Monday, April 6, 2026
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims

by DigestWire member
April 6, 2026
in Blockchain, Crypto Market, Cryptocurrency
0
This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

North Korea‑connected operatives have spent years quietly embedding themselves inside crypto companies and DeFi projects.

A Long-Standing Crypto-Infiltration Saga

News and reports from the Democratic People’s Republic of Korea tend to have a particular conspiracy theory-action movie feel to them. However, they also have the tendency to be true and not over exaggerated at all.

This time, security researcher and MetaMask developer Taylor Monahan said on a Sunday post on the social network X that these methods date back to DeFi’s formative years, with actors linked to the DPRK quietly contributing to several major, widely used protocols.

Yuppppppp

Lots of DPRK IT Workers built the protocols you know and love, all the way back to defi summer

The “7 years blockchain dev experience” on their resume is not a lie. https://t.co/EQNgl5KhJ5

— Tay 💖 (@tayvano_) April 5, 2026

She claims that North Korean IT workers have quietly worked inside more than 40 DeFi projects over roughly seven years, including protocols that became household names after DeFi summer.

oh god uhhhh like sushi, thorchain, yam, pickle, harvest, reclaim, swing, paid, naos, shezmu, qrolli, saffron, sifu, napier, harmony, blueberry, stabble, onering, elemental, divvy, la token, impermax, kira, cook, fantom, ankr, gamerse, metaplay, spice, beanstalk, deltaprime,…

— Tay 💖 (@tayvano_) April 5, 2026

These workers often have “real” on‑chain experience (seven years of blockchain dev) but operate under stolen or synthetic identities, plugging into teams via normal hiring funnels

Her posts reply to tim, a pseudonymous builder and public face of Titan, a Solana‑based DEX aggregator and routing project, claiming that for a previous job they interviewed an extremely qualified candidate that turned out to be a Lazarus operative, the North-Korea affiliated group that has funneled billions of dollars in stolen money through cryptocurrency networks.

at a previous job, we interviewed someone who turned out to be a Lazarus operative. he did video calls and was extremely qualified

we invited him for in person interviews and he ultimately declined to fly out, so we passed

only later did we find his name in a Lazarus info dump… https://t.co/Vnvffrkjee

— tim | Titan (@timahhl) April 5, 2026

Renowned crypto detective ZachXBT also replied to tim’s post, explaining that this is not just “Lazarus” but a network of DPRK units (Lazarus, APT38, AppleJeus, etc.) coordinated by the Reconnaissance General Bureau and optimized for financial cybercrime. Their methods are based on “basic, relentless” outreach via LinkedIn, job boards, interviews, Zoom, plus remote dev roles that teams still grant far too easily.

Lazarus Group is the collective name for all DPRK state sponsored cyber actors.

The main issue is everyone groups them all together when the complexity of threats are different.

Threats via job postings, LinkedIn, email, Zoom, or interviews are basic and in no way… pic.twitter.com/NL8Jck5edN

— ZachXBT (@zachxbt) April 5, 2026

Recent U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctions and Chainalysis findings signal that DPRK IT networks generated $800 million in 2024 alone and have moved billions in stolen crypto since 2017, feeding weapons of mass destruction (WMD) and missile programs.

New Information On The Crypto-Hack On Drift Protocol

The April 1st $285 million attack on Drift Protocol reignited fears about insider threats from North Korea, especially after the protocol itself confirmed on Saturday that speculation linking the attack to North Korean hacking groups was right.

https://t.co/qYBMCup9i6

— Drift (@DriftProtocol) April 5, 2026

They attributed the attack “with medium confidence” to UNC4736, a North Korea–aligned, state‑sponsored hacking group.

The protocol claimed the attackers relied on a well elaborated social engineering strategy: fake professional personas, in‑person conference interactions, and booby‑trapped developer tooling to compromise contributors before finally executing the exploit. The attackers posed as a legitimate trading firm, met Drift contributors in person across several countries and used fully constructed identities with work histories and professional networks before triggering the exploit

The attackers weaponized common developer tooling by slipping malicious tasks into VS Code and Cursor configurations, delivering a compromised repository that contributors ran locally without realizing it. All these combined make the incident far more like an insider‑style supply‑chain compromise than a straightforward smart contract.

The day after the attack, Ledger CTO Charles Guillement linked the attack method to Bybit’s $1.4 billion hack, which was attributed to the regime’s cyber units. Then, on Friday, blockchain analytics firm Elliptic released an investigation claiming the on‑chain behavior, laundering methods, and network‑level indicators match the techniques seen in prior DPRK‑linked operations. Bitcoinist covered the story.

Market Implications

This saga crypto-hacking has turned into structural national‑security risk. Regulators and sanctions bodies are already tightening around DPRK IT networks, and more aggressive enforcement is likely to follow.

Large, state‑linked exploits create latent protocol risk: higher insurance premia, potential delistings, governance infighting over restitution, and longer risk‑off periods for DeFi tokens and perp volumes.

Bitcoin, BTC, BTCUSDT

Cover image from Perplexity. BTCUSDT chart from Tradingview.

Read Entire Article
Tags: BitcoinistBlockchainCoin Surges
Share30Tweet19
Next Post
Bybit’s P2P Crypto Gateway In Rwanda Gets Axed

Bybit’s P2P Crypto Gateway In Rwanda Gets Axed

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

TrueFi (TRU) Price Explodes 160%—Is it a Breakout or a Low-Liquidity Trap?

Michael Saylor’s “Strategy” Buys 4,871 Bitcoin for $330M

XRP Tokyo 2026: Ripple, a16z, SBI and Rakuten Converge in Japan Tomorrow

Marc Andreessen calls AI job loss fears “fake,” expects employment gains

Rushed quantum fix may backfire for Bitcoin, Samson Mow warns

Savannah Guthrie Returns to ‘Today’ Anchor Desk Amid Mom’s Disappearance and Says ‘It’s Good to Be Home’: ‘Ready or Not, Let’s Do the News’

Trending

Bybit’s P2P Crypto Gateway In Rwanda Gets Axed
Blockchain

Bybit’s P2P Crypto Gateway In Rwanda Gets Axed

by DigestWire member
April 6, 2026
0

Bybit has ranked low in Rwanda’s crypto adoption figures — and the country’s central bank wants to...

This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims

This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims

April 6, 2026

Here’s what happened in crypto today

April 6, 2026
TrueFi (TRU) Price Explodes 160%—Is it a Breakout or a Low-Liquidity Trap?

TrueFi (TRU) Price Explodes 160%—Is it a Breakout or a Low-Liquidity Trap?

April 6, 2026
Michael Saylor’s “Strategy” Buys 4,871 Bitcoin for $330M

Michael Saylor’s “Strategy” Buys 4,871 Bitcoin for $330M

April 6, 2026
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Bybit’s P2P Crypto Gateway In Rwanda Gets Axed April 6, 2026
  • This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims April 6, 2026
  • Here’s what happened in crypto today April 6, 2026

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.