MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases

Summary

A third-party contractor worked on MetaMask code from March 9 until Consensys revoked access in April after linking the person to North Korea. Consensys said the investigation found no stolen assets or data, no malicious code, and no user safety impact. It also said it quickly detected the risk, cut access, investigated, notified law enforcement, and later tightened third-party controls. Reports said an internal alert paused product releases and told staff not to engage the consultant. The incident highlights that vendor relationships still need contractor-specific safeguards. Recommended defenses include strong identity verification, multiple interviews, hardware-backed authentication, location/IP checks, reference checks, least-privilege access, continuous monitoring, and fast revocation. Repository security should make activity attributable, require independent review of production-bound changes, and limit what any contractor can change. A predefined release freeze is also useful during suspicious-access investigations.