Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Consensys Hired Suspected North Korean Hacker for MetaMask Wallet: Tyler Knapp Case Revealed

Consensys MetaMask Hired Suspected North Korean Hacker “Tyler Knapp” – What We Know

Sathish Kumar Kaliraj by Sathish Kumar Kaliraj
July 18, 2026
in Security & Hacks
0 0
Consensys Removed North Korea-Linked MetaMask Consultant After Month-Long Code Access

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

In a significant security lapse that has sent ripples through the cryptocurrency industry, blockchain giant Consensys, the company behind the widely used MetaMask wallet, inadvertently hired a developer with suspected ties to North Korea. The revelation, first reported by Drop Site News on July 17, 2026, underscores the persistent and evolving risks posed by state-sponsored actors targeting the crypto sector.

The “Tyler Knapp” Case: What Happened

According to internal communications obtained by Drop Site News, the individual operated under the alias “Tyler Knapp” and GitHub username imyugioh. He was onboarded as a consultant through a third-party service provider that Consensys had previously trusted.

Knapp’s contributions focused on core platform elements of MetaMask, particularly features related to on-ramps and off-ramps, the critical bridges between cryptocurrency and traditional fiat currencies. His work reportedly included code that handled interactions with third-party payment providers.

  • Timeline: GitHub activity began around March 9, 2026, and ceased abruptly in April 2026.
  • Duration: Approximately one month of internal access.
  • Discovery: Consensys General Counsel Matt Corva issued a company-wide alert in April, suspending product releases and ordering staff to cease all interaction with Knapp during the probe.

Corva later stated that the company’s security protocols identified the threat quickly. A full investigation confirmed no misappropriation of assets or data, no deployment of malicious code, and crucially, no impact on user safety or security. Law enforcement was notified.

“We’ve reviewed our practices for utilizing third-party services to ensure the rigorous standard which we apply to all of our employees is also followed in more complex third-party relationships.” — Matt Corva, General Counsel, Consensys

MetaMask Celebrates 10th Anniversary Amid Security Scrutiny

The incident comes shortly after MetaMask celebrated its 10th anniversary, marking a decade as one of Ethereum’s most important on-ramps. With tens of millions of users worldwide, any potential supply-chain risk to the wallet ecosystem carries major implications for decentralized finance and Web3 adoption.

Examining the GitHub Profile and Contributions

The imyugioh profile presents as a typical blockchain developer. Its bio reads “Ready or not, Spirit, This is where you take over,” with a location listed as “Domino City,” a clear reference to the Yu-Gi-Oh! franchise. The account has around 33 followers and holds GitHub Developer Program membership.

Pinned repositories prominently feature forks of major MetaMask projects, including MetaMask/core and MetaMask/metamask-mobile.

One of the final public contributions was Pull Request #28399, merged on April 5, 2026. This update fixed a problem that was preventing some users from properly seeing supported tokens when buying or selling crypto through the app’s ramp features.

Our Cryip team analyst reviewed the repositories and pull request commits in detail. The changes improved how the app checks which payment providers support specific tokens. The update was tested, reviewed by the team, and included before-and-after demonstration videos. It was merged into the next release shortly before the account’s access was revoked.

While the visible public contributions appear to be legitimate bug fixes aimed at improving user experience, the timing raises important questions. It is unclear whether any other modifications were made in private code or internal systems during the same period.

Consensys’ Position and Lessons Learned

In statements to Drop Site News, Matt Corva emphasized pride in the rapid response and highlighted ongoing collaboration with law enforcement. The company is conducting a broader review of outsourcing and third-party engineering practices, a necessary step given the decentralized and fast-moving nature of blockchain development.

MetaMask remains one of the most popular entry points to Ethereum. Any compromise in its supply chain could have had serious consequences for the wider ecosystem.

The Wider DPRK Threat Landscape

The Consensys incident is not isolated. North Korean IT workers and hackers have aggressively targeted the crypto industry for years, generating hundreds of millions, if not billions, in revenue for the regime.

  • Remote Job Infiltration: Operatives use stolen or fabricated identities, polished GitHub histories, and remote desktop tools to secure positions at Western tech and crypto firms. See our earlier report: Fake Job Candidate Exposed After Failing “Insult Kim Jong Un” Test (April 2026).
  • Financial Networks: On-chain investigator ZachXBT recently exposed an internal DPRK payment server processing over 3.5 million dollars in illicit remittances from IT workers. The platform, luckyguys.site, featured weak security and detailed hierarchies. Full coverage: ZachXBT Exposes DPRK Crypto Payment Network.
  • Exploit Surge: April 2026 recorded an alarming 625 million dollars in DeFi exploits, many linked to sophisticated North Korean groups such as Lazarus. Read: Record 625 Million Dollars in DeFi Exploits – April 2026.

Why Crypto Remains a Prime Target

Several factors make blockchain companies attractive:

  1. Remote-friendly roles with high salaries that can be funneled back to Pyongyang.
  2. Access to valuable intellectual property, smart contract logic, and sometimes direct wallet infrastructure.
  3. Relatively lighter background checks compared to traditional finance in some startups.
  4. The pseudonymous and borderless nature of crypto aligns with sanctions-evasion goals.

Researchers have documented cases spanning years, with North Korean workers embedded in DeFi protocols, wallets, and infrastructure projects. Behavioral indicators, such as hesitation on politically sensitive topics or sudden connection drops, are now part of the informal screening toolkit used by vigilant hiring managers.

Industry Implications and Recommendations

The incident serves as a wake-up call. Even well-resourced firms like Consensys can be breached through the supply chain. Smaller teams remain even more vulnerable.

Best Practices Emerging:

  • Multi-layered identity verification beyond resumes and GitHub.
  • Company-issued devices and restricted remote access tools.
  • Behavioral and technical interviews designed to detect inconsistencies.
  • Continuous monitoring of code contributions and internal access.
  • Collaboration with law enforcement and threat intelligence firms specializing in DPRK operations.

As the industry matures, expect tighter scrutiny on hiring, greater use of AI-assisted vetting, and possibly regulatory pressure to implement stronger supply-chain security standards.

Conclusion

The “Tyler Knapp” affair highlights both the ingenuity of North Korean cyber programs and the persistent vulnerabilities in the global remote workforce. While Consensys acted decisively once the threat was identified, the case illustrates how state actors can blend into open-source communities and development teams.

Original source material includes reporting by Drop Site News. GitHub profiles and pull requests are publicly accessible as of publication. This article contains independent analysis and context by Saravana Kumar Mahendran, a content writer and security analyst whose work has been cited by Halborn and Sherlock.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: Crypto ScamsMetaMaskNorth Korea
Sathish Kumar Kaliraj

Sathish Kumar Kaliraj

Sathish Kumar Kaliraj is a crypto journalist and data analyst at Cryip, covering on-chain activity, market movements, and regulatory developments across the crypto industry. His reporting combines statistical analysis and blockchain data verification, drawing on certifications in data journalism, fact-checking (IFCN, Google News Initiative), and journalism fundamentals (NBC Universal Academy). His work has been cited by Coincu, Tech Times, and Bitcoinist.

Related Posts

Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing
Policy & Regulation

Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

by Saravana Kumar Mahendran
August 8, 2026

The U.S. Treasury's Office of Foreign Assets Control sanctioned Dubai-based Shelbit Exchange and Tehran-based Aban Tether on Aug. 7, 2026,...

Read moreDetails
Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

August 8, 2026
oung people from the Russian regions looking for easy money

FSB Shuts Down Nine Illegal Moscow Crypto Exchanges Linked to Ukrainian Call-Center Fraud

August 8, 2026
MetaMask's New AI Wallet Caps Loss Protection at $10,000 a Month

MetaMask’s New AI Wallet Caps Loss Protection at $10,000 a Month

August 8, 2026
EU Warns Crypto Scammers Are Exploiting MiCA Transition as Users Move Funds

EU Warns Crypto Scammers Exploit MiCA Transition as Users Move Funds

August 6, 2026
Three Missouri Men Indicted in Connecticut Bitcoin Kidnapping Case, Then Fled Before Robbery

Three Missouri Men Indicted in Connecticut Bitcoin Kidnapping Case, Then Fled Before Robbery

August 5, 2026
Why the FBI Could Only Recover Part of the $1 Million an Agent Allegedly Stole

Why the FBI Could Only Recover Part of the $1 Million an Agent Allegedly Stole

August 4, 2026
Next Post
TrustedVolumes Attacker Returns 1,122 ETH

TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement

Cathie Wood Buys SpaceX Dip

Cathie Wood Buys SpaceX Dip as Stock Falls Below IPO Price

Recommended

  • All
  • Crypto News Today
Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support

Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support

August 8, 2026
Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

August 8, 2026
Trump Media Ends Crypto.com Partnership, Signaling Retreat From Its Crypto Expansion Plans

Trump Media Ends Crypto.com Partnership, Signaling Retreat From Its Crypto Expansion Plans

August 8, 2026
Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

August 8, 2026
Brazil Tightens Crypto Transfer Rules With 24-Hour Delay to Combat Fraud

Brazil Tightens Crypto Transfer Rules With 24-Hour Delay to Combat Fraud

August 8, 2026
oung people from the Russian regions looking for easy money

FSB Shuts Down Nine Illegal Moscow Crypto Exchanges Linked to Ukrainian Call-Center Fraud

August 8, 2026
MetaMask's New AI Wallet Caps Loss Protection at $10,000 a Month

MetaMask’s New AI Wallet Caps Loss Protection at $10,000 a Month

August 8, 2026
Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

August 7, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • South Africa’s Rand Stablecoin Lost to Dollar Tokens: Now the IMF Says That’s a Warning Sign
  • Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support
  • Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.