Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Bitcoin miners' AI pivot faces $50 billion reality check, says VanEck

June 17, 2026

Grayscale Analysis Pegs AAVE as Undervalued, Sets $175 Bull Case Target

June 17, 2026

AAVE Price Prediction: $80 Is the Line in the Sand — Break It or Break Down

June 17, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»North Korean IT workers operated within DeFi protocols for years, researcher warns
Security

North Korean IT workers operated within DeFi protocols for years, researcher warns

April 7, 2026No Comments2 Mins Read

North Korean-linked operators have spent years quietly integrating into crypto firms and DeFi teams, raising fresh concerns about insider risk after a string of high-value exploits tied to the country’s cyber apparatus.

Security researcher and MetaMask developer Taylor Monahan said these tactics stretch back to the early days of decentralized finance, with individuals tied to the Democratic People’s Republic of Korea contributing to several widely used protocols.

“Lots of DPRK IT workers built the protocols you know and love, all the way back to DeFi summer,” she said on Sunday, adding that more than 40 platforms, including several well-known projects, have at some point relied on such developers.

However, she noted that the “seven years of blockchain dev experience” listed on their resumes is “not a lie.”

Investigators have long tied North Korea’s cyber operations to the Lazarus Group, a state-backed collective believed to have stolen around $7 billion in digital assets since 2017, according to R3ACH analysts.

The group has been associated with some of the industry’s largest breaches, including the $625 million Ronin Bridge exploit in 2022, the $235 million WazirX hack in 2024, and the $1.4 billion Bybit incident in 2025.

Last week’s $280 million exploit of Drift Protocol has drawn renewed scrutiny. The project said it had “medium-high confidence” that a North Korean state-affiliated group was behind the attack, linking the incident to a wider pattern of infiltration and social engineering.

However, the face-to-face meetings that led up to the breach were not with North Korean nationals, but rather “third party intermediaries” using “fully constructed identities including employment histories, public facing credentials, and professional networks.”

See also  North Korean Hackers Bag Another $100m in Crypto Heists

These profiles included employment histories, public credentials, and active professional networks, allowing them to build trust through in-person interactions before the exploit unfolded.

Independent blockchain investigator ZachXBT has warned in a recent X post that not all threats tied to North Korea operate at the same level of sophistication.

“The main issue is that everyone groups them all together when the complexity of threats is different,” he said.

He described many infiltration attempts as relatively simple, relying on persistence rather than technical complexity. Outreach through job postings, LinkedIn, email, Zoom calls, and interview processes remains common.

“Basic and in no way sophisticated […] the only thing about it is they’re relentless,” he said, adding that teams continuing to fall for such tactics in 2026 risk being seen as negligent.

Source link

DeFi Korean North operated Protocols Researcher Warns Workers years

Related Posts

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026
Top Posts

WLD Price Prediction: Worldcoin Eyes $0.44 Recovery After 27% Surge Momentum

February 7, 2026

Perpetual Trading Protocol GMX Bags Biggest Chunk of $40M Arbitrum Grant

October 13, 2023

Michael Saylor says bitcoin has likely bottomed, quantum risk overblown

April 8, 2026

Type above and press Enter to search. Press Esc to cancel.