A contractor linked to North Korea contributed to MetaMask code from March 9 until Consensys terminated access in April. The company found no evidence of asset theft, data compromise or malicious code.
Consensys said an internal April alert suspended all product releases while the matter was investigated. Staff were instructed not to interact with the consultant during that period.
General counsel Matt Corva stated the firm identified the threat quickly, cut off access and notified law enforcement. He noted that the service provider relationship had been viewed as reputable.
No user accounts or wallet assets were compromised, according to the company. Consensys has since reviewed its third-party service practices to apply stricter controls.
The incident involved code contributions only and did not affect deployed software or user funds.