Probe Says About 100 North Korea-Linked Operatives Entered Crypto Firms

Probe Says About 100 North Korea-Linked Operatives Entered Crypto Firms

N
News Editor 01
2026-07-23 00:35:14
A security probe backed by ETH Rangers said about 100 suspected North Korea-linked individuals entered crypto firms using fake identities, shifting attention from external hacks to insider access and hiring risks.
North Koreacrypto securityEthereumETH Rangershiring risk

A probe led by the Ketman Project with support from ETH Rangers said about 100 individuals suspected of ties to North Korea secured jobs at crypto companies. Investigators said many used false names and fabricated work histories, entering firms through ordinary hiring channels that made them difficult for HR and compliance teams to spot.

The inquiry described the activity as coordinated rather than isolated. Several suspects were found to have held roles across multiple firms in the sector, suggesting a broad effort to penetrate crypto workplaces instead of targeting a single company.

ETH Rangers outlined the scale of its security work

ETH Rangers, which is connected to the Ethereum Foundation, funds researchers who assess vulnerabilities across decentralized platforms. According to figures cited in the report, the initiative has supported 17 independent researchers, helped identify more than 785 vulnerabilities, and handled 36 incident response operations. It has also assisted in recovering or blocking $5.8 million in compromised crypto funds.

Hiring pipelines are now part of the threat model

North Korea-linked cyber activity has long been associated with exchange hacks and outside technical exploits. The report said the pattern is changing. Gaining internal access through employment is becoming a more prominent route, giving operatives potential exposure to critical systems, code repositories, and internal workflow tools for extended periods without detection.

That shift has put routine recruiting practices under pressure. Security experts cited in the report said stronger identity verification is now necessary. One example mentioned was Stabble, where a person linked to the DPRK joined the company’s management and a withdrawal alert followed. Cases like that show how sensitive access can extend well beyond junior technical roles.

Losses tied to North Korea-linked crypto crime remain high

The financial toll remains severe. The report said actors tied to North Korea stole $2.02 billion in 2025, a 51% increase from the previous year, bringing cumulative losses to $6.75 billion. In April 2026, Drift Protocol was hit in an exploit worth $285 million, described as the largest DeFi hack of the year, and investigations into the stolen assets were still ongoing.

As infiltration cases and thefts rise, crypto firms are tightening internal monitoring and restricting access to wallets and sensitive systems. Industry observers also expect closer scrutiny of remote hiring and employee verification procedures as the threat changes.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.