used crypto wallets in the world was essentially on hold, and users had no idea why.
Consensys has since said it is extending the vetting standards applied to full-time employees to cover third-party staffing relationships. Corva framed this as a process upgrade rather than a failure, though the fact that a foreign-state operative reached production code at a company of Consensys's profile will raise questions regardless of the outcome.
North Korea's IT infiltration playbook is getting harder to ignore
This incident fits a well-documented pattern. The FBI has warned repeatedly that North Korean IT workers apply for remote roles at tech and crypto firms using fabricated identities, then use that access to copy code repositories, embed backdoors, or simply collect intelligence. The bureau has urged companies to require in-person identity verification at hire, audit their staffing vendors, and enforce least-privilege access so contractors can only touch what they genuinely need.
The scale of the problem is striking. According to TRM Labs, North Korea was responsible for roughly 64% of the total value stolen through crypto hacks in 2025, a year in which losses across the industry surpassed $2.7 billion. That figure includes sophisticated exchange breaches, but supply-chain infiltration via remote contractors is increasingly part of the mix.
MetaMask has tens of millions of active users. The fact that a state-linked actor reached its code at all, even briefly, even without apparent damage, is the kind of near-miss that changes how security teams think about outside contributors.
This article is for informational purposes only and does not constitute financial or investment advice.



