Blockchain company ConsenSys, which is behind the popular crypto wallet MetaMask, made a serious security mistake. A developer with ties to North Korea gained access to the company's internal systems and worked on the code for an entire month.
This incident sheds light on vulnerabilities in hiring processes even in technologically advanced organizations like ConsenSys. The programmer was brought in through a third-party service provider and was listed as an external consultant. His access to repositories and development systems was not promptly restricted.
Company management claims that signs of a threat were detected almost immediately after the collaboration began, and access was blocked in accordance with internal regulations. The investigation conducted did not reveal any data leaks or malicious changes to the code. Nevertheless, the very fact that a representative of the North Korean hacker ecosystem could work on MetaMask without hindrance raises serious questions.
This is not the first time North Korean developers have infiltrated cryptocurrency projects. Previously, similar incidents were recorded at Jump Crypto and other major industry players. Pyongyang actively uses fake resumes and front persons to embed its specialists in Western companies for the purpose of stealing funds or introducing backdoors.
My expert assessment: Although ConsenSys claims there were no consequences, such incidents undermine trust in the security of one of the most widely used crypto wallets in the world. The industry needs to implement stricter verification procedures for remote employees, especially from countries with a high level of cyber threats. One month of access to critical infrastructure is a sufficient period for the introduction of sophisticated espionage mechanisms that could be activated later.