One of the world’s largest blockchain companies was nearly breached from within. Consensys, the creator of the MetaMask wallet and Infura infrastructure services, unwittingly engaged a software developer later revealed to have ties to North Korea - and the individual held access to parts of its systems for roughly a month.
The incident was first reported Friday by Drop Site. Earlier this year, Consensys brought on a developer using the alias “Tyler Knapp.” Only later was it discovered that the individual was connected to the Democratic People’s Republic of Korea. Once the threat was detected, the company temporarily paused product releases and launched an internal investigation.
Consultant, Not an Employee
Consensys general counsel Matt Corva explained how the individual gained access. “‘Knapp’ was introduced through an existing relationship with a trusted third-party service provider and collaborated with Consensys as a consultant. He was never hired as a Consensys employee,” he told Cointelegraph.
According to Corva, the company’s response was swift. “Very quickly after introduction, we discovered the threat, followed our security protocol, immediately terminated all access and launched a comprehensive investigation that confirmed no compromise of assets or data, no malicious code deployed, and no impact to user security,” he said.
A Familiar Pattern for North Korean Hackers
This case is not an isolated event, but part of an increasingly familiar pattern across the crypto industry: North Korean hacking groups target digital asset companies through fake job applications or solicitations, aiming for positions that grant access to codebases. Once inside, they can steal funds, plant malicious code, or scout for security vulnerabilities.
In response to the incident, Consensys stated it will reevaluate its engineering and development outsourcing practices moving forward.
A Lesson for Everyone in Crypto
If a company of Consensys’s stature - whose products are used by millions to access Ethereum - can come so close to a compromise through recruitment channels, the threat is real for everyone. The good news is that layered defenses held firm before any damage occurred. But the incident serves as a reminder that in crypto, attacks don’t always come from outside the walls - sometimes they arrive applying to be your coworker.
Reported by Cointelegraph.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




