Fort Worth-based blockchain firm Consensys, creator of the popular Ethereum-based MetaMask crypto wallet, accidentally hired a software developer linked to North Korea, according to internal messages obtained by Drop Site News.
North Korean nationals have increasingly targeted American software companies, posing as engineers and securing software development roles in order to expropriate trade secrets or infiltrate the software development supply chain. The DPRK-linked engineer, who was hired by Consensys as a consultant, used the alias “Tyler Knapp” and GitHub handle “imyugioh.”
The revelation comes as Republican senators are planning to brief President Donald Trump on new crypto legislation, the Clarity Act, details of which have yet to be released publicly.
Internal Slack communications indicate “Knapp” worked on core platform code for the MetaMask wallet, and contributed to parts of the platform related to conversion between crypto and fiat currency via third-party payment providers. Drop Site has confirmed that the public GitHub profile associated with “Knapp” also made contributions to MetaMask’s mobile wallet platform; his contributions abruptly stopped in April 2026—the same time his access to the Consenys team was terminated. The contributions began on March 9, meaning the actor had roughly a month to roam inside the system.
“‘Knapp’ was introduced to us through an existing relationship with a reputable third-party service provider,” Consensys’s general counsel Matt Corva said in a statement to Drop Site. “Very quickly after being introduced, we discovered the threat, followed our security protocols, immediately terminated any access and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security. We notified law enforcement and provided them with all relevant information.”
Corva did not say how Consensys determined the consultant was linked to North Korea. In April, Corva issued a company-wide alert regarding an investigation into “Tyler Knapp,” ordering “All product releases are to be suspended immediately pending investigation.” He added, “Do not interact with this individual while we perform our investigation.”
Corva ended with a plea to “Please keep this matter internal and confidential while we investigate.” The messages obtained by Drop Site indicate that Consensys’ investigation ultimately identified “Knapp” as connected to the Democratic People’s Republic of Korea.
“Regarding the DPRK-linked persona, we are proud of our response and security protocols, which quickly identified the threat,” Corva said in a statement.
Corva argued that the “incident demonstrated that our security protocols and the organization’s security-first principles are working, even against persistent and complex nation-state level threats,” He suggested that these protocols included close collaboration with law enforcement to identify security threats. Still, he said, the company has launched a review of its practices for outsourcing engineering and development work. “We’ve reviewed our practices for utilizing third-party services, including existing relationships, to ensure the rigorous standard which we apply to all of our employees is also followed in more complex third-party relationships,” he said.
Several North Korean nationals have recently been caught obtaining remote work in the United States under false pretenses. Crypto firms are unusually sensitive targets because an engineer’s ordinary access may extend beyond source code to transaction-signing infrastructure, where stolen assets can be moved across chains without first passing through a bank. Infrastructure for bypassing international banking regulations is valuable to organized crime groups and national intelligence services in countries under economic sanctions.
In May 2024, a woman from Arizona was arrested for running a ‘laptop farm’ from her house, allowing North Korean IT workers to use US residential internet service providers, to give the appearance of working from within the United States. The scheme earned more than $17 million in illicit revenue for Chapman and the DPRK-based entities. She was sentenced in July of last year.
In May this year, federal judges sentenced two American nationals to 18 months in prison for their roles in separate schemes facilitating North Korean remote IT workers. The Department of Justice said the schemes generated more than $1.2 million and affected nearly 70 U.S. companies.
Cryptocurrency is a special area of interest for the North Korean government starved of foreign exchange; consequently, the country has become one of the biggest sources of crypto related scams and heists in the world. According to an estimate by blockchain intelligence firm TRM Labs, nearly $700 million, or 66%, of all dollars stolen in crypto hacks can be attributed to North Korea-linked activity. One of the biggest crypto heists in history, the ByBit hack, estimated to be worth $1.5 billion, was reportedly conducted by North Korean hackers last year.
Click Here For The Original Source.

