GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Revoke.cash Notice: Ultimate subscription users need to check Auto-Revoking settings.

Revoke.cash issued a reminder stating that, following last week's Magic Eden security incident, Ultimate subscribers must ensure their wallets meet two conditions for the Auto-Revoking feature to properly protect assets: first, granting Auto-Revoking permissions for the wallet in MetaMask; second, the wallet has been upgraded to a MetaMask Smart Account on the corresponding network. The second step is normally completed automatically during the authorization process, but if the address had already been upgraded to a Smart Account via another wallet application, the upgrade may fail.

Joseph Lubin: Some infrastructure experienced a security incident; MetaMask wallets and user funds remain unaffected.

Consensys founder Joseph Lubin stated in a post that the team has recently addressed and resolved a security incident impacting some infrastructure. Based on current investigation results, there is no indication that the MetaMask wallet or user funds within it were affected. The mnemonic phrase, private keys, and wallet assets were not compromised in this incident, and users retain full control over their assets.

MetaMask Responds to Security Incident: Exits Affected Validator Nodes, Wallet and Funds Unaffected

MetaMask announced it is exiting the affected validator nodes in its non-custodial staking service, and there are currently no signs that wallets or customer funds have been compromised.

Aave Founder: Following Up on MetaMask Incident with Lido, Aave Market Currently Normal

Aave founder Stani stated on X that the team is tracking the developments of the MetaMask staking infrastructure security incident in collaboration with Lido. Stani noted that so far, the Aave market has not been affected by the incident, and all operations remain fully operational.

MetaMask Responds to Infrastructure Security Incident: No Direct Risk to Wallet Identified So Far

MetaMask stated that some infrastructure was affected by a security incident, but no direct threat to MetaMask wallets has been identified to date, and it has voluntarily exited the affected validator nodes.

Specter: A MetaMask Swap Router Contract Address Has Been Blacklisted by Tether Since 2021

blockchain security researcher Specter has stated that while investigating the Payy Network attack incident, he discovered that an address associated with a MetaMask Swap router contract was blacklisted by Tether in 2021 and has remained blacklisted ever since. Specter said he had not previously noticed this situation.

MetaMask team infiltrated by North Korean hacker aftermath: hacker's identity was publicly exposed as early as September 2025, yet still bypassed background checks to enter MetaMask through outsourcing in March this year

that, according to DeFi researcher @Zun2025 posted on X platform, "MetaMask hired a DPRK-linked hacker as a developer without even conducting a proper background check that could have revealed his identity.The hacker's GitHub username is imyugioh, and he has been publicly listed on the Lazarus Group website since September 2025, yet MetaMask still hired this individual in March 2026. Source: lazarus.group/team/mauro-liu. Imagine that one of the largest wallets granted core code repository access to someone already on a publicly known list of DPRK hackers. Now think about what might happen to those small protocols with absolutely no security teams."Earlier reports stated that a North Korean hacker, Tyler Knapp, infiltrated the MetaMask team. He entered MetaMask through a long-term cooperating human resources supplier via an outsourcing arrangement, bypassing the background checks of the company's direct recruitment process. He worked at the company for a month and participated in the development of the wallet's fiat on/off ramp functionality. During this period, his IP address and behavioral anomalies were detected by the company's security monitoring. The company immediately revoked all his access permissions and suspended the release of all products he had worked on. No substantial data or financial losses have been caused so far.