Wire · operational-macro
North Korea-Linked Contractor Had MetaMask Code Access for Over a Month
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
A North Korea-linked contractor accessed MetaMask's codebase for roughly a month (March 9 to April) through a reputable third-party vendor before Consensys detected and revoked access. Though no assets, user data, or malicious code were stolen, the incident exposed a gap in continuous verification of third-party contributors and prompted Consensys to freeze product releases and raise contractor vetting standards.
This Wire brief sits within Fusion42's coverage of Crypto & Web3 and Cybersecurity.
◆ ◆ The Wire takeaway
If you're building crypto infrastructure or wallets, the threat isn't a protocol flaw—it's a contractor with a forged resume sitting in your repository for a month undetected. Consensys just proved that even reputable vendors can deliver bad actors, and 76% of crypto theft now comes from insider access, not code exploits; your security model needs continuous verification baked in, not just onboarding checks.
◆ Coverage
1 source · 19 Jul 2026
◆ Related on Wire
◆ Topics