MetaMask developer and security researcher Taylor Monahan said North Korean IT workers have been embedded in the crypto sector for at least seven years, and that more than 40 DeFi protocols unknowingly moved them through hiring pipelines. Her point was blunt: this is not a recent twist. According to her, the infiltration dates back to the DeFi summer era, which means teams may already have interacted with these operators without realizing it.
A long-running operation tied to roughly $7 billion in thefts
Monahan argued that the “seven years of blockchain development experience” listed on these résumés can be technically accurate. The experience is real. What employers did not know, she said, was where the payroll money ultimately ended up. Citing figures attributed to R3ACH analysts, the report says Lazarus Group has stolen about $7 billion in crypto assets since 2017. Examples listed include the $625 million Ronin Bridge hack in 2022, the $235 million WazirX theft in 2024, and the $1.4 billion Bybit case in 2025.
The Drift case points to a shift in contact tactics
Monahan’s remarks came only hours after Drift Protocol published details tied to its latest loss. Drift said last week’s $285 million incident was linked, with “medium-high confidence,” to a North Korean state-affiliated organization. One detail from the post-incident review stood out: the in-person contact was not a North Korean national, but a third-party intermediary carrying a fully built identity, including work history, publicly checkable credentials, and a professional network.
That detail matters because it weakens older screening logic. Measures that many teams treated as practical filters, such as mandatory in-person interviews or accent-based suspicion, no longer look reliable on their own.
A candidate impressed the team, then appeared on a Lazarus leak list
Titan Exchange founder Tim Ahhl described a similar breakdown in hiring controls. He said a team at his previous job completed an interview process with one applicant, only to later find that person on a Lazarus-related leaked information list. The candidate joined by video, showed what Ahhl described as extremely strong technical ability, and raised only one unusual signal: refusal to do an in-person interview.
That pattern was not rare during the hiring boom of 2021 to 2022. In a market built around remote work, declining to appear on site did not automatically trigger an alarm.
Basic methods, repeated without stopping
Blockchain investigator ZachXBT added that “Lazarus Group” is often used as a catch-all label for North Korean state-backed cyber operators, even when the actual threats vary widely in sophistication. In his view, attacks launched through job postings, LinkedIn, email, Zoom, or interview processes are basic rather than highly advanced. The defining trait is persistence.
The report also noted that the U.S. Office of Foreign Assets Control, or OFAC, maintains a public sanctions search tool and has published warning guidance on fraudulent IT worker patterns. The issue is not the absence of defensive resources. It is whether crypto firms treat hiring risk as a standard part of security operations.

