
The blockchain company said the MetaMask contractor worked through a third-party provider from March 9 until April, prompting a release pause and scrutiny of vendor access controls after no user impact was found.
Consensys said a contractor brought in through a third-party provider worked on MetaMask code from March 9 until access was cut off in April after the company identified links to North Korea. Matt Corva, Consensys's general counsel, said the threat was identified quickly, access was terminated, a comprehensive investigation was launched and law enforcement was notified. Consensys said it found no compromised assets or data, no malicious code deployment and no impact to user safety or security. Drop Site reported that an internal April alert paused all product releases during the investigation and instructed staff not to interact with the consultant. The episode has reinforced industry focus on tighter controls over contractor and repository access, including identity verification, least-privilege permissions, independent code review and rapid revocation of access when concerns arise.