Author: Liam 'Akiba' Wright
Compiled by: Deep Tide TechFlow
Deep Tide Insights: A North Korean-linked contractor gained access to the MetaMask codebase through a third-party vendor, working from March 9th until being removed in April. Although Consensys stated that no asset theft or malicious code was found, this incident exposed a critical vulnerability in the outsourcing management of crypto projects—about 76% of stolen DeFi funds result from operational-level permission failures, not code vulnerabilities.
A contractor introduced by Consensys via a third-party vendor began participating in MetaMask code work on March 9th and was not cut off until April. Consensys later described the individual as having ties to North Korea.
Consensys stated that their investigation found no evidence of misappropriated assets or data, no deployment of malicious code, and no impact on user security. General Counsel Matt Corva said the company quickly identified the threat, terminated access, launched a comprehensive investigation, and notified law enforcement.
Drop Site reported that an internal alert in April requested a pause on all product launches to cooperate with the investigation and instructed employees not to interact with the consultant. Corva described the service vendor relationship as a good one, and Consensys has since reviewed its third-party service practices, extending the stringent standards applied to employees to more complex external relationships.
Contractor Screening Requires Codebase Permission Restrictions
There is no indication that user accounts or wallet assets were compromised in this incident. However, a vulnerability persists in Consensys's existing relationship with vendors: each contractor and account requires its own safeguards.
MetaMask's general security guidelines warn that malicious actors can use fake identities and forged documents to obtain remote positions. It recommends verifying with physical documents, conducting multiple interviews, using hardware authentication, IP and location verification, background checks, and restricting access to critical systems.
The FBI additionally warns that North Korean IT workers leverage company network access to copy codebases. Its guidelines call for identity verification during interviews, onboarding, and throughout employment; regular audits of third-party staffing firms; least-privilege access; and monitoring for anomalous remote connections or codebase exfiltration.
Codebase Permissions and Review are Core Safeguards
After onboarding, codebase permissions and review become core safeguards. UK National Cyber Security Centre guidelines recommend making codebase activity traceable, reviewing every production environment change, conducting additional scrutiny on external contributions, and swiftly revoking access when it is no longer needed. Hardware-backed credentials can protect accounts from credential theft, while strictly defined permissions and independent reviews can limit the changes an authorized account can make.
CryptoSlate reported on July 5th that in the first half of 2024, operational-level attacks surrounding keys, custody, signatures, and approval systems accounted for approximately 76% of stolen funds, despite smart contract vulnerabilities being more frequent. This gap illustrates why access and operational controls are important, even if they cause fewer incidents numerically.
Wallet and protocol teams should treat contractor access as continuously conditional. Identity checks should persist throughout employment, third-party firms should be audited, codebase permissions should remain narrow and observable, every production change should undergo independent review, and access should be revoked immediately once it is no longer needed.
Consensys pausing releases in April also demonstrates the value of retaining predefined methods to halt changes for use when investigating suspicious access.





