eading Ethereum software firm Consensys has firmly denied rumors that user data or funds were compromised after a North Korea-linked IT worker temporarily gained access to the core codebase of its popular Web3 wallet, MetaMask.
The security incident, which took place earlier this year, involved an individual operating under the alias "Tyler Knapp" (GitHub username: imyugioh). The individual was not a direct employee of Consensys, but was instead engaged as a consultant through an unnamed third-party provider.
Between March 9 and early April 2026, the contractor contributed directly to MetaMask’s core codebase, specifically working on the wallet's fiat on-ramp and off-ramp features.
Upon detecting the threat, Consensys took immediate and aggressive action. The firm froze all product releases, swiftly terminated the contractor's access, and launched a comprehensive internal security audit. The company also confirmed that it has notified law enforcement agencies regarding the infiltration.
Correcting misinformation
In a public statement released on X (formerly Twitter), Consensys sought to correct recent misinformation circulating online about the severity of the breach.
"Earlier this year, we identified and contained a threat from an individual engaged as a consultant through a third-party provider," the company stated. "After the threat was quickly identified, we immediately terminated all access, launched a comprehensive investigation, and notified law enforcement."
To reassure its massive user base, Consensys emphasized the results of its internal audit, confirming that the threat was neutralized before any damage could occur.
"Our investigation confirmed no malicious code was deployed, no customer assets or data were compromised, and there was no impact to user safety, funds, or security," the firm concluded.