IT Workers From North Korea Have Been Infiltrating DeFi Platforms for Past 7 Years

Research highlights long-term insider risks in decentralised finance projects

Advertisement
Written by Rahul Dhingra, Edited by Rohan Pal | Updated: 6 April 2026 14:55 IST
Highlights
  • Researcher links DPRK workers to over 40 DeFi platforms
  • Social engineering tactics used in major exploit cases
  • Lazarus group tied to multi-billion crypto thefts

Security concerns rise over insider threats in decentralised finance systems

Photo Credit: Unsplash/Shubham Dhage

Security researcher Taylor Manonan has claimed that North Korean IT workers have been infiltrating DeFi platforms for the past 7 years. This includes over 40 DeFi platforms, which she listed in a post on X. She further added that seven years of DeFi experience on their resumes is not a lie, cause they have built all the critical protocols that run on each of these DeFi platforms. This data revelation came hours after the Drift Protocol disclosed a $280 million (roughly Rs. 2,600 crore) exploit, which also had a DPRK group behind it. 

Long-Term Infiltration Raises Concerns Over DeFi Security Risks

Drift Protocol, which fell prey to this scam were completely oblivious. In a post on X, Drift Protocol explained that this was not a typical hack, but a months-long, highly coordinated social engineering operation. Bad actors posed as a legitimate trading firm, met the execs at Drift Protocol at a lot of crypto events. They even invested a million dollars in capital on the platform. Over time, they managed to trick team members into interacting with malicious code and apps, likely compromising their devices and gaining access to critical systems. This operation is now linked to a DPRK group called UNC4736. 

Advertisement

This is not the first time that a DPRK group has been part of such a scam. As per the analysts at Creator Network R3ACH, the Lazarus group has stolen over $7 billion (roughly Rs. 65,000 crore) in crypto since 2017. These attacks include a $625 million (roughly Rs. 5,803 crore) scam of Ronin Bridge in 2022, the $235 million (roughly Rs. 2,182 crore) WazirX exploit in 2024, and $1.4 billion (roughly Rs. 13,000 crore) Bybit heist in 2025, which is also the biggest hack on their timeline. 

Commenting on this issue, Tim Ahhl, the founder of the Titan Exchange, which is a Solana-based Dex aggregator, said that in a previous job, “we interviewed someone who turned out to be a Lazarus executive.” Ahhl further added that the candidate “did video calls and was extremely qualified”. The bad actor declined an in-person interview, and the execs at Titan Exchange later found his name in a Lazarus “info dump.”

Advertisement

Earlier this year, the US Treasury had sanctioned individuals and entities tied to a North Korea-linked IT worker scheme that allegedly used fake identities to secure remote tech jobs and funnel earnings through cryptocurrency. Officials say the network helped generate illicit revenue for the North Korean regime.

Cryptocurrency is an unregulated digital currency, not a legal tender and subject to market risks. The information provided in the article is not intended to be and does not constitute financial advice, trading advice or any other advice or recommendation of any sort offered or endorsed by NDTV. NDTV shall not be responsible for any loss arising from any investment based on any perceived recommendation, forecast or any other information contained in the article.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Gemini Offers Agentic Design Creation With New Adobe and Canva Connectors
  2. Xiaomi 17 Max Debuts With 8,000mAh Battery, Leica-Tuned Cameras: See Price
  3. Honor Might Be Working on a Wide Foldable Phone With This Snapdragon Chip
  4. Honor Win Turbo is All Set to Launch in China Next Week
  5. Maa Behen OTT Release: When and Where to Watch it Online?
  6. Google's AI Studio Will Soon Let Android Users Vibe Code Apps
  7. Oppo Enco Air 5 Pro With 12mm Drivers Arrives in India at This Price
  8. Oppo Find X9s Review: Almost 'Pro'
  9. PS Plus Prices Hiked Across All Tiers in India: Check New Pricing
  10. Oppo Find X9s vs Vivo X300 FE vs OnePlus 15: Price and Features Compared
  1. Scientists Discover New Fuel-Saving Route to the Moon
  2. Madhu Vidhu OTT Release: Where to Watch, Plot, Cast, IMDb Rating, and More
  3. Maa Behen OTT Release Revealed: When and Where to Watch it Online?
  4. LOL: Last One Laughing Germany Season 7 Out on OTT: Know Where to Watch it Online
  5. Warrant: From the World of Vilangu OTT Release Date: When and Where to Watch it Online?
  6. Xiaomi Clip Open-Ear Earbuds Launched With LHDC 5.0 Audio, Up to 38 Hours Total Battery Life: Price, Specifications
  7. Sathi Leelavathi Now Streaming on SunNXT: Everything You Need to Know About Plot, Cast, and More
  8. Xiaomi Smart Band 10 Pro Launched With 1.74-Inch AMOLED Screen, Up to 21 Days Battery Life: Price, Features
  9. Honor Developing Wide-Foldable Phone With Snapdragon 8 Elite Gen 6 SoC, Tipster Claims
  10. Google’s Gemini Offers Agentic Design Creation With New Adobe and Canva Connectors
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.