Consensys has responded to the incident involving access to the MetaMask codebase. The company disclosed that a consultant, introduced via a third-party service, had brief access to the core MetaMask codebase earlier this year; however, internal investigations found no malicious code deployed, and no user data or assets were compromised.
The involved personnel participated in the development of the fiat currency feature.
According to the company’s statement, the individual involved operated under the identity "Tyler Knapp" with the GitHub username imyugioh. This person was not a direct employee of ConsenSys but worked as an external consultant.
The company stated that the consultant submitted contributions directly to the MetaMask core codebase between March 9 and early April 2026, primarily concerning the wallet’s fiat on-ramp and off-ramp functionalities.
Pause publication after detecting a risk
Consensys stated that after identifying the risk, the company paused all product releases, revoked the consultant’s access, and initiated a comprehensive internal security audit. The company has also notified law enforcement authorities regarding this matter.
This incident has drawn attention because MetaMask is one of the most widely used wallets in the Ethereum ecosystem, and any access issue involving its core codebase raises concerns among users about the security of their assets and data.
The company stated that no actual damage was found.
Consensys subsequently posted a statement on X, stating that recent online descriptions of the severity of the incident were inaccurate. The company said the investigation revealed that the risk was contained before causing any actual impact.
Consensys stated that an internal investigation confirmed no malicious code was deployed, no customer assets or data were compromised, and user security, funds, and product safety were unaffected.
Additional information: ConsenSys has not disclosed the name of the third-party service provider in its statement, nor has it explained how the consultant gained access to the relevant development processes through external channels.

