Svmuu News: According to a post by DeFi researcher @Zun2025 on X, “MetaMask hired a hacker linked to the DPRK as a developer without even conducting a proper background check—they could have uncovered his identity.”
The hacker’s GitHub account is imyugioh, and he has been publicly listed on the Lazarus Group website since September 2025, yet MetaMask still hired him in March 2026. Source: lazarus.group/team/mauro-liu. Just imagine—one of the largest wallets actually granted access to its core code repository to someone who had long been publicly listed as a DPRK hacker. Now think about what could happen to small protocols that have absolutely no security teams at all.”
In a previous report, a North Korean hacker named Tyler Knapp infiltrated the MetaMask team. He entered MetaMask through an outsourced HR vendor with whom the company had a long-standing partnership, bypassing the background checks required for direct hiring. He worked at the company for one month and participated in the development of the wallet’s fiat deposit and withdrawal features. During this period, he was detected by the company’s security monitoring due to abnormal IP activity and behavior. The company immediately revoked all his access privileges and suspended all product releases he had worked on. No substantial data or financial losses have occurred so far.