North Korea-linked contractor accessed MetaMask code for a month

A contractor linked to North Korea contributed to MetaMask code from March 9 until Consensys terminated access in April. The company found no evidence of asset theft, data compromise or malicious code.

Consensys said an internal April alert suspended all product releases while the matter was investigated. Staff were instructed not to interact with the consultant during that period.

General counsel Matt Corva stated the firm identified the threat quickly, cut off access and notified law enforcement. He noted that the service provider relationship had been viewed as reputable.

No user accounts or wallet assets were compromised, according to the company. Consensys has since reviewed its third-party service practices to apply stricter controls.

The incident involved code contributions only and did not affect deployed software or user funds.

Related Articles

Illustration of a hacked Polymarket wallet showing $520,000 being drained on the Polygon blockchain.
Image generated by AI

Polymarket internal wallet drained of over $500,000

Reported by AI Image generated by AI

A private key compromise led to a drain of more than $520,000 from a Polymarket-linked wallet on the Polygon blockchain on May 22. The prediction market platform confirmed that user funds and core contracts remained unaffected.

Hackers stole roughly $3.1 million in PUSD tokens from 11 user wallets on the prediction platform. The theft followed a phishing attack that exploited a compromised third-party vendor.

Reported by AI

MetaMask has introduced a new wallet designed for AI agents to conduct decentralized finance trades while maintaining user oversight. The launch was announced Monday by the Consensys-owned provider. It includes built-in security measures such as transaction simulations and spending controls.

Jaredfromsubway.eth, a prominent Ethereum MEV bot, lost more than $7.5 million after approving attacker-controlled contracts that enabled an allowance drain. The incident occurred through a series of fake trading routes set up over several weeks. Security firm Blockaid identified the exploit as targeting the bot's automated approval logic rather than private keys or protocol flaws.

Reported by AI

South Korean prosecutors have arrested the creators of the Solana-based meme coin CatFi over allegations of a rug pull that caused around $599,000 in investor losses. The arrests mark the first application of the country's new Virtual Asset User Protection Act. The coin surged 6,000 percent following the detentions.

MetaMask has introduced a new Money Account that combines stablecoin yield, spending and trading in one self-custodial product. The feature is built on the Monad blockchain and centers on the company's mUSD stablecoin.

Reported by AI

Allbridge Core has paused its cross-chain stablecoin protocol after losing roughly 1.65 million dollars in a flash loan attack on its Solana liquidity pools. The attacker used a 1.12 million dollar flash loan from Kamino to manipulate pool ratios before withdrawing assets and bridging them to Ethereum.

 

 

 

This website uses cookies

We use cookies for analytics to improve our site. Read our privacy policy for more information.
Decline