ads
bc-game

MetaMask code was exposed to a company linked to North Korea

2 min read
PortalCripto
MetaMask code was exposed to a company linked to North Korea
Source: Ray Hennessy/Unsplash — MetaMask code was exposed to a company linked to North Korea
Give preference to us on Google
Advertisement

The source code of the wallet MetaMask was accessible for about a month to a contractor linked to a third-party company that was later associated with North Korea. The case occurred between March 9 and April, a period in which the professional worked in Consensys repositories before having their access terminated by the company.

According to Consensys, the investigation internal investigation concluded that there was no theft of assets, leakage of user data, insertion of malicious code, or any impact on the security of the wallets. After identifying the situation, the company immediately revoked the contractor's permissions, launched a full inquiry, and reported the case to the authorities.

The company's chief legal officer, Matt Corva, stated that the threat was detected quickly and that the relationship with the third-party supplier had been considered trustworthy until then. After the incident, Consensys began expanding its controls so that external partners follow the same security standards required of internal employees.

During the investigation, an internal notice ordered the temporary suspension of product launches and instructed employees not to maintain contact with the contractor while the analysis was underway.

Although the episode did not compromise MetaMask users' accounts or funds, it revealed a gap in third-party management processes. The company highlighted that each contractor must have individual security controls, including permissions limited to repositories and their own authentication mechanisms.

MetaMask's security recommendations also warn that malicious actors may use false identities and altered documents to secure remote positions. Suggested measures include rigorous document validation, multiple interviews, hardware authentication, verification of location and IP address, checking professional references, and limiting access to the most sensitive systems.

U.S. authorities have also warned companies about IT workers linked to North Korea who seek access to corporate networks to copy code repositories. The guidelines include frequent audits of suppliers, application of the principle of least privilege, monitoring of unusual remote connections, and independent review of every change intended for production.

After the onboarding of new collaborators, specialists point out that continuous control of permissions becomes essential. Tracking activities in repositories, immediate revocation of unnecessary access, and mandatory review of changes are measures considered fundamental to reduce operational risks in projects linked to cryptocurrencies and digital wallets.

Tags
Advertisement