Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

Strategy (MSTR) Sells $263.5 Million In MSTR Shares, Skips Bitcoin Purchase As USD Reserve Tops $3.2 Billion

July 20, 2026

PI Network price nears $0.10 after 11% surge

July 20, 2026

Bitcoin ETF inflows return, but $2.3 billion stablecoin liquidity drain leaves $57,000 exposed

July 20, 2026
Facebook X (Twitter) Instagram
Monday, July 20 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases

July 19, 2026Updated:July 19, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases
Share
Facebook Twitter LinkedIn Pinterest Email
ad

A contractor introduced in by a third-party supplier labored on MetaMask code from March 9 till Consensys lower off entry in April. Consensys later described the individual as linked to North Korea.

Consensys stated its investigation discovered no misappropriation of belongings or knowledge, no malicious code deployment and no affect to consumer security or safety. Normal counsel Matt Corva stated the corporate recognized the menace rapidly, terminated entry, launched a complete investigation and notified legislation enforcement.

Drop Web site reported that an inner April alert ordered all product releases suspended pending the investigation and instructed employees to not work together with the guide. Corva known as the service supplier relationship respected and stated Consensys has since reviewed its third-party service practices, so the rigorous requirements utilized to workers additionally cowl extra advanced exterior relationships.

MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases
Associated Studying

Compromised builders mendacity dormant inside crypto initiatives dangers subsequent main crypto exploit

The larger threat after Drift often is the entry attackers acquire earlier than a protocol is aware of it has an issue.

Apr 8, 2026 · Gino Matos

Contractor checks want repository limits

The incident offers no indication that consumer accounts or pockets belongings have been compromised. Consensys’ current relationship with the seller nonetheless left a niche: each contractor and account wanted its personal safeguards.

Infographic showing the reported March-to-April MetaMask contractor contribution window, Consensys's no-impact findings, and seven controls for contractor identity, repository access, review, monitoring, and revocation.Infographic showing the reported March-to-April MetaMask contractor contribution window, Consensys's no-impact findings, and seven controls for contractor identity, repository access, review, monitoring, and revocation.

MetaMask’s common safety steering warns that malicious staff can use false identities and solid paperwork to acquire distant roles. It recommends checks utilizing precise paperwork, a number of interviews, {hardware} authentication, IP and site verification, reference checks, and limits on entry to important programs.

Secret laptop footage exposes North Korean spies infiltrating US companiesSecret laptop footage exposes North Korean spies infiltrating US companies
Associated Studying

Secret laptop computer footage exposes North Korean spies infiltrating US firms

Researchers watched in real-time because the Well-known Chollima division used this widespread distant work setup to bypass firewalls.

Dec 3, 2025 · Oluwapelumi Adejumo

The FBI has individually warned that North Korean IT staff have used company-network entry to repeat code repositories. Its steering requires id verification throughout interviews, onboarding and all through employment, routine audits of third-party staffing corporations, least-privilege entry and monitoring for uncommon distant connections or repository exfiltration.

CryptoSlate Every day Temporary

Every day alerts, zero noise.

Market-moving headlines and context delivered each morning in a single tight learn.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, seems like there was an issue. Please strive once more.

You’re subscribed. Welcome aboard.

After onboarding, repository permissions and evaluation turn out to be the core safeguards. UK Nationwide Cyber Safety Heart steering recommends making repository exercise attributable, reviewing each production-bound change, making use of additional scrutiny to exterior contributions, and revoking entry rapidly when it’s now not required. {Hardware}-backed credentials can shield an account from credential theft, whereas tightly scoped permissions and unbiased evaluation restrict what a certified account can change.

The next big DeFi exploit will start before the code is deployedThe next big DeFi exploit will start before the code is deployed
Associated Studying

The following large DeFi exploit will begin earlier than the code is deployed

A brand new malware marketing campaign focusing on crypto builders exhibits how attackers can transfer upstream, stealing GitHub tokens, SSH keys, cloud credentials, wallets, and atmosphere variables earlier than a protocol ever ships susceptible code.

Might 26, 2026 · Gino Matos

CryptoSlate reported on July 5 that operational compromises round keys, custody, signing and approval programs accounted for roughly 76% of stolen worth through the first half of 2026, despite the fact that smart-contract exploits have been extra frequent. That hole exhibits why entry and operational controls matter even after they account for fewer incidents.

Pockets and protocol groups ought to deal with contractor entry as constantly conditional. Id checks ought to lengthen by employment, third-party corporations ought to be audited, repository privileges ought to stay slender and observable, each production-bound change ought to obtain unbiased evaluation, and entry ought to be revoked as quickly as it’s now not required.

Consensys’s April launch pause additionally exhibits the worth of retaining a predefined option to halt modifications whereas suspicious entry is investigated.

ad
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

Strategy (MSTR) Sells $263.5 Million In MSTR Shares, Skips Bitcoin Purchase As USD Reserve Tops $3.2 Billion

July 20, 2026

BTC Price Focus Turns To $67,000 Despite Iran Risk-Asset Pressures

July 20, 2026

Ethereum bridge users have 24 hours to exit before chain shuts down after just 5 week warning

July 20, 2026

Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit

July 20, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
Strategy (MSTR) Sells $263.5 Million In MSTR Shares, Skips Bitcoin Purchase As USD Reserve Tops $3.2 Billion
July 20, 2026
PI Network price nears $0.10 after 11% surge
July 20, 2026
Bitcoin ETF inflows return, but $2.3 billion stablecoin liquidity drain leaves $57,000 exposed
July 20, 2026
BTC Price Focus Turns To $67,000 Despite Iran Risk-Asset Pressures
July 20, 2026
Polymarket odds put July Fed hold at 93% after inflation broadens report
July 20, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.