Consensys responded to a visit to the MetaMask Code Library. The company disclosed that a consultant introduced through a third-party service provider had brief access to the MetaMask Core Code Library earlier in the year, but that internal investigations had not found that malicious codes had been deployed and that user data and assets had not been affected.

Participation of persons involved in the development of French currency functions

According to the company, the persons involved used the “Tyler Knapp” identity, and GitHub user name was imyugioh. The person was not a direct employee of Consensys, but was involved as an outside consultant.

According to the company, during the period from 9 March to the beginning of April 2026, the consultant submitted information directly to the MetaMask Core Code Library, mainly relating to the financial and gold-producing functions of the wallet.

Pause release after risk is detected

Consensys stated that after identifying the risks, the company suspended all product issuances, terminated the consultant ' s access rights and initiated a full internal security audit. At the same time, the company has notified the law enforcement authorities of the matter.

The incident was brought to the fore because MetaMask was one of the most widely used purses in the hawk ecology, and any access to the core code library would raise external concerns about user assets and data security.

The company claimed no actual damage was discovered

Consensys subsequently issued a statement on platform X stating that there were errors in the recent description of events on the Internet. According to the company, the results of the survey showed that this risk was controlled before it actually had an impact.

Consensys stated that internal investigations confirmed that no malicious code had been online, that no customer assets or data had been leaked, and that user, financial and product safety had been compromised.

Additional information:Currently, Connsensys does not disclose the name of the third-party service provider in its statement, nor does it indicate how the consultant entered the development chain through an external process.