Crypto
Home›Crypto›Regulation›Consensys halted MetaMask code releases after a North…
Consensys halted MetaMask code releases after a North Korea-linked contractor
Consensys said its investigation found no compromised assets or user impact, and it reviewed its third-party service practices after cutting off access in April.
Consensys stopped MetaMask code releases after it determined a contractor working through a third-party provider was linked to North Korea, with access running from March 9 until Consensys cut it off in April, according to CryptoSlate. In a company statement shared by CryptoSlate, Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment, and no impact to user safety or security. Consensys general counsel Matt Corva said the firm identified the threat quickly, terminated access, launched a comprehensive investigation, and notified law enforcement. CryptoSlate also reported that an internal April alert ordered all product releases suspended pending the investigation and instructed staff not to interact with the consultant. Corva characterized the service provider relationship as reputable, but said the incident highlighted that contractors and accounts still require safeguards similar to those applied to employees. MetaMask security guidance cited by CryptoSlate warns that malicious workers can use false identities and forged documents to obtain remote roles, and it recommends identity and access controls such as verified documentation, hardware authentication, IP and location verification, and least-privilege access. The article also references broader government warnings, including FBI guidance about North Korean IT workers targeting company-network access to copy code repositories, and UK National Cyber Security Center recommendations to improve repository accountability, review production-bound changes, apply scrutiny to external contributions, and revoke access quickly when no longer needed.