Ethereum Foundation ETH Rangers: $5.8M Recovered, 100 North Korean IT Workers Exposed in 6 Months

Ethereum Foundation ETH Rangers: $5.8M Recovered, 100 North Korean IT Workers Exposed in 6 Months

N
News Editor 01
2026-07-23 17:45:16
The Ethereum Foundation's ETH Rangers program concluded after 6 months: 17 researchers recovered or froze over $5.8M, documented 785 bugs, and identified roughly 100 North Korean IT workers infiltrating Web3 projects.
Ethereum FoundationETH RangersNorth Korean hackersbug bountyWeb3 security

The Ethereum Foundation released the final report of its ETH Rangers program this week, revealing a dense string of results from six months of security operations: over $5.8 million recovered or frozen, 785 bugs documented, and roughly 100 North Korean IT infiltrators exposed.

Launched in late 2024 in partnership with Secureum, The Red Guild, and Security Alliance (SEAL), the program provided grants to individuals contributing to public-good security within the Ethereum ecosystem. The foundation said the initiative is now officially complete, with 17 grantees spanning incident response, threat intelligence, vulnerability research, and security education.

DeFiHackLabs: 620 PoCs, University Workshops, HITCON CTF

Led by SunSec, the DeFiHackLabs team built the Incident Explorer platform, which hosts over 620 proof-of-concept (PoC) attack reproductions with root-cause analysis. The team also ran a PoC Summer Contest that received 43 new submissions, and hosted 6 workshops at multiple universities in South Korea. In partnership with HITCON CTF, they designed Web3 security challenges that attracted 717 teams.

Ketman Project: North Korean IT Worker Investigation Sets Industry Standard

The report highlighted the Ketman Project, which contacted roughly 53 Web3 projects and identified about 100 North Korean IT workers operating as contractors or developers. The team open-sourced gh-fake-analyzer, a tool for detecting suspicious GitHub activity, and co-authored the DPRK IT Workers Framework with SEAL, now the de facto reference for handling such threats. The research was also presented at the DEF CON hacking conference.

Nick Bax: 36 SEAL 911 Cases, 200K Views on Warning Video

Security researcher Nick Bax handled over 36 SEAL 911 emergency response cases, most notably assisting in the Loopscale exploit where $5.8 million was successfully recovered. He also identified and notified more than 30 projects that were unknowingly hiring North Korean IT workers, and helped freeze associated funds. His warning video about the "North Korean fake VC scam" accumulated over 200,000 views on X. Additionally, Bax discovered and disclosed the "ELUSIVE COMET" threat group's exploitation of a Zoom homoglyph vulnerability, which was later patched.

Africa's First Web3 Security Summit

Guild Audits focused on security education in Africa and globally. Its trainees reported over 110 vulnerabilities on major bug bounty platforms like Sherlock, Code4rena, and Immunefi, with several ranking in the top 10. They also published more than 55 technical articles. The most notable event was Africa's first Web3 Security Summit, held on November 8, 2025, pushing security education into a region previously underserved.

On the protocol side, researchers conducted DoS stress tests on the five major Ethereum execution clients — Geth, Besu, Erigon, Nethermind, and Reth — uncovering 14 bugs involving CPU asymmetric consumption (up to 4x) and out-of-memory crashes. The testing framework has been handed over to the Ethereum Foundation's Protocol Security Team.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.