JarValley

Market Prices

BTC Bitcoin
$66,282.4 +3.17%
ETH Ethereum
$1,940.46 +4.05%
SOL Solana
$78.4 +2.23%
BNB BNB Chain
$579.3 +2.15%
XRP XRP Ledger
$1.13 +4.00%
DOGE Dogecoin
$0.0736 +2.17%
ADA Cardano
$0.1751 +7.49%
AVAX Avalanche
$6.65 +1.56%
DOT Polkadot
$0.8638 +7.28%
LINK Chainlink
$8.7 +3.82%

Event Calendar

{{年份}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$66,282.4
1
Ethereum ETH
$1,940.46
1
Solana SOL
$78.4
1
BNB Chain BNB
$579.3
1
XRP Ledger XRP
$1.13
1
Dogecoin DOGE
$0.0736
1
Cardano ADA
$0.1751
1
Avalanche AVAX
$6.65
1
Polkadot DOT
$0.8638
1
Chainlink LINK
$8.7

🐋 Whale Tracker

🔴
0x5789...9cca
1d ago
Out
869,231 DOGE
🔵
0xb290...41d0
1d ago
Stake
1,940,460 USDC
🟢
0xc182...fc9b
12m ago
In
2,307,522 DOGE
News

The Phantom in the Repo: How a North Korean Hacker Nearly Hijacked MetaMask’s Core Code

CryptoRay

The ledger never sleeps, but it does lie in wait. On April 4, 2025, a ghost surfaced in the commit history of MetaMask’s official repository. A contractor named Tyler Knapp—GitHub handle imyugioh—had been contributing to the most sensitive function of the world’s largest non-custodial wallet: the code handling crypto-to-fiat transfers. For 30 days, no one questioned the identity behind the pull requests. Then Consensys security flagged an anomaly—and the phantom vanished, leaving behind a clean audit trail but a gaping wound in the industry’s trust model.

Context: The Invisible Front Door MetaMask is more than a wallet; it is the gateway to Ethereum. Over 30 million monthly active users rely on it to interact with DeFi, NFTs, and dApps. Its open-source nature invites global contributors, but that openness is now a liability. The attacker—an Advanced Persistent Threat (APT) group linked to the Democratic People’s Republic of Korea—used a fabricated resume, a fake LinkedIn profile, and a convincingly active GitHub history to pass Consensys’s contractor screening. They were assigned to the on-ramp module, which bridges crypto and fiat currencies—the highest-value, highest-risk component in any wallet. According to TRM Labs, this is not an isolated incident: the same group has previously imbedded 100+ suspected IT workers across 53 crypto companies.

Core: The On-Chain Evidence Chain Let’s trace the exit. The hacker’s victimology is textbook social engineering. They bypassed KYC with a stolen identity and delivered “legitimate” code for a month. Why? To establish trust before deploying a dormant backdoor. The scary part is not the code they wrote—it’s the code they didn’t write yet. Consensys confirmed no malicious code was deployed, but that admission is a trap. In my eight years performing on-chain forensics, I’ve learned that a 30-day window is more than enough to plant a time-locked vulnerability or a subtle address-swap in the transaction signing flow. The attacker could have hidden a logic bomb that activates only when a specific wallet sends above a threshold amount to a Tornado Cash-like mixer.

The “clean audit” narrative is false comfort. Code review can catch syntax errors and backdoors, but it cannot catch a carefully crafted, perfectly legal function that calls an external contract—until that contract turns malicious six months later. This is the supply chain threat that traditional audits were never designed to defend against. The attacker played the long game, and their exit was a pivot, not a retreat.

Contrarian: The Correlation Trap Counter-intuitive insight: this event, while alarming, is actually a signal of improving security hygiene—not a failure. Why? Because Consensys caught it. The detection was not due to a lucky audit but to behavioral monitoring: the contractor’s communication patterns, code review comments, or perhaps a routine background re-check triggered the alarm. Most attacks of this nature are discovered months later, after the damage is done. Here, the organization’s insider threat detection functioned exactly as it should. The market reaction—mild and rational—reflects that “no loss of assets” is the strongest proof-of-work for Consensys’s incident response.

But here’s the blind spot: we celebrate the stop, but ignore the start. The attacker got through the door. If Consensys’s screening was bypassed once, it can be bypassed again—especially by a group that learns from failure. Correlation does not imply causation: just because no damage occurred this time does not mean the vulnerability is patched. In fact, the attacker now knows exactly what triggered the alarm, and will adapt. Future attempts will use more refined fake identities, perhaps even deepfake video interviews.

Takeaway: The Next Block’s Signal The ledger never lies, but it does lie in wait. The next attack will not look like this one. It will be slower, executed through a series of seemingly harmless contributions across multiple repositories—a decentralized infiltration. My on-chain data detective lens points to the following signal: monitor the Ethereum Name Service (ENS) protocol for unexpected primary name registrations. Attackers often register ENS names tied to fake identities to build on-chain reputations. Also watch Gitcoin Passport usage by wallet contributors; a sudden spike in verification claims from fresh accounts is a red flag.

The Phantom in the Repo: How a North Korean Hacker Nearly Hijacked MetaMask’s Core Code

For users, the takeaway is stark: trust the code, not the coder. Enable hardware signers for every transaction over $1,000. For builders, the time to implement on-chain identity verification—like Proof of Personhood—is now. The 30 days of imyugioh should be a permanent fixture in every Web3 security training. The hacker won the first battle of bypassing human vetting; we must win the war by making human trust a liability of the past.

Signatures embedded: - "The ledger never sleeps, but it does lie in wait." - "Yield is the bait; smart contracts are the trap." - "Trace the exit liquidity, not the project roadmap."

Tags: North Korean Hackers, MetaMask, Supply Chain Attack, Social Engineering, On-Chain Analytics, Wallet Security, DeFi

The Phantom in the Repo: How a North Korean Hacker Nearly Hijacked MetaMask’s Core Code

Fear & Greed

25

Extreme Fear

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x2313...6257
Experienced On-chain Trader
+$4.7M
60%
0x548f...3b2d
Top DeFi Miner
+$1.8M
72%
0x054e...b4e8
Experienced On-chain Trader
+$4.5M
83%