Última hora
DE13-Jähriger stirbt bei WM-Siegesfeier in Spanien nach Brunnen-EinsturzEUAndy Burnham Appointed UK Prime MinisterVNHuyền thoại bóng đá Anh Kevin Keegan qua đời ở tuổi 75TRMİT, uluslararası uyuşturucu kaçakçısı Kasra Ashrafi'yi Bodrum'da yakaladıARالدفاعات الجوية الكويتية تعترض صواريخ ومسيّرات إيرانية بعد استهداف قاعدة علي السالمFRLa HAS recommande l'obligation vaccinale contre la grippe pour les professionnels de santéARروسيا تطرد دبلوماسيين إيطاليين رداً على إجراء مماثل من روماVNMỹAJ và Lyndsey Lozano gỡ ảnh menu AI sau chỉ trích tại nhà hàng Grind & UnwindDEUS-Märkte starten schwerfällig in die Woche; Nahost-Spannungen beeinflussen AnlegerGLOBALHead of US AI Standards Center Resigns Three Months After AppointmentDE13-Jähriger stirbt bei WM-Siegesfeier in Spanien nach Brunnen-EinsturzEUAndy Burnham Appointed UK Prime MinisterVNHuyền thoại bóng đá Anh Kevin Keegan qua đời ở tuổi 75TRMİT, uluslararası uyuşturucu kaçakçısı Kasra Ashrafi'yi Bodrum'da yakaladıARالدفاعات الجوية الكويتية تعترض صواريخ ومسيّرات إيرانية بعد استهداف قاعدة علي السالمFRLa HAS recommande l'obligation vaccinale contre la grippe pour les professionnels de santéARروسيا تطرد دبلوماسيين إيطاليين رداً على إجراء مماثل من روماVNMỹAJ và Lyndsey Lozano gỡ ảnh menu AI sau chỉ trích tại nhà hàng Grind & UnwindDEUS-Märkte starten schwerfällig in die Woche; Nahost-Spannungen beeinflussen AnlegerGLOBALHead of US AI Standards Center Resigns Three Months After Appointment
Newsgather
AtrásContractor linked to North Korea worked on MetaMask code
Contractor linked to North Korea worked on MetaMask code
Tecnología
CryptoSlatehace 21 horasTecnología2 min de lectura

Contractor linked to North Korea worked on MetaMask code

Consensys cut off access to the individual in April after identifying a link to North Korea, but found no misappropriation of assets or data.

En resumen

  • A contractor, later linked to North Korea, worked on MetaMask code for Consensys from March to April before access was terminated.
  • Consensys's investigation found no asset or data misappropriation, malicious code, or impact on user safety.
  • The incident highlights the need for rigorous third-party contractor security, including identity verification, least-privilege access, and continuous monitoring.

Resumen generado por IA

Por qué importa

A contractor linked to North Korea worked on MetaMask code for Consensys, prompting an internal investigation and termination of access.

Tamaño de fuente

A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April. Consensys later described the person as linked to North Korea.

Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security. General counsel Matt Corva said the company identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement.

Drop Site reported that an internal April alert ordered all product releases suspended pending the investigation and told staff not to interact with the consultant. Corva called the service provider relationship reputable and said Consensys has since reviewed its third-party service practices, so the rigorous standards applied to employees also cover more complex outside relationships.

Contractor checks need repository limits

The incident gives no indication that user accounts or wallet assets were compromised. Consensys’ existing relationship with the vendor still left a gap: every contractor and account needed its own safeguards.

MetaMask's general security guidance warns that malicious workers can use false identities and forged documents to obtain remote roles. It recommends checks using actual documents, multiple interviews, hardware authentication, IP and location verification, reference checks, and limits on access to critical systems.

The FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories. Its guidance calls for identity verification during interviews, onboarding and throughout employment, routine audits of third-party staffing firms, least-privilege access and monitoring for unusual remote connections or repository exfiltration.

After onboarding, repository permissions and review become the core safeguards. UK National Cyber Security Center guidance recommends making repository activity attributable, reviewing every production-bound change, applying extra scrutiny to external contributions, and revoking access quickly when it is no longer required. Hardware-backed credentials can protect an account from credential theft, while tightly scoped permissions and independent review limit what an authorized account can change.

CryptoSlate reported on July 5 that operational compromises around keys, custody, signing and approval systems accounted for roughly 76% of stolen value during the first half of 2026, even though smart-contract exploits were more frequent. That gap shows why access and operational controls matter even when they account for fewer incidents.

Wallet and protocol teams should treat contractor access as continuously conditional. Identity checks should extend through employment, third-party firms should be audited, repository privileges should remain narrow and observable, every production-bound change should receive independent review, and access should be revoked as soon as it is no longer required.

Consensys's April release pause also shows the value of retaining a predefined way to halt changes while suspicious access is investigated.

Preguntas abiertas

  • How was the contractor initially vetted?
  • What specific vulnerabilities did the contractor have access to?

Temas relacionados

This article was originally published by CryptoSlate.

Noticias relacionadas

Más sobre este temaMetaMask