← Back

security

Consensys Suspends MetaMask Releases After North Korea-Linked Contractor Access

Consensys halted MetaMask product releases after discovering a contractor with ties to North Korea had access to the wallet's code for about a month. The company reports no stolen assets or malicious code found.

AS1 NewsSource: thedefiant.io

securitymetamaskconsensysinfrastructurecybersecuritythird-party-riskblockchain
ETH$2,518.56+1.65%

Ethereum software firm Consensys suspended updates to MetaMask earlier this year after uncovering that a contractor connected to North Korea had access to the wallet's code for approximately one month. The contractor was engaged through a third-party service provider rather than directly by Consensys.

The company conducted an investigation and confirmed that no assets were stolen, nor was any data exposed or malicious code introduced during the breach. As a precaution, Consensys paused product releases to ensure security and integrity.

This incident was identified after security checks revealed the contractor's access, prompting the company to take immediate action. The breach highlights ongoing security challenges in the crypto infrastructure sector, especially concerning third-party vendors.

While the company has assured that no malicious activity occurred, the event underscores the importance of rigorous vetting and monitoring of third-party contractors involved in critical security functions within crypto projects.

The impact on MetaMask users appears limited, with no reported loss or compromise of funds. The incident may prompt other crypto firms to review their third-party security protocols, emphasizing the need for enhanced oversight.

Overall, this event serves as a reminder of the vulnerabilities in crypto infrastructure and the importance of strict security measures in maintaining user trust and system integrity.

neutral

The incident highlights ongoing security risks in crypto infrastructure, prompting increased vigilance among industry players.