BNB $571.32 +0.39%
XRP $1.11 +1.31%
ETH $1,904.35 +1.90%
BTC $65,169.44 +0.90%
BNB $571.32 +0.39%
XRP $1.11 +1.31%
ETH $1,904.35 +1.90%
BTC $65,169.44 +0.90%
BREAKING
Digital Wallet

North Korean Developer Spent a Month Inside MetaMask’s GitHub Codebase

North Korean Developer Spent a Month Inside MetaMask's GitHub Codebase
North Korean Developer Spent a Month Inside MetaMask's GitHub Codebase

Community Trust ScoreVerified

87%
Real
Verified47 votes
Updated 15 hours ago

A suspected North Korean operative worked inside MetaMask’s core wallet code for roughly a month before getting caught. The developer, hired under the alias “Tyler Knapp,” made real contributions to MetaMask’s GitHub repository until April, when he was finally ousted after being flagged as a security threat.

Consensys, the parent company behind MetaMask, said Knapp was brought in through a reputable third-party service provider. That detail matters — it means the company didn’t hire him directly off the street. Someone vouched for him. And yet, according to security analyst Zun, Knapp’s alias had already appeared on a public database tracking North Korean IT workers back in September 2025. Months passed. He kept committing code. The database, run by the Security Alliance, exists specifically to help crypto and tech companies avoid hiring operatives linked to the Democratic People’s Republic of Korea. Knapp was listed there not just as “Tyler Knapp” but also under the name “Mauro Liu.” Both names tied back to the same person, the same threat.

Not a clean record, either.

Advertisement

A Trail Across Crypto’s Biggest Names

The GitHub username “imyugioh” connected the developer directly to MetaMask’s codebase. But MetaMask wasn’t close to his only stop. The Security Alliance’s tracking site linked him to MagicCraft, a Web3 gaming company, back in 2022. Then Napier Finance, a DeFi product firm, in 2023. His name also appeared alongside Ankr, Pickle Finance, and Clover Network. That’s a pretty wide footprint for someone operating under a fake identity. It’s not random either — it looks deliberate, a slow crawl through different corners of the crypto industry, picking up access and probably income along the way.

Zun was blunt about it. He criticized MetaMask and Consensys for not running a thorough background check, saying that kind of basic vetting could have stopped the hire before it started. The developer’s involvement in converting cryptocurrencies and fiat currencies for third-party payment firms added another layer of concern — that kind of financial access, in the wrong hands, can expose sensitive operations fast.

Consensys pushed back on the severity, at least in terms of damage. After terminating Knapp’s access, the company ran an internal investigation. Their conclusion: no assets stolen, no malicious code deployed, no user data compromised. MetaMask’s systems, they said, stayed clean. Whether you take that at face value probably depends on how much you trust internal investigations to catch everything.

This Pattern Keeps Repeating

Knapp’s case isn’t isolated. Before him, another North Korean operative surfaced in the space — someone identified first as “Moo” and later revealed as Keisuke Watanabe. That person worked at a Solana-based decentralized exchange before getting fired. Two cases, two different projects, two different fake identities. The method is basically the same each time: build a plausible work history, get introduced through a trusted channel, contribute enough to seem legitimate, and stay quiet.

The crypto industry runs heavily on remote work and pseudonymous contributors. That’s kind of baked into its culture — open-source development, GitHub handles, no one necessarily expecting a passport scan before merging a pull request. It’s a structure that works well for decentralization and works just as well for someone trying to slip in undetected.

And the Security Alliance’s database, as useful as it is, can only do so much if companies aren’t actively checking it before every hire. Knapp was flagged in September 2025. He kept working until April. That’s a gap worth examining.

What Consensys Says It Did Right

To be fair, once the identification came through, Consensys moved fast. Access terminated, investigation launched, results published. The company leaned on the fact that their security protocols held — no malicious code made it into production, no user funds were touched. For a wallet that handles billions in assets across millions of users, that’s the outcome that matters most. But the fact that someone got in at all, someone already flagged on a public list, is the part that’s hard to spin away.

Zun’s criticism didn’t really soften after the investigation results came out. The analyst’s position is pretty straightforward: if the database exists and the name is on it, you check before you hire. Full stop.

The broader industry is probably going to feel this one. North Korean operatives using fake identities to infiltrate crypto projects isn’t new — it’s been a documented concern for years, tied to state-level efforts to generate hard currency through illicit means. But each new case adds pressure on companies to tighten hiring pipelines, especially for roles touching core infrastructure like wallet code.

Consensys said the developer was introduced through a reputable third-party service. That third-party service has not been named publicly.

Frequently Asked Questions

Who is Tyler Knapp and what did he do at MetaMask?

Tyler Knapp is an alias used by a suspected North Korean operative who contributed to MetaMask’s core wallet code on GitHub for roughly a month before being identified and removed by Consensys.

Was MetaMask’s code or user funds compromised by the North Korean developer?

Consensys said its internal investigation found no malicious code deployed, no assets stolen, and no user data compromised during the developer’s time on the project.

Community Trust IndexHigh Confidence
87%
Real
Real87%13%Fake
47 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories