No Result
View All Result
  • Login
Monday, July 20, 2026
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Cryptocurrency

MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases

by theadvisertimes.com
1 day ago
in Cryptocurrency
Reading Time: 5 mins read
A A
0
MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases
Share on FacebookShare on TwitterShare on LInkedIn


A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April. Consensys later described the person as linked to North Korea.

Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security. General counsel Matt Corva said the company identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement.

Drop Site reported that an internal April alert ordered all product releases suspended pending the investigation and told staff not to interact with the consultant. Corva called the service provider relationship reputable and said Consensys has since reviewed its third-party service practices, so the rigorous standards applied to employees also cover more complex outside relationships.

Compromised developers lying dormant within crypto projects risks next major crypto exploit
Related Reading

Compromised developers lying dormant within crypto projects risks next major crypto exploit

The bigger risk after Drift may be the access attackers gain before a protocol knows it has a problem.

Apr 8, 2026 · Gino Matos

Contractor checks need repository limits

The incident gives no indication that user accounts or wallet assets were compromised. Consensys’ existing relationship with the vendor still left a gap: every contractor and account needed its own safeguards.

Infographic showing the reported March-to-April MetaMask contractor contribution window, Consensys's no-impact findings, and seven controls for contractor identity, repository access, review, monitoring, and revocation.Infographic showing the reported March-to-April MetaMask contractor contribution window, Consensys's no-impact findings, and seven controls for contractor identity, repository access, review, monitoring, and revocation.

MetaMask’s general security guidance warns that malicious workers can use false identities and forged documents to obtain remote roles. It recommends checks using actual documents, multiple interviews, hardware authentication, IP and location verification, reference checks, and limits on access to critical systems.

Secret laptop footage exposes North Korean spies infiltrating US companiesSecret laptop footage exposes North Korean spies infiltrating US companies
Related Reading

Secret laptop footage exposes North Korean spies infiltrating US companies

Researchers watched in real-time as the Famous Chollima division used this common remote work setup to bypass firewalls.

Dec 3, 2025 · Oluwapelumi Adejumo

The FBI has separately warned that North Korean IT workers have used company-network access to copy code repositories. Its guidance calls for identity verification during interviews, onboarding and throughout employment, routine audits of third-party staffing firms, least-privilege access and monitoring for unusual remote connections or repository exfiltration.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

After onboarding, repository permissions and review become the core safeguards. UK National Cyber Security Center guidance recommends making repository activity attributable, reviewing every production-bound change, applying extra scrutiny to external contributions, and revoking access quickly when it is no longer required. Hardware-backed credentials can protect an account from credential theft, while tightly scoped permissions and independent review limit what an authorized account can change.

The next big DeFi exploit will start before the code is deployedThe next big DeFi exploit will start before the code is deployed
Related Reading

The next big DeFi exploit will start before the code is deployed

A new malware campaign targeting crypto developers shows how attackers can move upstream, stealing GitHub tokens, SSH keys, cloud credentials, wallets, and environment variables before a protocol ever ships vulnerable code.

May 26, 2026 · Gino Matos

CryptoSlate reported on July 5 that operational compromises around keys, custody, signing and approval systems accounted for roughly 76% of stolen value during the first half of 2026, even though smart-contract exploits were more frequent. That gap shows why access and operational controls matter even when they account for fewer incidents.

Wallet and protocol teams should treat contractor access as continuously conditional. Identity checks should extend through employment, third-party firms should be audited, repository privileges should remain narrow and observable, every production-bound change should receive independent review, and access should be revoked as soon as it is no longer required.

Consensys’s April release pause also shows the value of retaining a predefined way to halt changes while suspicious access is investigated.



Source link

Tags: CodeConsenSyscontractorHaltedKorealinkedMetamaskmonthNorthOpenReleases
ShareTweetShare
Previous Post

Infantino’s 60,000-mile World Cup odyssey — the FIFA chief’s whopping private jet trips don’t even include the funeral in Qatar

Next Post

Active Funds Can’t Beat the S&P 500? This One Didn’t Get the Memo

Related Posts

Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street

Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street

by theadvisertimes.com
July 20, 2026
0

Key TakeawaysThe Dow fell 307 points and the S&P 500 dropped 0.2% as the Iran war reached its 10th night...

Democrats Added Certain Consumer Protection Rules to CLARITY: Coinbase Exec

Democrats Added Certain Consumer Protection Rules to CLARITY: Coinbase Exec

by theadvisertimes.com
July 20, 2026
0

As lawmakers in the US Senate are likely to vote soon on the Digital Asset Market Clarity (CLARITY) Act, representatives...

Dogecoin Price Eyes Breakout as Whales Buy 200M DOGE and Open Interest Surges

Dogecoin Price Eyes Breakout as Whales Buy 200M DOGE and Open Interest Surges

by theadvisertimes.com
July 20, 2026
0

Dogecoin price hovered near $0.072 on Monday after posting a modest weekly gain. The broader cryptocurrency market remained largely steady,...

Bitcoin whale dumps 2 million 40x long right before liquidation can strike

Bitcoin whale dumps $122 million 40x long right before liquidation can strike

by theadvisertimes.com
July 20, 2026
0

A public Hyperliquid wallet valued at about $107 million on July 19 fully exited its 40x Bitcoin long on July...

‘Japan’s Wealth Is Returning’: Anonymous BOJ Insider Sparks Panic Over Looming Carry Trade Unwind

‘Japan’s Wealth Is Returning’: Anonymous BOJ Insider Sparks Panic Over Looming Carry Trade Unwind

by theadvisertimes.com
July 19, 2026
0

Key TakeawaysA BOJ insider warned Japan will unwind the yen carry trade, threatening global stock and crypto liquidity.Japan’s Finance Minister...

South Korea Uncovers 30 Cases Unfair Trading

South Korea Uncovers 30 Cases Unfair Trading

by theadvisertimes.com
July 19, 2026
0

South Korea’s financial authorities investigated more than 40 cases of unfair trading, including market manipulation and fraudulent crypto trading, in...

Next Post
Active Funds Can’t Beat the S&P 500? This One Didn’t Get the Memo

Active Funds Can’t Beat the S&P 500? This One Didn’t Get the Memo

Major car dealer cuts 40% of its locations, issues serious warning

Major car dealer cuts 40% of its locations, issues serious warning

  • Trending
  • Comments
  • Latest
SEC pushes private market access, but retail is already in

SEC pushes private market access, but retail is already in

July 16, 2026
How I Maximize My Sapphire Reserve Dining Credit

How I Maximize My Sapphire Reserve Dining Credit

July 10, 2026
Fourth of July 2026 Freebies and Deals

Fourth of July 2026 Freebies and Deals

July 3, 2026
5 things financial therapists want every advisor to know

5 things financial therapists want every advisor to know

June 26, 2026
Should You Offer a Concession to Get Your Apartment Leased Faster?

Should You Offer a Concession to Get Your Apartment Leased Faster?

June 15, 2026
The 10 Largest NYC Tech Startup Funding Rounds of June 2026 – AlleyWatch

The 10 Largest NYC Tech Startup Funding Rounds of June 2026 – AlleyWatch

July 6, 2026
Wildfire Smoke: Is Hazardous Air the New Normal?

Wildfire Smoke: Is Hazardous Air the New Normal?

0
70/20/10 Budget: Why Combining Needs & Wants Could Backfire

70/20/10 Budget: Why Combining Needs & Wants Could Backfire

0
Marsh & McLennan Companies (MRSH) Q2 2026 Preview: EPS Est. .89, Reports July 21

Marsh & McLennan Companies (MRSH) Q2 2026 Preview: EPS Est. $2.89, Reports July 21

0
Market Talk – July 20, 2026

Market Talk – July 20, 2026

0
Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street

Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street

0
FTC Says Some “Made in the USA” Claims May Mislead Shoppers

FTC Says Some “Made in the USA” Claims May Mislead Shoppers

0
Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street

Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street

July 20, 2026
FTC Says Some “Made in the USA” Claims May Mislead Shoppers

FTC Says Some “Made in the USA” Claims May Mislead Shoppers

July 20, 2026
Here’s How Much Coffee Is Safe to Drink Every Day, Research Says

Here’s How Much Coffee Is Safe to Drink Every Day, Research Says

July 20, 2026
Average retirement savings by state: Where are Americans saving the most — and least?

Average retirement savings by state: Where are Americans saving the most — and least?

July 20, 2026
Democrats Added Certain Consumer Protection Rules to CLARITY: Coinbase Exec

Democrats Added Certain Consumer Protection Rules to CLARITY: Coinbase Exec

July 20, 2026
Social Security Payments Arrive This Week—Who’s Eligible for Up to ,181?

Social Security Payments Arrive This Week—Who’s Eligible for Up to $5,181?

July 20, 2026
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Trump Vows Retaliation as 10th Night of US Strikes on Iran Rattles Wall Street
  • FTC Says Some “Made in the USA” Claims May Mislead Shoppers
  • Here’s How Much Coffee Is Safe to Drink Every Day, Research Says
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.