Fresh Warning for DeFi Security
Security researcher Taylor Monahan said North Korean IT workers have infiltrated more than 40 decentralized finance platforms over the past seven years, adding to concerns about long-running cybersecurity threats across the crypto sector.
The disclosure suggests the activity was not isolated, but part of a broader and sustained effort to penetrate DeFi operations. According to the report, these operatives exploited weaknesses in DeFi systems to obtain unauthorized access, creating potential risks for both platform infrastructure and user funds and data.
State-Backed Threats Remain a Major Crypto Risk
Monahan’s findings point to what appears to be a coordinated campaign linked to North Korean entities. For the digital asset industry, that raises the stakes significantly: the threat is not limited to opportunistic hackers, but may involve organized, persistent, and well-resourced state-sponsored actors.
DeFi platforms are especially exposed because of their open architecture, complex on-chain interactions, and layered protocol dependencies. Weaknesses in access control, operational security, or internal processes can create openings for infiltration, even beyond well-known smart contract vulnerabilities.
Broader Industry Implications
The revelation is likely to intensify scrutiny of insider risk, supply chain exposure, and identity verification practices throughout the DeFi ecosystem. While the report did not identify the affected platforms or quantify financial damage, the figure of more than 40 platforms indicates the scale and persistence of the problem.
Overall, the findings serve as another warning for the crypto industry. As attack methods become more sophisticated, DeFi projects may need to strengthen not only technical defenses, but also hiring checks, permission management, and continuous monitoring to reduce the impact of future infiltrations.

