Consensys says North Korea-linked developer had system access for a month

Consensys says North Korea-linked developer had system access for a month

The blockchain company said the MetaMask contractor worked through a third-party provider from March 9 until April, prompting a release pause and scrutiny of vendor access controls after no user impact was found.

Fact Check
The Drop Site News primary report, citing internal Consensys communications, confirms all key elements of the claim: a North Korea-linked consultant introduced by a third-party provider, access to MetaMask-related systems beginning March 9 lasting roughly a month before termination (consistent with April 2026), and a company finding of no data, asset, or malicious-code impact per its general counsel. Cointelegraph and CryptoBriefing independently report the same facts, both tracing to the Drop Site report. The consistency across sources and the specific corroborated 'March 9' start date support the claim, though the phrasing 'Consensys says' rests on reported internal communications rather than a located public company statement.
    Reference123
Summary

Consensys said a contractor brought in through a third-party provider worked on MetaMask code from March 9 until access was cut off in April after the company identified links to North Korea. Matt Corva, Consensys's general counsel, said the threat was identified quickly, access was terminated, a comprehensive investigation was launched and law enforcement was notified. Consensys said it found no compromised assets or data, no malicious code deployment and no impact to user safety or security. Drop Site reported that an internal April alert paused all product releases during the investigation and instructed staff not to interact with the consultant. The episode has reinforced industry focus on tighter controls over contractor and repository access, including identity verification, least-privilege permissions, independent code review and rapid revocation of access when concerns arise.

Terms & Concepts
  • least-privilege permissions: An access-control approach that gives users only the minimum system rights needed to do their jobs.
  • repository access: Permission to view or change source code stored in a software version-control system.
  • malicious code: Software intentionally designed to damage systems, steal information or enable unauthorized activity.