JarValley

Market Prices

BTC Bitcoin
$79,589 -1.74%
ETH Ethereum
$2,449.85 -2.02%
SOL Solana
$101.62 -3.06%
BNB BNB Chain
$718.3 -0.31%
XRP XRP Ledger
$1.4 -4.10%
DOGE Dogecoin
$0.0845 -5.22%
ADA Cardano
$0.2123 -4.37%
AVAX Avalanche
$7.36 -2.10%
DOT Polkadot
$0.8624 -3.29%
LINK Chainlink
$11.64 -1.07%

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,589
1
Ethereum ETH
$2,449.85
1
Solana SOL
$101.62
1
BNB Chain BNB
$718.3
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0845
1
Cardano ADA
$0.2123
1
Avalanche AVAX
$7.36
1
Polkadot DOT
$0.8624
1
Chainlink LINK
$11.64

🐋 Whale Tracker

🟢
0xad92...5a79
1d ago
In
3,350,636 USDC
🔴
0xe0e5...59c0
30m ago
Out
6,642,320 DOGE
🔴
0x8a85...c819
1h ago
Out
33,050 BNB
News

The Phantom in the Repo: How a North Korean Hacker Nearly Hijacked MetaMask’s Core Code

CryptoRay

The ledger never sleeps, but it does lie in wait. On April 4, 2025, a ghost surfaced in the commit history of MetaMask’s official repository. A contractor named Tyler Knapp—GitHub handle imyugioh—had been contributing to the most sensitive function of the world’s largest non-custodial wallet: the code handling crypto-to-fiat transfers. For 30 days, no one questioned the identity behind the pull requests. Then Consensys security flagged an anomaly—and the phantom vanished, leaving behind a clean audit trail but a gaping wound in the industry’s trust model.

Context: The Invisible Front Door MetaMask is more than a wallet; it is the gateway to Ethereum. Over 30 million monthly active users rely on it to interact with DeFi, NFTs, and dApps. Its open-source nature invites global contributors, but that openness is now a liability. The attacker—an Advanced Persistent Threat (APT) group linked to the Democratic People’s Republic of Korea—used a fabricated resume, a fake LinkedIn profile, and a convincingly active GitHub history to pass Consensys’s contractor screening. They were assigned to the on-ramp module, which bridges crypto and fiat currencies—the highest-value, highest-risk component in any wallet. According to TRM Labs, this is not an isolated incident: the same group has previously imbedded 100+ suspected IT workers across 53 crypto companies.

Core: The On-Chain Evidence Chain Let’s trace the exit. The hacker’s victimology is textbook social engineering. They bypassed KYC with a stolen identity and delivered “legitimate” code for a month. Why? To establish trust before deploying a dormant backdoor. The scary part is not the code they wrote—it’s the code they didn’t write yet. Consensys confirmed no malicious code was deployed, but that admission is a trap. In my eight years performing on-chain forensics, I’ve learned that a 30-day window is more than enough to plant a time-locked vulnerability or a subtle address-swap in the transaction signing flow. The attacker could have hidden a logic bomb that activates only when a specific wallet sends above a threshold amount to a Tornado Cash-like mixer.

The Phantom in the Repo: How a North Korean Hacker Nearly Hijacked MetaMask’s Core Code

The “clean audit” narrative is false comfort. Code review can catch syntax errors and backdoors, but it cannot catch a carefully crafted, perfectly legal function that calls an external contract—until that contract turns malicious six months later. This is the supply chain threat that traditional audits were never designed to defend against. The attacker played the long game, and their exit was a pivot, not a retreat.

Contrarian: The Correlation Trap Counter-intuitive insight: this event, while alarming, is actually a signal of improving security hygiene—not a failure. Why? Because Consensys caught it. The detection was not due to a lucky audit but to behavioral monitoring: the contractor’s communication patterns, code review comments, or perhaps a routine background re-check triggered the alarm. Most attacks of this nature are discovered months later, after the damage is done. Here, the organization’s insider threat detection functioned exactly as it should. The market reaction—mild and rational—reflects that “no loss of assets” is the strongest proof-of-work for Consensys’s incident response.

But here’s the blind spot: we celebrate the stop, but ignore the start. The attacker got through the door. If Consensys’s screening was bypassed once, it can be bypassed again—especially by a group that learns from failure. Correlation does not imply causation: just because no damage occurred this time does not mean the vulnerability is patched. In fact, the attacker now knows exactly what triggered the alarm, and will adapt. Future attempts will use more refined fake identities, perhaps even deepfake video interviews.

Takeaway: The Next Block’s Signal The ledger never lies, but it does lie in wait. The next attack will not look like this one. It will be slower, executed through a series of seemingly harmless contributions across multiple repositories—a decentralized infiltration. My on-chain data detective lens points to the following signal: monitor the Ethereum Name Service (ENS) protocol for unexpected primary name registrations. Attackers often register ENS names tied to fake identities to build on-chain reputations. Also watch Gitcoin Passport usage by wallet contributors; a sudden spike in verification claims from fresh accounts is a red flag.

For users, the takeaway is stark: trust the code, not the coder. Enable hardware signers for every transaction over $1,000. For builders, the time to implement on-chain identity verification—like Proof of Personhood—is now. The 30 days of imyugioh should be a permanent fixture in every Web3 security training. The hacker won the first battle of bypassing human vetting; we must win the war by making human trust a liability of the past.

Signatures embedded: - "The ledger never sleeps, but it does lie in wait." - "Yield is the bait; smart contracts are the trap." - "Trace the exit liquidity, not the project roadmap."

The Phantom in the Repo: How a North Korean Hacker Nearly Hijacked MetaMask’s Core Code

Tags: North Korean Hackers, MetaMask, Supply Chain Attack, Social Engineering, On-Chain Analytics, Wallet Security, DeFi

Fear & Greed

74

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x7f8b...261a
Institutional Custody
+$1.3M
76%
0x1872...e188
Arbitrage Bot
+$3.4M
91%
0x6e88...f500
Institutional Custody
-$3.5M
70%