Consensys is facing new questions over its development security practices after revealing that a contractor later identified as linked to North Korea had access to MetaMask code for roughly a month. According to the available details, the worker was brought in through a third-party provider and had access from March 9 until the company cut off access in April.

The company said its review found no compromised assets or data, no deployment of malicious code, and no impact on users. Even so, the disclosure has drawn attention because MetaMask is one of the best-known crypto wallet products, making any internal access issue a sensitive matter for the broader digital asset sector.

The episode appears to center less on an observed breach and more on how outside contractors are vetted and monitored when working on critical software. The fact that releases were halted before access was removed is likely to intensify scrutiny of internal controls, vendor management, and the speed of response once concerns emerged.

For Consensys, the incident highlights the ongoing challenge of securing software supply chains in crypto and beyond. While the company says it found no evidence of user harm, the case is likely to remain a point of focus as observers assess how major blockchain firms manage contractor permissions and development risk.