
MetaMask Confirms Infiltration by North Korea-Linked Developer... Core Code Modified for One Month
Consensys, the developer of the world's largest self-custody wallet MetaMask, admitted to hiring a developer linked to North Korea. The developer, who used the alias 'Tyler Knapp,' had access to core code, and it was revealed that all past projects he worked on suffered security incidents.
On July 18, 2026, Consensys, a major Ethereum-based blockchain company, officially confirmed that a North Korean operative had infiltrated the development team of its core service, MetaMask. Using the alias 'Tyler Knapp,' the developer accessed and worked on MetaMask's core codebase for approximately one month. Consensys identified the developer's identity in April and immediately revoked his access, but this fact was only recently made public.
The developer was confirmed to be an individual linked to North Korea (DPRK), and all system access rights were revoked immediately upon discovery. He participated in building core infrastructure and held a significant level of code access.
This incident goes beyond a simple hiring mistake and reveals security vulnerabilities across the virtual asset industry. Before joining Consensys, Tyler Knapp had a history of working at five major DeFi projects, including Ankr, Blueberry Protocol, DEPO, Pickle Finance, and Harmony. Surprisingly, all five protocols were found to have suffered large-scale hacking and security incidents while he was employed or immediately after he left.
Core Code Access and Potential Risks
According to Consensys, the North Korea-linked developer participated in building MetaMask's pivotal infrastructure, including modules responsible for fund transfers between virtual assets and fiat currency. The company claims that no evidence of user funds or data being stolen has been found so far. However, security experts warn that since he had access to the core code of a wallet with over 30 million monthly active users, the possibility of long-term backdoor installation cannot be ruled out.
- Ankr: A former team member planted malicious code, resulting in a $5 million fund theft.
- Blueberry Protocol: Suffered damage from a security incident linked to developer infiltration.
- Harmony: Exposed security flaws, including a major bridge hacking incident.
- Pickle Finance: Experienced a vulnerability attack on its yield aggregator system.
- DEPO: A security breach occurred during the developer's tenure.
In particular, the case of Ankr Protocol clearly demonstrates the dangers of this incident. At the time, Ankr suffered an incident where a former team member planted malicious code in a smart contract to unauthorizedly issue trillions of tokens, suggesting that insider security threats can be far more lethal than external attacks. Concerns are being raised that the work performed by Tyler Knapp at MetaMask may have exploited internal system trust in a similar manner.
North Korea's offensive in stealing virtual assets is becoming even more intense in 2026. According to Chainalysis's 2026 Crypto Crime Report, North Korea stole a record-high $2 billion worth of virtual assets in 2025 alone, with cumulative stolen funds reaching $6.75 billion. In April 2026, North Korea-linked hacker groups continued high-intensity cyberattacks, including an attack on a major virtual asset exchange that resulted in the theft of approximately $293 million.
Limitations and Responses of Developer Verification Systems
The fact that even large companies like Consensys failed to filter out sophisticated, state-sponsored operatives has come as a great shock to the industry. Analysis suggests that the virtual asset industry's unique culture of respecting anonymity and the remote work environment are providing favorable infiltration routes for North Korean operatives. Experts agree that stricter identity verification procedures and centralized verification systems are necessary for developers handling core infrastructure.
MetaMask users should carefully monitor upcoming security patches and update announcements. Consensys is conducting additional code audits and has announced follow-up measures to strengthen security. This incident has once again highlighted that North Korea's cyber threats are a systemic risk that can shake the very foundations of trust in the virtual asset ecosystem, moving beyond the security issues of individual companies.
In conclusion, this MetaMask infiltration incident symbolizes one of the most sophisticated threats facing the DeFi ecosystem. North Korea is employing a strategy that goes beyond simple external attacks, infiltrating major projects as internal developers to seize control of systems. Unless accompanied by innovation in hiring processes across the industry and the establishment of real-time code monitoring systems, a second 'Tyler Knapp incident' could recur at any time.



This content is for information and commentary only and is not investment advice.
Join the reader conversation
Read reactions to this article and leave your own note.