North Korean IT Workers Infiltrated Crypto for 7 Years, Hitting Over 40 DeFi Hiring Pipelines

North Korean IT Workers Infiltrated Crypto for 7 Years, Hitting Over 40 DeFi Hiring Pipelines

N
News Editor 01
2026-07-24 07:05:17
Taylor Monahan said North Korean IT workers have been embedded in crypto for at least seven years, with more than 40 DeFi protocols unknowingly completing hiring processes. The Drift case suggests Lazarus now uses non-North Korean intermediaries, weakening older interview-based defenses.

MetaMask developer and security researcher Taylor Monahan said North Korean IT workers have been embedded in the crypto sector for at least seven years, and that more than 40 DeFi protocols unknowingly moved them through hiring pipelines. Her point was blunt: this is not a recent twist. According to her, the infiltration dates back to the DeFi summer era, which means teams may already have interacted with these operators without realizing it.

A long-running operation tied to roughly $7 billion in thefts

Monahan argued that the “seven years of blockchain development experience” listed on these résumés can be technically accurate. The experience is real. What employers did not know, she said, was where the payroll money ultimately ended up. Citing figures attributed to R3ACH analysts, the report says Lazarus Group has stolen about $7 billion in crypto assets since 2017. Examples listed include the $625 million Ronin Bridge hack in 2022, the $235 million WazirX theft in 2024, and the $1.4 billion Bybit case in 2025.

The Drift case points to a shift in contact tactics

Monahan’s remarks came only hours after Drift Protocol published details tied to its latest loss. Drift said last week’s $285 million incident was linked, with “medium-high confidence,” to a North Korean state-affiliated organization. One detail from the post-incident review stood out: the in-person contact was not a North Korean national, but a third-party intermediary carrying a fully built identity, including work history, publicly checkable credentials, and a professional network.

That detail matters because it weakens older screening logic. Measures that many teams treated as practical filters, such as mandatory in-person interviews or accent-based suspicion, no longer look reliable on their own.

A candidate impressed the team, then appeared on a Lazarus leak list

Titan Exchange founder Tim Ahhl described a similar breakdown in hiring controls. He said a team at his previous job completed an interview process with one applicant, only to later find that person on a Lazarus-related leaked information list. The candidate joined by video, showed what Ahhl described as extremely strong technical ability, and raised only one unusual signal: refusal to do an in-person interview.

That pattern was not rare during the hiring boom of 2021 to 2022. In a market built around remote work, declining to appear on site did not automatically trigger an alarm.

Basic methods, repeated without stopping

Blockchain investigator ZachXBT added that “Lazarus Group” is often used as a catch-all label for North Korean state-backed cyber operators, even when the actual threats vary widely in sophistication. In his view, attacks launched through job postings, LinkedIn, email, Zoom, or interview processes are basic rather than highly advanced. The defining trait is persistence.

The report also noted that the U.S. Office of Foreign Assets Control, or OFAC, maintains a public sanctions search tool and has published warning guidance on fraudulent IT worker patterns. The issue is not the absence of defensive resources. It is whether crypto firms treat hiring risk as a standard part of security operations.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.

North Korean IT Workers Infiltrated Crypto for 7 Years, Hitting Over 40 DeFi Hiring Pipelines | Bit.Fan