Consensys says MetaMask codebase breach exposed no user data or funds

A contractor with reported links to North Korea accessed MetaMask’s core code from March 9 until April 2026 before Consensys removed access, paused releases, and said its investigation found no user impact.

Summary

Consensys said a contractor engaged through a third-party service provider accessed MetaMask’s core codebase from March 9 until April 2026, contributing to code including components used to connect users with third-party fiat payment providers. The company suspended product releases during the investigation, terminated the contractor’s access, and notified law enforcement after identifying the threat. Consensys said its investigation found no misappropriation of assets or data, no deployment of malicious code, and no impact to user safety, security, accounts, or wallet assets. General counsel Matt Corva described the staffing provider as reputable and said the company has reviewed its third-party hiring controls after the incident. The episode fits a broader pattern highlighted by the FBI of North Korean IT workers seeking remote roles under false identities to gain access to company systems and code repositories.

Terms & Concepts
  • MetaMask: A Web3 wallet for managing digital assets
  • fiat payment providers: Third-party services that let users buy or sell crypto using traditional currency
  • least-privilege access controls: Security settings that give workers only the minimum system access needed for their jobs