MetaMask paused releases after North Korea-linked contractor probe

Crypto users track smart contract bugs, but this case points to a different risk: who gets access to wallet code before software ships. Consensys said a contractor hired through a third-party provider worked on MetaMask code from March 9 until access was cut off in April, after the person was identified as linked to North Korea.
The company said its investigation found no theft of assets or data, no malicious code deployment, and no effect on user safety or security. General counsel Matt Corva said Consensys moved quickly to terminate access, opened a broad internal review, and notified law enforcement.
Drop Site reported that an internal alert in April told staff to suspend all product releases while the investigation was underway and not to interact with the contractor. Consensys said the staffing provider relationship had been considered reputable, but the incident exposed a gap in how outside contractors were covered.
The episode adds to a wider security concern for crypto teams: authorized access can become a threat even when no exploit reaches production. Consensys said it has since reviewed its third-party service practices so the same standards used for employees also apply to more complex contractor relationships.
◆ Source
Originally published by CryptoSlate on July 19, 2026.
◆ Build with us
Every event, verified and scored. One API call away.


