A serious security incident has occurred in the infrastructure of the blockchain company ConsenSys, which is behind the popular crypto wallet MetaMask. A developer linked to North Korea gained access to the company's internal systems and remained there for an entire month.
As it turned out, the programmer was hired through a third-party service provider and worked as an external consultant. According to official statements, ConsenSys's security team detected suspicious activity almost immediately after his connection and promptly blocked access in accordance with internal regulations.
Nevertheless, the very fact that a representative of the North Korean regime, known for its active cyber espionage activities and attacks on cryptocurrency projects, had direct access to MetaMask's code raises serious questions. The company's investigation did not reveal any data leaks or compromise of user assets, but the incident itself highlights vulnerabilities in the supply chains of even the largest market players.
Situation Analysis
Such incidents are not uncommon in the industry. North Korean hackers and developers often infiltrate crypto companies disguised as freelancers to implant backdoors or steal confidential information. The fact that ConsenSys managed to identify the threat in time is a positive signal, but it also serves as a reminder that even multi-level counterparty checks do not provide a 100% guarantee.
My professional assessment: The ConsenSys incident is a wake-up call for the entire ecosystem. If a North Korean developer was able to gain access to MetaMask's code — one of the most widely used crypto wallets with millions of users — it means that risks for decentralized applications remain extremely high. I recommend that all teams review their security protocols when working with remote specialists, especially those from regions with a high level of cyber threats.