MetaMask Hired North Korean Developer Already Listed by Its Own Security Partner

22 July 2026 - 11:00 UTC
North Korea
Photo by Mike Bravo on Unsplash

(Updated with comment from Consensys).

Consensys, the Ethereum software firm behind the MetaMask crypto wallet, hired a contractor linked to the Democratic People's Republic of Korea (DPRK) this year who, according to security researchers, had already been identified months earlier on a public registry MetaMask itself helped build.

The contractor, using the alias "Tyler Knapp" and GitHub handle "imyugioh," was onboarded through a third-party provider and contributed to MetaMask's core wallet code and its crypto-to-fiat conversion features from 9 Mar until Consensys terminated access in April. "Very quickly after being introduced, we discovered the threat, followed our security protocols, immediately terminated any access and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security," Consensys general counsel Matt Corva said in a statement.

A name SEAL already had

Security Alliance (SEAL), a threat-intelligence coalition that lists MetaMask as a founding partner alongside WalletConnect, Backpack and Phantom, maintains a public registry of suspected DPRK IT operatives. According to a security analyst using the handle Zun, cited by Protos, Knapp appears in that registry under a different alias, with reported prior contractor stints at Web3 gaming firm MagicCraft in 2022 and DeFi protocol Napier Finance in 2023, before ever reaching Consensys.

As reported in April, a similar case saw Solana DEX Stabble terminate a developer publicly identified as North Korean and urge users to withdraw funds, underscoring how often these placements surface only after the fact rather than being caught at hiring.

A Consensys spokesperson told Sandmark that Knapp came to the company through an existing relationship with a third-party service provider and worked as a consultant. "He was never hired as a Consensys employee," the spokesperson said.

The company said its protocols include comprehensive background screening before onboarding, alongside monitoring tools and long-standing relationships with security personnel and law enforcement. It notified law enforcement of the incident and said its controls contained the matter before customer assets or user security were affected.

Consensys did not address whether it checked SEAL's registry before onboarding Knapp, or why its founding-partner relationship with the coalition failed to surface a name that the registry is said to have already held.

The spokesperson said the company had re-evaluated its practices for using third-party services, including existing relationships, to ensure the standard it applies to employees is also applied in more complex third-party arrangements.

MetaMask helped build the registry meant to catch hires like this one. It didn't.

Add as a preferred source on Google