
Fake Teams “Update” Led to $630K Crypto Theft
AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…
A suspected North Korean IT worker allegedly got hired by Consensys (MetaMask’s parent) using an alias and contributed to MetaMask’s core wallet code for about a month. The person was later removed, and Consensys says an investigation found no stolen assets, no data theft, and no malicious code shipped. The case highlights a realistic “fake contractor / fake identity” hiring workflow that security teams can simulate and train against.
A suspected North Korean IT worker allegedly used the alias "Tyler Knapp" to get hired by Consensys, MetaMask's parent company, as a consultant. The individual contributed to MetaMask's core wallet code for about a month before being identified and removed. Consensys says its investigation found no misappropriation of assets or data and no malicious code deployed. The person has also been linked to the GitHub username "imyugioh" and was reportedly flagged earlier on a public tracking site for known Lazarus Group operatives.
The case followed a pattern security teams increasingly need to plan for: a contractor is introduced through a trusted channel, quickly onboarded, and given access to sensitive repositories before independent verification is complete. According to Consensys's General Counsel, the individual "was introduced to us through an existing relationship with a reputable third-party service provider." This kind of introduction can create a false sense of assurance, since the trust placed in the referring party substitutes for direct identity verification of the person being hired.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A developer allegedly used the alias "Tyler Knapp" to get hired by Consensys, MetaMask's parent company, as a consultant and contributed to MetaMask code for about a month before being removed.
Consensys says its investigation found no misappropriation of assets or data and no malicious code deployed.
The individual was introduced through an existing relationship with a reputable third-party service provider, according to Consensys's General Counsel.
Watch for identities presented under aliases rather than verifiable legal identities, reliance on third-party introductions without independent verification, and contractors quickly receiving access to sensitive codebases.
Imagine this: a fake developer slips into the MetaMask wallet codebase under a totally made‑up name. They say, “Hi team, I’m Tyler Knapp, introduced by your third‑party provider, ready to start on the MetaMask repo.” GitHub handle? “imyugioh”, already listed on a public site tracking suspected DPRK IT workers. Consensys caught it fast, cut access, investigated, and confirmed no assets or data were stolen. But here’s the scary part: a fake identity still got a month of core wallet access because an intro from a “reputable” partner felt safe enough. Your move: before any contractor touches a sensitive repo, match their real legal identity to their online handles, GitHub, aliases, everything, or their access doesn’t go live. No match, no access.

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During…

Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and…

A researcher demonstrated that a Claude web-browsing agent could be manipulated by a fake “Cloudflare authentication” warning on a malicious website. Once the…

Researchers showed that an attacker can hide instructions inside an Azure DevOps pull request description so an AI coding agent follows the attacker’s…

Scammers are approaching Céline Dion fans on Facebook and steering them into paying for “tickets” outside official resale channels. Victims may even receive a…