IT Workers From North Korea Have Been Infiltrating DeFi Platforms for Past 7 Years

Research highlights long-term insider risks in decentralised finance projects

IT Workers From North Korea Have Been Infiltrating DeFi Platforms for Past 7 Years

Photo Credit: Unsplash/Shubham Dhage

Security concerns rise over insider threats in decentralised finance systems

Click Here to Add Gadgets360 As A Trusted Source As A Preferred Source On Google
Highlights
  • Researcher links DPRK workers to over 40 DeFi platforms
  • Social engineering tactics used in major exploit cases
  • Lazarus group tied to multi-billion crypto thefts
Advertisement

Security researcher Taylor Manonan has claimed that North Korean IT workers have been infiltrating DeFi platforms for the past 7 years. This includes over 40 DeFi platforms, which she listed in a post on X. She further added that seven years of DeFi experience on their resumes is not a lie, cause they have built all the critical protocols that run on each of these DeFi platforms. This data revelation came hours after the Drift Protocol disclosed a $280 million (roughly Rs. 2,600 crore) exploit, which also had a DPRK group behind it. 

Long-Term Infiltration Raises Concerns Over DeFi Security Risks

Drift Protocol, which fell prey to this scam were completely oblivious. In a post on X, Drift Protocol explained that this was not a typical hack, but a months-long, highly coordinated social engineering operation. Bad actors posed as a legitimate trading firm, met the execs at Drift Protocol at a lot of crypto events. They even invested a million dollars in capital on the platform. Over time, they managed to trick team members into interacting with malicious code and apps, likely compromising their devices and gaining access to critical systems. This operation is now linked to a DPRK group called UNC4736. 

This is not the first time that a DPRK group has been part of such a scam. As per the analysts at Creator Network R3ACH, the Lazarus group has stolen over $7 billion (roughly Rs. 65,000 crore) in crypto since 2017. These attacks include a $625 million (roughly Rs. 5,803 crore) scam of Ronin Bridge in 2022, the $235 million (roughly Rs. 2,182 crore) WazirX exploit in 2024, and $1.4 billion (roughly Rs. 13,000 crore) Bybit heist in 2025, which is also the biggest hack on their timeline. 

Commenting on this issue, Tim Ahhl, the founder of the Titan Exchange, which is a Solana-based Dex aggregator, said that in a previous job, “we interviewed someone who turned out to be a Lazarus executive.” Ahhl further added that the candidate “did video calls and was extremely qualified”. The bad actor declined an in-person interview, and the execs at Titan Exchange later found his name in a Lazarus “info dump.”

Earlier this year, the US Treasury had sanctioned individuals and entities tied to a North Korea-linked IT worker scheme that allegedly used fake identities to secure remote tech jobs and funnel earnings through cryptocurrency. Officials say the network helped generate illicit revenue for the North Korean regime.

Cryptocurrency is an unregulated digital currency, not a legal tender and subject to market risks. The information provided in the article is not intended to be and does not constitute financial advice, trading advice or any other advice or recommendation of any sort offered or endorsed by NDTV. NDTV shall not be responsible for any loss arising from any investment based on any perceived recommendation, forecast or any other information contained in the article.
Comments

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Rahul Dhingra
Rahul Dhingra is a crypto writer at Gadgets 360, where he covers the exciting world of Cryptocurrency, Blockchain, Defi and Web3. Before joining Gadgets 360, he worked as a content specialist for a European-based Crypto Exchange. Rahul loves storytelling, not just through the written word but also through the visual medium. Beyond his professional life, Rahul is a sports fanatic. Whether it’s cricket or football, his passion for the game is contagious. More
Xiaomi 17 Max Launch Timeline, Price Range Tipped Along With Key Specifications, Features
Red Magic Gaming Tablet 5 Pro Launch Timeline Revealed

Advertisement

Follow Us

Advertisement

© Copyright Red Pixels Ventures Limited 2026. All rights reserved.
Trending Products »
Latest Tech News »