GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

MetaMask team infiltrated by North Korean hacker aftermath: hacker's identity was publicly exposed as early as September 2025, yet still bypassed background checks to enter MetaMask through outsourcing in March this year

that, according to DeFi researcher @Zun2025 posted on X platform, "MetaMask hired a DPRK-linked hacker as a developer without even conducting a proper background check that could have revealed his identity.The hacker's GitHub username is imyugioh, and he has been publicly listed on the Lazarus Group website since September 2025, yet MetaMask still hired this individual in March 2026. Source: lazarus.group/team/mauro-liu. Imagine that one of the largest wallets granted core code repository access to someone already on a publicly known list of DPRK hackers. Now think about what might happen to those small protocols with absolutely no security teams."Earlier reports stated that a North Korean hacker, Tyler Knapp, infiltrated the MetaMask team. He entered MetaMask through a long-term cooperating human resources supplier via an outsourcing arrangement, bypassing the background checks of the company's direct recruitment process. He worked at the company for a month and participated in the development of the wallet's fiat on/off ramp functionality. During this period, his IP address and behavioral anomalies were detected by the company's security monitoring. The company immediately revoked all his access permissions and suspended the release of all products he had worked on. No substantial data or financial losses have been caused so far.

Anthropic Claude Mythos Discovers 271 Vulnerabilities in Firefox Browser

According to Decrypt, Mozilla recently revealed that Anthropic’s latest AI model, Claude Mythos, identified 271 security vulnerabilities during internal testing of the Firefox browser; all related vulnerabilities were patched this week. For comparison, a previous Anthropic model had detected only 22 security-sensitive vulnerabilities. Mozilla stated that all discovered vulnerabilities fell within the scope of what top human researchers could identify. Claude Mythos was officially launched in March 2026 and is Anthropic’s most powerful model to date for reasoning, coding, and cybersecurity. It is currently available exclusively to vetted partners—including Amazon, Apple, and Microsoft—under Anthropic’s “Project Glasswing” initiative.