CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MetaMask hired suspected North Korean dev flagged months earlier

CryptaCount Editorial · · 5 min read
AML / KYC / LICENSING MetaMask hired suspected North Koreandev flagged months earlier

According to a report published by Protos on 20 July 2026, the crypto wallet firm MetaMask engaged a developer whom the report describes as a suspected North Korean mole, and who a security analyst says had already been listed on a public tracking page almost a year before the engagement. Protos attributes the account to reporting by DropSite News and to claims made by a DeFi security analyst known as Zun.

The report states that the developer was reportedly hired by MetaMask's parent firm, Consensys, as a consultant while posing under the alias "Tyler Knapp". According to Protos he reportedly made GitHub contributions to MetaMask's wallet until he was ousted by the company in April. The report's standfirst describes him as having worked on MetaMask's core wallet code "for a whole month".

What does the report say about the MetaMask North Korea developer?

The central claim is attributed to Zun. Protos writes that Zun claims that Knapp "had already been flagged on a public Lazarus Group operative tracking site back in September 2025". That is presented in the report as Zun's claim rather than as an established finding, and Protos does not report that Consensys has confirmed it.

The tracking page is run by the Security Alliance. According to the report, it "creates profiles for known remote Democratic People's Republic of Korea (DPRK) IT workers in the hopes that it will help companies to identify them before they're hired". On that site, the report says, the person using the Knapp alias appears under the name "Mauro Liu", and is linked to MetaMask through the GitHub username "imyugioh".

The report also sets out prior engagements attributed to the same profile. It says he "appears to have worked for" Web3 game firm MagicCraft in 2022 and DeFi product firm Napier Finance in 2023. The other firms listed on the profile, according to Protos, are:

  • Ankr
  • Pickle Finance
  • Harmoney
  • Gamerse
  • Clover Network
  • DEPO
  • Sifu Vision
  • Oxytocin
  • Tomodachi
  • Blueberry

The hedge is the report's own: Protos writes "appears to have worked for" of the MagicCraft and Napier Finance entries, and presents the remainder as firms listed on the profile. The report does not state that any of those companies confirmed an engagement, and it does not carry comment from them.

What did Consensys say about the developer?

Consensys's General Counsel, Matt Corva, told DropSite that the developer "was introduced to us through an existing relationship with a reputable third-party service provider".

Corva is quoted further: "Very quickly after being introduced, we discovered the threat, followed our security protocols, immediately terminated any access and launched a comprehensive investigation that confirmed there was no misappropriation of assets or data, no malicious code deployed, and no impact to user safety and security."

That statement is the company's own account of its own investigation. Protos does not report an independent verification of it, and reports no regulatory or law enforcement finding.

What code did the developer have access to?

Beyond the wallet contributions, the report says DropSite "reports, based on internal Slack messages, that Knapp was also contributing to code involving the conversion of crypto and fiat currency by third-party payment firms". Protos does not name those payment firms, does not describe the contributions in any detail, and does not state that any defect or backdoor was found in that code. Corva's statement, as quoted, says no malicious code was deployed.

Why the MetaMask North Korea developer case is a hiring-controls question

Read narrowly, the report describes a screening question rather than a confirmed loss. On the company's own account, quoted above, no assets or data were misappropriated and no user impact was found. The contested point in the report is timing: whether information that would have identified the individual was already public before the engagement began.

That is what makes the Security Alliance page central to the story. Protos describes its purpose as helping companies identify remote DPRK IT workers "before they're hired" — that is, as a pre-engagement control rather than a post-incident one. Zun's claim, as reported, is that MetaMask hired the developer without a "proper background check that would have caught him".

Consensys, in the quoted statement, says the introduction came through "an existing relationship with a reputable third-party service provider", which places part of the vetting question with an intermediary rather than solely with the hiring firm. Protos does not name that provider and does not report any comment from it.

For any firm that engages contractors through intermediaries, the shape of the problem described in the report is procedural rather than technical: an introduction that carries implied assurance, and a public list that is only useful to the companies that actually consult it. Nothing in the report establishes what checks were or were not carried out. Zun's characterisation is a claim; Consensys's statement addresses what the firm did after discovery rather than what it did before the hire.

What happened in the Stabble case?

The report closes with an earlier incident it presents as comparable. It says that "last April, a North Korean mole called 'Moo' was named by crypto sleuth ZachXBT and was fired from Solana-based DEX Stabble". According to Protos the firm "subsequently encouraged all of its users to withdraw all their funds". The report states that Moo, "real name Keisuke Watanabe, was, by its own admission, employed by Stabble for a whole year".

The phrase "by its own admission" is the report's wording. Protos does not set out what that admission consisted of, where it was made, or by whom it was recorded.

What has not been established?

Several elements of the account are attributed rather than confirmed, and they are worth separating:

  • That the individual was flagged in September 2025 is Zun's claim, as reported by Protos.
  • The identification of the alias with the "Mauro Liu" profile and the "imyugioh" GitHub account is drawn from the Security Alliance page as described by Protos.
  • The earlier employment history carries the report's own hedge, "appears to have worked for".
  • The account of the internal Slack messages is DropSite's reporting.
  • The finding of no misappropriation is Consensys's, from an investigation it conducted itself.

Protos does not report a charge, a sanctions designation, a regulatory action or a court finding against any individual named in its article, and nothing here should be read as one. The full report is available from Protos.

USGLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
OFAC Sanctions Iranian Exchange BitBank Over IRGC Bitcoin Transfers
AML/KYC & Licensing
US Sanctions Iran's BitBank Over IRGC Bitcoin Transfers
AML/KYC & Licensing
Al-Qassam Brigades DOJ Filing: What Crypto Firms Must Know Now
AML/KYC & Licensing
Terrorist Financing Shifts to USDT on TRON: 25 Years After 9/11