![Hero: Digital illustration of a hooded figure at a laptop accessing lines of MetaMask wallet source code, with blockchain network connections and red security alert icons overlaying the screen in a dimly lit workspace](A tense workspace scene showing infiltration of crypto code)

Summary

  • Consensys hired a North Korean-linked contractor who accessed MetaMask source code for one month using the alias Tyler Knapp.
  • The firm paused product releases after uncovering the access to internal systems in mid-July 2026.
  • A separate Sioux Falls investor faces 29 federal counts in an unrelated alleged $20 million crypto Ponzi scheme.

Consensys brought in a North Korean-linked contractor. He worked on MetaMask source code for a full month. The contractor used the alias Tyler Knapp and the GitHub handle imyugioh on core wallet features.

This incident came to light in mid-July 2026. It also overlapped with fraud charges against a South Dakota investor.

Context

Consensys maintains MetaMask. It ranks among the most popular self-custody wallets in crypto. External contractors often get access to code repositories for development work.

The July 2026 discovery forced an immediate halt to product releases. Internal teams reviewed the full scope of access. No prior public alerts had flagged the contractor's background.

Details

The contractor contributed to MetaMask features during that month. Consensys ended the relationship after the fact. Internal logs later tied the activity to North Korean networks.

Consensys halted releases to contain any potential exposure. The firm continues its investigation.

"No evidence of actual code exfiltration or exploit deployment has been confirmed."

, Consensys (Source)

A parallel case involves Sioux Falls investor Benjamin Paul Wiener. He faces indictment on 29 counts of wire fraud and money laundering in an alleged $20 million scheme. Both stories broke around the same time.

Crypto wallet security stays under pressure. North Korean infiltration tactics target hiring pipelines. Firms like Consensys now face renewed scrutiny over contractor screening.

Reaction

Community discussion on X quickly focused on MetaMask hack concerns. People called for stronger identity checks.

Social Highlight · @cryptoalert · 2026-07-15

North Korean developer infiltrates MetaMask. Wallet teams must audit every contractor now. (link)

Crypto firms must strengthen contractor identity verification. Wallet providers face ongoing state-sponsored risks. They require continuous monitoring of access logs.

Audits at Consensys have already expanded. Regulators now pay closer attention to contractor vetting across the sector.