Consensys cuts MetaMask contractor access after North Korea link discovered
In brief
- Contractor accessed MetaMask code for roughly one month before Consensys revoked access in April
- Investigation confirmed no compromised assets, malicious code, or user security impact
- Consensys strengthened third-party vendor security controls to match employee standards
- FBI warns North Korean IT workers exploit network access to steal proprietary code
- Operational compromises drove 76% of crypto theft in H1 2026
Investigation finds no compromise
Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security. General counsel Matt Corva outlined the response: the company identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement.
An internal April alert ordered all product releases suspended pending the investigation. The suspension was precautionary — no evidence emerged that the contractor had deployed malicious code or exfiltrated sensitive materials during the access window.
Vendor controls tightened
The incident prompted Consensys to review its third-party service practices. Consensys has since reviewed its third-party service practices, so the rigorous standards applied to employees also cover outside relationships. This includes checks using actual documents, multiple interviews, hardware authentication, IP and location verification, reference checks, and limits on access to critical systems.
The breach highlights a broader threat landscape. The FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories. Operational compromises around keys, custody, signing and approval systems have proven costly across the crypto industry — operational compromises accounted for roughly 76% of stolen value during the first half of 2026.
The incident gives no indication that user accounts or wallet assets were compromised. Still, the episode underscores how vendor risk — even when contained — can disrupt operations and force systemic review.


