← Back

Wire · founder news, decoded · operational-macro

North Korea-Linked Contractor Had MetaMask Code Access for Over a Month

Published

19 July 2026

Topic

operational-macro

Sectors

Crypto & Web3Cybersecurity

Geography

United States

Source

Read at t.co

Verified

Fusion42 · 20 July 2026 · Fusion42 review

A North Korea-linked contractor accessed MetaMask's codebase for roughly a month (March 9 to April) through a reputable third-party vendor before Consensys detected and revoked access. Though no assets, user data, or malicious code were stolen, the incident exposed a gap in continuous verification of third-party contributors and prompted Consensys to freeze product releases and raise contractor vetting standards.

This Wire brief sits within Fusion42's coverage of Crypto & Web3 and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

The Wire takeaway

If you're building crypto infrastructure or wallets, the threat isn't a protocol flaw—it's a contractor with a forged resume sitting in your repository for a month undetected. Consensys just proved that even reputable vendors can deliver bad actors, and 76% of crypto theft now comes from insider access, not code exploits; your security model needs continuous verification baked in, not just onboarding checks.

Related on Wire

Topics

Crypto & Web3 · Cybersecurity · third-party-access-risk · contractor-screening · code-repository-security · operational-compromise · identity-verification

North Korea-Linked Contractor Had MetaMask Code Acces… | Fusion42