Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

North Korean IT Workers Embedded in DeFi Projects for Seven Years, Analyst Says

Author
Austin Mwendia
Austin Mwendia
Crypto Writer
Fact Checked by Joshua Downes
Last updated: April 6, 2026
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
North Korean IT Workers Embedded in DeFi Projects for Seven Years, Analyst Says

Highlights:

  • North Korean IT workers spent seven years inside DeFi teams and helped build real crypto protocols.
  • Lazarus Group has stolen about $7 billion in crypto through fewer but larger attacks.
  • Crypto firms still miss infiltration risks during hiring despite repeated interview-based entry attempts.

North Korean IT workers have spent at least seven years working inside crypto companies and DeFi projects, according to a post by security researcher and MetaMask developer Taylor Monahan. In the post shared on Sunday, she said these workers joined teams as developers and helped build widely used DeFi protocols. She also said their resumes showing years of blockchain experience were accurate. Crypto companies hired them after interviews confirmed their coding ability.

🚨ALERT: NORTH KOREAN DEVS HAS BEEN BUILDING CRYPTO'S BIGGEST PROTOCOLS RIGHT UNDER OUR NOSES

DPRK IT workers have been embedded inside major crypto protocols since DeFi Summer, quietly building the very platforms millions of users trust daily, on-chain analyst Tay (@tayvano_)… pic.twitter.com/sUSjdwXn7B

— BSCN (@BSCNews) April 6, 2026

Taylor Monahan said more than 40 DeFi platforms employed these workers between 2020 and 2026. She said this activity began during DeFi summer, when projects rushed to launch new products. During that period, many companies hired remote developers to meet demand. Some teams reduced identity checks to speed up hiring. These workers used that gap to enter teams and secure long-term roles.

She said these workers contributed code, maintained smart contracts, and supported daily protocol operations. She named projects such as Yearn, Sushi, and Fantom as examples of possible exposure. These workers were part of engineering teams that managed live user funds. They accessed codebases, deployment tools, and internal communication channels. This access placed them inside the core structure of several DeFi platforms.

This position allowed them to understand how each protocol handled transactions and stored assets. They reviewed system designs and observed how teams fixed bugs and handled upgrades. This knowledge helped them identify weak points inside the systems.

North Korean IT Workers Drive Billion-Dollar Crypto Theft Activity

This infiltration links to the Lazarus Group, which analysts associate with North Korea’s cyber operations. Analysts at R3ACH Network said the group has stolen about $7 billion in crypto since 2017. They also reported that the group stole about $2.02 billion last year alone. These attacks did not happen frequently, but each one targeted large amounts. This pattern shows a shift toward fewer and larger thefts.

The Ronin Bridge attack resulted in losses of about $625 million. The WazirX hack caused losses of about $235 million. The Bybit breach led to losses of about $1.4 billion. Earlier this month, Drift Protocol reported a $280 million exploit and linked it to North Korean actors. Each attack followed a planned sequence rather than a quick breach.

In its postmortem, Drift Protocol said attackers prepared the exploit over several months. The attackers used social engineering to gain access through trusted interactions. They did not break in directly but used access points already inside the system.

Hiring Channels and Proxy Identities Expand the Threat Network

Crypto companies have been encountering North Korean IT workers during the hiring processes. Tim Ahhl, founder of Titan Exchange, said his team interviewed a candidate later linked to Lazarus. He said the candidate passed interviews and completed technical discussions without issues. The candidate joined video calls and answered questions in detail. However, the candidate refused to attend an in-person meeting. Later checks linked the identity to a Lazarus information dump.

at a previous job, we interviewed someone who turned out to be a Lazarus operative. he did video calls and was extremely qualified

we invited him for in person interviews and he ultimately declined to fly out, so we passed

only later did we find his name in a Lazarus info dump… https://t.co/Vnvffrkjee

— tim | Titan (@timahhl) April 5, 2026

Drift Protocol said attackers used intermediaries to approach teams during hiring and collaboration stages. These intermediaries created identities with employment records, public profiles, and references. They communicated through normal channels such as email and video meetings. Teams treated them as legitimate candidates or partners during discussions. This process allowed them to build trust before any exploit took place.

Blockchain investigator ZachXBT said attackers use simple methods to reach targets. He said they contact teams through job listings, LinkedIn messages, and direct emails. He also said they repeat these attempts until a company responds.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Tags

DeFiHacksLazarus GroupMetaMaskNorth Korea
Austin Mwendia
Author

Austin Mwendia

Austin Mwendia is a passionate crypto journalist with three years of experience. He has contributed to various media outlets, covering blockchain technology, market analysis, and financial trends. He is committed to educating readers and expanding the adoption of blockchain and decentralized finance.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
  • CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
  • Circle Explains USDC Freeze Limits After Drift Protocol Hack

Related Articles:

Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
Crypto News4 hours ago
Syed Ali Haider
By Syed Ali Haider4/11/2026
CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
Crypto News6 hours ago
Syed Ali Haider
By Syed Ali Haider4/11/2026
Circle Explains USDC Freeze Limits After Drift Protocol Hack
Circle Explains USDC Freeze Limits After Drift Protocol Hack
Crypto News18 hours ago
Chinedu Agbakwusi
By Chinedu Agbakwusi4/10/2026

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
  • CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
  • Circle Explains USDC Freeze Limits After Drift Protocol Hack
  • Aethir Halts Bridge Exploit, Caps Losses Below $90K
  • Ethereum Network Activity Hits All-Time High with 1.3M Transactions
  • Hong Kong Issues First Stablecoin Licences to HSBC and Standard Chartered Venture
  • Bitcoin Could Be Quantum Safe Without a Soft Fork, Analyst Says
  • Top Crypto Picks for Today, April 10 – Zcash, Hyperliquid, BNB
  • Japan Approves Bill to Treat Crypto as Financial Instruments
  • Coinbase CEO Backs Treasury Secretary’s Call to Pass the CLARITY Act
  • Hyperliquid Price Outlook – HYPE Gains Strength, $42.15 in Focus
  • Bitmine Uplists to NYSE with 4.8M ETH and a $4 Billion Buyback
  • Best Crypto Gainers Today, April 9 – SIREN, DEXE, JUST
  • Bitcoin Price Holds Near $71K as Iran BTC Toll Plan Raises Uncertainty
  • Bitcoin Depot Loses 50.9 BTC in Wallet Breach Revealed in SEC Filing
  • Ethereum Foundation Offloads 3,750 ETH Worth $8.3M
  • Stablecoin Volumes May Hit $1.5 Quadrillion by 2035: Chainalysis
  • Treasury Secretary Scott Bessent Calls CLARITY Act a National Priority
  • Canary Capital Seeks SEC Approval for Spot PEPE ETF
  • Iran Plans Bitcoin Toll for Laden Oil Tankers Crossing Strait of Hormuz