More

    MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases

    A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April. Consensys later described the person as linked to North Korea.

    Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security. General counsel Matt Corva said the company identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement.

    Drop Site reported that an internal April alert ordered all product releases suspended pending the investigation and told staff not to interact with the consultant. Corva called the service provider relationship reputable and said Consensys has since reviewed its third-party service practices, so the rigorous standards applied to employees also cover more complex outside relationships.

    Compromised developers lying dormant within crypto projects risks next major crypto exploitCompromised developers lying dormant within crypto projects risks next major crypto exploit
    Related Reading

    Compromised developers lying dormant within crypto projects risks next major crypto exploit

    The bigger risk after Drift may be the access attackers gain before a protocol knows it has a problem.

    Apr 8, 2026 · Gino Matos

    Contractor checks need repository limits

    The incident gives no indication that user accounts or wallet assets were compromised. Consensys’ existing relationship with the vendor still left a gap: every contractor and account needed its own safeguards.

    Infographic showing the reported March-to-April MetaMask contractor contribution window, Consensys's no-impact findings, and seven controls for contractor identity, repository access, review, monitoring, and revocation.Infographic showing the reported March-to-April MetaMask contractor contribution window, Consensys's no-impact findings, and seven controls for contractor identity, repository access, review, monitoring, and revocation.

    MetaMask’s general security guidance warns that malicious workers can use false identities and forged documents to obtain remote roles. It recommends checks using actual documents, multiple interviews, hardware authentication, IP and location verification, reference checks, and limits on access to critical systems.

    Secret laptop footage exposes North Korean spies infiltrating US companiesSecret laptop footage exposes North Korean spies infiltrating US companies
    Related Reading

    Secret laptop footage exposes North Korean spies infiltrating US companies

    Researchers watched in real-time as the Famous Chollima division used this common remote work setup to bypass firewalls.

    Dec 3, 2025 · Oluwapelumi Adejumo

    The FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories. Its guidance calls for identity verification during interviews, onboarding and throughout employment, routine audits of third-party staffing firms, least-privilege access and monitoring for unusual remote connections or repository exfiltration.

    CryptoSlate Daily Brief

    Daily signals, zero noise.

    Market-moving headlines and context delivered every morning in one tight read.