icon_install_ios_web icon_install_ios_web icon_install_android_web

That was close! A hired third-party contractor nearly destroyed MetaMask

分析10小時前發佈 lywt
317 0

Author: Golem (`@web3_golem`)

That was close! A hired third-party contractor nearly destroyed MetaMask

Last week, just after MetaMask celebrated its 10th anniversary, the media broke a “security scandal” about the company accidentally hiring a North Korean hacker.

On July 17, according to internal Slack records from Consensys obtained by Drop Site News, a North Korean hacker using the fake identity “Tyler Knapp” (GitHub account imyugioh) was hired as a consultant on March 9, 2026, through a third-party HR vendor that Consensys has a long-term partnership with. Internal records show that this North Korean hacker was not involved in a peripheral project but had access to the core MetaMask wallet code and participated in developing the wallet’s fiat on-ramp and off-ramp functionality.

Imagine if this North Korean hacker had tampered with MetaMask’s fiat gateway, the assets of tens of millions of users would have been threatened. Fortunately, this disaster did not occur. One month after the hacker joined the company, Consensys’s internal security department detected the anomaly. After Consensys’s investigation concluded that Tyler Knapp’s true identity was a North Korean hacker, it immediately revoked all his internal access and contacted law enforcement.

Matt Corva, General Counsel at Consensys, stated that after initiating a company-wide investigation into Tyler Knapp, he ordered an immediate halt to all MetaMask product releases, pleaded with everyone to keep the matter confidential, and instructed them not to contact this individual.

Although this security incident did not result in user asset or data loss, Matt Corva never disclosed how they ultimately determined Tyler Knapp’s connection to the North Korean hacker group.

Has the Consensys Recruitment Process 蜜蜂n Infiltrated by Hackers?

The question remains: how could a North Korean hacker so easily bypass Consensys’s recruitment background checks?

Matt Corva’s explanation was, “We became aware of ‘Knapp’ through an existing relationship with a reputable third-party service provider.” However, this clearly cannot justify Consensys’s failure to conduct a thorough background check on the applicant. More absurdly, Consensys may not have performed even a simple review of Tyler Knapp during the recruitment process, as Knapp did not go to great lengths to conceal his North Korean hacker identity. An ordinary person could have discovered it by asking an 人工智慧.

According to a post on X by DeFi researcher @Zun2025, the North Korean hacker’s GitHub account is imyugioh. He has been publicly listed on the Lazarus Group hacker roster since September 2025, under his real name, Mauro Liu. (Odaily: Lazarus Group is North Korea’s largest hacking group. The $1.5 billion theft from Bybit in 2025 was also attributed to Lazarus Group.)

That was close! A hired third-party contractor nearly destroyed MetaMask

North Korean hacker imyugioh, real name Mauro Liu

Consensys is reluctant to reveal the true reasons for identifying Tyler Knapp’s connection to the North Korean hacker group, likely fearing it would expose vulnerabilities in the company’s recruitment process.

Matt Corva later defended the company, stating that it had initiated a review of its engineering and development outsourcing practices. “We are reviewing all third-party services, including existing relationships, to ensure the same rigorous standards we apply to all employees are also applied to our more complex third-party partnerships.”

More ironically, MetaMask’s Head of Security, Taylor Monahan, had been focusing on North Korean hackers’ infiltration of Web3 company recruitment processes. She previously stated that North Korean IT professionals have been actively participating in DeFi projects and contributing to well-known protocols for at least seven years. Affected projects include SushiSwap, THORChain, Fantom, 柴犬, Yearn Finance, and Floki, now adding MetaMask itself to the list.

As a long-time observer of North Korean hackers, Taylor Monahan has not commented on X about MetaMask accidentally hiring one. Although this incident was a “successful infiltration of the recruitment process without a successful attack,” it still exposed the overall state of security negligence within MetaMask, which starkly contrasts with the image it projects externally—allowing an outsourced contractor to access core code for such a critical product module as the wallet’s fiat gateway.

Even large 加密貨幣 companies like Consensys, possessing comprehensive code audit systems, are often more vulnerable than smaller teams in recruitment and outsourcing checks due to their size, making the recruitment link particularly susceptible to hackers.

North Korean Hackers Disguising as Employees Has Become the Easiest Attack Vector

Over the past year, with the continuous improvement of 人工智慧 intelligence and coding capabilities, many worry that hackers could use AI to find protocol vulnerabilities and execute attacks. Counter-intuitively, however, history shows that for large companies, social engineering attacks are the easiest and most lucrative method for North Korean hackers.

Compared to launching external technical attacks, infiltrating the recruitment pipeline or posing as job applicants is a lower-cost strategy for hacker groups. On-chain detective ZachXBT has noted that many infiltration methods used by Lazarus Group, the largest North Korean hacking group, are surprisingly simple. Examples include posting job openings, contacting targets via LinkedIn, sending direct messages, holding Zoom calls, and conducting interviews. This method offers persistence and allows for a “broad net” approach.

Furthermore, this attack method presents a cost asymmetry. North Korean hackers can create new identities with almost zero cost, whereas for large 加密貨幣 companies supporting remote work, third-party outsourcing, and open-source collaboration, maintaining continuous identity verification and background checks is a high-cost endeavor requiring significant manpower and resources.

Many crypto enterprises were not as fortunate as MetaMask and managed to identify the “insider” before any theft occurred.

In April 2026, a North Korean hacker spent six months infiltrating Drift Protocol, obtaining internal permissions through fake recruitment/partnerships, resulting in the theft of approximately $285 million in user assets. In an earlier case in 2024, a North Korean hacker infiltrated the Bitcoin DMM exchange through recruitment, gaining internal access and stealing approximately $308 million. In 2022, a North Korean hacker disguised as a blockchain game developer entered the Ronin Network company, directly leading to the theft of approximately $620 million from the Ronin bridge, one of the largest crypto hacks in history at that time.

MetaMask narrowly avoided an incident, but it did not miss a warning. For today’s crypto industry, the greatest security risk may no longer lie in the code, but beyond it. The security boundary of blockchain has long extended from on-chain to the real world. Code can be repeatedly audited, contracts can be continuously upgraded, but identity remains difficult to verify. In the past, people thought smart contracts were the weakest link in the crypto industry. Now, it seems that what is truly difficult to defend against is always the management process, and the people behind it.

本文源自網路: That was close! A hired third-party contractor nearly destroyed MetaMask

Related: Ethereum is retracing the same path as the Internet and Linux: everyone refuses to yield to anyone else, and in the end, the neutral party takes it all.

Original Translation: TechFlow Introduction: Stripe wants everyone to use Tempo, JPMorgan wants to push its own chain, Circle wants to launch Arc – giants will never build on each other’s turf. This is Ethereum’s opportunity: when everyone refuses to submit to a single company’s infrastructure, the only option is a neutral layer that no one controls. Ethereum is replaying the history of the internet and Linux. “Stripe wants everything to happen on Tempo, but JPMorgan wants everything to happen on the JPMorgan chain, Circle wants everything to happen on Arc, and so on. They will never agree. The big players will never agree to build on another big player’s infrastructure. That’s why Ethereum is the only option. It is the only way forward – as neutral infrastructure that everyone can…

© 版權聲明

相關文章