MetaMask’s Close Call: North Korean Hacker Hid in Its Fiat Ramp Code for a Month (And This Is Just the Tip of the Iceberg)

(SeaPRwire) –

By: Lucas Caldwell

MetaMask, the crypto wallet used by 30 million monthly users, just dodged a bullet. A North Korean hacker using the alias Tyler Knapp slipped into its development team as a contractor. He worked on the fiat on-off ramp—one of the most sensitive parts of the codebase—for nearly a month. The kicker? He came through a long-term HR vendor, bypassing standard background checks. This isn’t a random breach; it’s a targeted insider play.

Knapp’s GitHub handle was imyugioh. His code contributions ran from March 9 to April 2026. Consensys, MetaMask’s parent company, caught him via unusual IP activity and behavioral red flags from its security tools. The good news? No funds or user data were stolen, and no malicious code made it into production. But the close call is chilling.

Once Consensys identified the threat, it revoked all of Knapp’s access immediately. General counsel Matt Corva told staff to halt all product releases linked to the contractor. The firm also alerted law enforcement and started reviewing its contractor vetting process. Corva confirmed no harm was done, but the incident exposed a critical gap in third-party hiring.

This isn’t an isolated case. North Korean operatives routinely pose as software engineers to land remote crypto jobs. An Ethereum-funded project recently found 100 suspected North Korean IT workers across 53 crypto projects. TRM Labs says developer access is now the fastest path to systems that approve crypto withdrawals.

The financial stakes are massive. In 2025, North Korean hackers stole $1.5 billion from Bybit and accounted for over half of the $2.7 billion lost to crypto hacks that year. US courts have jailed Americans who helped these operatives appear locally based. Some crypto firms are now sharing threat intel to catch these actors earlier.

By 2027, crypto firms will either mandate in-person onboarding for all contractors or face state-sponsored insider breaches that destroy user trust beyond repair.

Author bio: Lucas Caldwell, a tech opinion leader with millions of followers on X/Twitter, focuses on crypto security and emerging industry threats.