ConsenSys Denies MetaMask User Data Breach Amid Code Access Incident

icon币界网
Share
AI summary iconSummary
ConsenSys addressed reports of a security breach tied to MetaMask, confirming that an external consultant gained unauthorized access to its core codebase from March 9 to early April 2026. The consultant, Tyler Knapp, was not an employee but was engaged via a third-party firm to assist with fiat on-ramp and off-ramp features. ConsenSys suspended product releases, revoked access, and initiated an internal audit. No malicious code was deployed, and no user data or assets were compromised. The company also reported the incident to authorities. While inflation data remains a secondary concern, ConsenSys emphasized that the issue was resolved before any real harm occurred. Details regarding the third-party service remain undisclosed.
CoinMarketCap reports:

Consensys has responded to the incident involving access to the MetaMask codebase. The company disclosed that a consultant, introduced via a third-party service, had brief access to the core MetaMask codebase earlier this year; however, internal investigations found no malicious code deployed, and no user data or assets were compromised.

The involved personnel participated in the development of the fiat currency feature.

According to the company’s statement, the individual involved operated under the identity "Tyler Knapp" with the GitHub username imyugioh. This person was not a direct employee of ConsenSys but worked as an external consultant.

The company stated that the consultant submitted contributions directly to the MetaMask core codebase between March 9 and early April 2026, primarily concerning the wallet’s fiat on-ramp and off-ramp functionalities.

Pause publication after detecting a risk

Consensys stated that after identifying the risk, the company paused all product releases, revoked the consultant’s access, and initiated a comprehensive internal security audit. The company has also notified law enforcement authorities regarding this matter.

This incident has drawn attention because MetaMask is one of the most widely used wallets in the Ethereum ecosystem, and any access issue involving its core codebase raises concerns among users about the security of their assets and data.

The company stated that no actual damage was found.

Consensys subsequently posted a statement on X, stating that recent online descriptions of the severity of the incident were inaccurate. The company said the investigation revealed that the risk was contained before causing any actual impact.

Consensys stated that an internal investigation confirmed no malicious code was deployed, no customer assets or data were compromised, and user security, funds, and product safety were unaffected.

Additional information: ConsenSys has not disclosed the name of the third-party service provider in its statement, nor has it explained how the consultant gained access to the relevant development processes through external channels.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.