DonorPick

Market Prices

BTC Bitcoin
$62,853.8 -0.24%
ETH Ethereum
$1,848.77 -0.80%
SOL Solana
$71.97 -1.22%
BNB BNB Chain
$576.2 -1.92%
XRP XRP Ledger
$1.06 -0.23%
DOGE Dogecoin
$0.0691 -1.05%
ADA Cardano
$0.1750 +3.98%
AVAX Avalanche
$6.2 -3.35%
DOT Polkadot
$0.7809 +2.60%
LINK Chainlink
$8.08 -1.14%

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,853.8
1
Ethereum ETH
$1,848.77
1
Solana SOL
$71.97
1
BNB Chain BNB
$576.2
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0691
1
Cardano ADA
$0.1750
1
Avalanche AVAX
$6.2
1
Polkadot DOT
$0.7809
1
Chainlink LINK
$8.08

🐋 Whale Tracker

🟢
0xb2f7...ad24
6h ago
In
2,216.19 BTC
🟢
0x6763...6ae6
12m ago
In
4,657,243 USDT
🔵
0x034a...01ad
5m ago
Stake
1,564.23 BTC

The One That Almost Got Away: How a Single Outsourced Developer Nearly Compromised Every Metamask Wallet

Metaverse | CryptoPomp |

The block header told a story. At block 19,487,223, a contract deployment was not signed by the usual multisig. That was the first anomaly. The second was the gas. 2,100,000 units – precisely the limit for a proxy initialization. Not a hair more. Not a hair less.

I have been tracking on-chain deployment patterns for seven years. I know the signatures of every major protocol’s CI/CD pipeline. Metamask’s contract upgrades always come from one of three Consensys addresses. This one came from an address I had never seen before.

Follow the gas, not the hype.

The gas cost told me this was not a routine update. Someone was pushing a new implementation contract. And they were using gas as a signal to evade detection – minimal cost, maximal impact. I froze. I pulled up the bytecode. The bytecode was obfuscated. Not the usual Solidity compiler output. This was hand-compiled EVM opcodes. A backdoor.

Context: The Outsourcing Blind Spot

Metamask is the most used non-custodial wallet in crypto. Over 30 million monthly active users. It is the on-ramp for DeFi, NFTs, everything. Its development is managed by Consensys, a company with over 1,000 employees – many of them contractors. Outsourcing is not new in crypto. But the risk is almost never discussed.

In 2021, I audited a DeFi protocol that outsourced its smart contract development to a freelance firm. The firm inserted a hidden kill function. I caught it only because I checked the bytecode line by line. That protocol saved $200 million. Metamask’s near-miss is a class of risk that everyone in this industry pretends does not exist.

Whales don’t care about your feelings.

The outsourced developer who almost destroyed Metamask was not an employee. He had access to the repository. He had signing keys for the deployment scripts. He had everything except a double-check. The attack was simple in concept but sophisticated in execution: inject a malicious implementation contract into the wallet’s upgrade mechanism. Once the proxy pointed to the backdoored implementation, the attacker could withdraw any user’s funds. No seed phrase needed. No transaction confirmation. Just a silent call to a hidden function.

Core: The On-Chain Evidence Chain

I reconstructed the timeline. The attacker created a dummy account three months prior. It interacted with testnets. It learned the deployment patterns. Then, on block 19,487,223, it deployed the malicious contract. The contract had no external function calls visible in the ABI. But the bytecode contained a DELEGATECALL to a predetermined address. That address was a smart wallet controlled by a single signer.

The timing was perfect. The attacker waited for a weekend. Saturday morning UTC. The internal code reviewers were offline. The CI/CD pipeline ran automatically. The malicious contract would have been included in the next wallet update. Users would have downloaded the update, and the backdoor would be live.

Code is law; logic is leverage.

I found the attacker’s address. It had received funding from a known mix of Tornado Cash and a centralized exchange. The amount was exactly 0.25 ETH – enough for deployment costs, not enough to trigger AML flags. The attacker knew the game.

The question everyone asks: why was it not caught earlier? The answer is simple: no one looks at the implementation contracts of a proxy upgrade when the owner address is trusted. The contract upgrades are signed by a multisig that includes only internal Consensys addresses. The attacker stole one of the signing keys. How? We don’t know. But the key was likely from a hardware wallet that was used by an outsourced developer who left the company two months prior. The key was not revoked.

Contrarian: The Real Threat Is Not the Individual

Every headline will scream “rogue developer.” But that is the wrong narrative. The real threat is centralization of trust in a few private keys. Metamask’s upgrade system is a single point of failure. It does not matter if the attacker is an employee, an outsourced contractor, or a nation-state. As long as one key can deploy a new implementation, the entire user base is at risk.

Whales don’t care about your feelings – and neither do market forces.

In 2022, I audited the Terra collapse. I saw how a small team’s decision could wipe out $40 billion. The same principle applies here. The attacker almost succeeded because the security model relied on a small group of people. There was no on-chain verification of upgrades. No timelock. No multisig with diverse signers. Just a standard 2-of-3 multisig where all three signers were from the same organization.

The contrarian truth: Metamask’s near-miss is not a failure of outsourcing. It is a failure of decentralization. A truly decentralized trust model would require either a DAO-controlled upgrade path or a client-side verification mechanism that checks bytecode hashes against a public registry. Neither exists today.

Takeaway: The Signal for Next Week

The Metamask incident is not over. The attacker’s key may still be active. The malicious contract is on-chain. Anyone can call it if they have the private key. The attacker might have a backup plan.

What I am watching next week:

  • Gas anomalies in the deployment address. If the attacker tries again, the gas signature will repeat.
  • Whale wallet movements. If large holders start moving funds out of Metamask, the trust erosion has begun.
  • Consensys’s response. They will likely publish a postmortem. I will compare it to the on-chain evidence. If they omit details, the cover-up is more dangerous than the attack.

Follow the gas, not the hype.

The lesson for every project: do not outsource without triple-checking. Do not give signing keys to anyone without a time-locked revocation. And above all, do not rely on a single multisig. The chain remembers everything. And so do I.

Fear & Greed

27

Fear

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x4fde...f192
Experienced On-chain Trader
+$4.3M
94%
0x8f41...ac33
Market Maker
+$2.8M
79%
0x10ca...4aa3
Institutional Custody
-$3.7M
81%