← Back

Wire · operational-macro

North Korea-Linked Contractor Had MetaMask Code Access for Over a Month

Published

19 July 2026

Topic

operational-macro

Sectors

Crypto & Web3Cybersecurity

Geography

United States

Source

Read at t.co

Verified

Fusion42 · 20 July 2026 · Fusion42 review

A North Korea-linked contractor accessed MetaMask's codebase for roughly a month (March 9 to April) through a reputable third-party vendor before Consensys detected and revoked access. Though no assets, user data, or malicious code were stolen, the incident exposed a gap in continuous verification of third-party contributors and prompted Consensys to freeze product releases and raise contractor vetting standards.

This Wire brief sits within Fusion42's coverage of Crypto & Web3 and Cybersecurity.

◆ The Wire takeaway

If you're building crypto infrastructure or wallets, the threat isn't a protocol flaw—it's a contractor with a forged resume sitting in your repository for a month undetected. Consensys just proved that even reputable vendors can deliver bad actors, and 76% of crypto theft now comes from insider access, not code exploits; your security model needs continuous verification baked in, not just onboarding checks.

Coverage

1 source · 19 Jul 2026

Related on Wire

Topics

Crypto & Web3Cybersecuritythird-party-access-riskcontractor-screeningcode-repository-securityoperational-compromiseidentity-verification