North Korea operates two parallel crypto extraction pipelines — direct hacking and embedded IT worker fraud — that collectively generated an estimated $2.8 billion in 2025 alone. Chainalysis data attributes $2.02 billion of that figure to outright theft across exchange and protocol exploits, whil...
"North Korean state-sponsored hackers steal and launder money to fund the regime's nuclear weapons program." — John K. Hurley, Under Secretary of the Treasury for Terrorism and Financial Intelligence
North Korea operates two parallel crypto extraction pipelines — direct hacking and embedded IT worker fraud — that collectively generated an estimated $2.8 billion in 2025 alone. Chainalysis data attributes $2.02 billion of that figure to outright theft across exchange and protocol exploits, while the U.S. Treasury estimates IT worker infiltration schemes yielded approximately $800 million in the same year. The cumulative all-time haul from DPRK-linked crypto theft now exceeds $6.75 billion across roughly 270 documented incidents, according to blockchain analytics firm BlockEden.
On April 17, 2026, the Ethereum Foundation-funded Ketman Project disclosed findings from a six-month investigation identifying 100 DPRK IT operatives embedded inside 53 Web3 organizations. One month earlier, on March 12, 2026, OFAC sanctioned six individuals and two entities facilitating DPRK IT worker fraud, flagging 21 cryptocurrency addresses and $12 million in transactions linked to the Amnokgang Technology Development Company. These developments underscore two distinct but converging threat vectors: high-profile exploits executed by state-linked hacking units, and low-profile salary extraction through operatives posing as legitimate developers.
This report compares the two pipelines — their scale, methods, economic yield, and the counter-measures now emerging — to assess the total cost of DPRK activity to the Web3 ecosystem.
DPRK-linked hacking units — primarily Lazarus Group (also tracked as TraderTraitor, APT38, UNC4736, AppleJeus, and Citrine Sleet) — have compiled the following documented theft timeline:
| Year | Estimated Theft | Notable Incidents | |------|----------------|-------------------| | 2022 | ~$1.7B | Ronin Bridge ($620M) | | 2023 | ~$1.0B | JumpCloud supply-chain breach | | 2024 | ~$1.3B | Majority of global crypto-hack losses | | 2025 | $2.02B | Bybit ($1.5B), multiple exchange hits | | 2026 Q1 | ~$309M | Drift Protocol ($285M), other incidents |
The February 2025 Bybit exploit — $1.5 billion drained through a supply-chain compromise of the Safe wallet interface — stands as the largest single crypto theft on record. The FBI attributed it to TraderTraitor, a subunit of North Korea's Reconnaissance General Bureau (RGB) 3rd Bureau. The attack followed a pattern of social engineering a system administrator, injecting dormant code into Safe's front-end, and activating it during a routine transaction authorization.
The April 1, 2026 Drift Protocol exploit followed a six-month infiltration campaign. Attackers, operating under the guise of a quantitative trading firm, compromised Drift's Security Council through Solana's durable nonce feature. They convinced council members to unknowingly pre-sign transactions that transferred admin control, then whitelisted a fabricated token (CVT) as collateral, depositing 500 million CVT and withdrawing $285 million in USDC, SOL, and ETH. Elliptic and TRM Labs linked the attack to UNC4736 based on on-chain indicators: Tornado Cash usage, transaction timing consistent with Pyongyang time zones (09:30 local), cross-chain bridging patterns, and fund flow overlap with Radiant Capital attackers.
The Drift attack also triggered cascading disruptions. According to Blockchain News, at least 12 additional protocols were subsequently attacked in a two-week period, with combined losses including $13.7 million from Grinex and $7.6 million from Rhea Finance.
The IT worker scheme operates on a fundamentally different model: low-visibility, high-persistence revenue generation. DPRK nationals — using stolen or fabricated identities — secure remote employment at Western technology companies, with particular concentration in Web3 firms. The DPRK government withholds up to 90% of wages, channeling revenue directly to weapons programs.
Scale: The U.S. Treasury estimated this scheme generated approximately $800 million in 2024. The United Nations estimates annual revenue between $250 million and $600 million since 2018, though the Treasury's higher figure suggests acceleration.
Operational structure: DPRK IT workers operate through organized delegations managed by entities like Amnokgang Technology Development Company, which runs offices in Shenyang and Dandong, China. Workers are deployed across multiple geographies — Vietnam, Laos, Russia, and Spain — using intermediary facilitators who handle identity documents and payment conversion.
DOJ indictments illustrate the scheme's domestic enabler network:
The IT worker pipeline also serves as a reconnaissance channel. Perry Choi, CEO of Aeye Intel and former U.S. Naval officer, noted in a 38 North analysis that embedded workers conduct internal reconnaissance that can facilitate subsequent hacking operations — blurring the line between the two pipelines.
On April 17, 2026, the Ketman Project published findings from a six-month investigation funded by the Ethereum Foundation's ETH Rangers program, launched in late 2024 to provide "stipends for individuals doing public goods security work."
Results:
gh_fake_analyzer) developed for GitHub activity analysisDetection methodology: Ketman's approach relies on behavioral pattern analysis across developer platforms. Documented red flags include:
The Ketman Dataset, a continuously updated threat actor database, and KetmanSearch, a private search engine with faceted filtering, represent the first systematic effort to catalog DPRK developer personas at scale. The Ethereum Foundation stated this work "directly addresses one of the most pressing operational security threats facing the Ethereum ecosystem today."
The significance of the 53-project figure requires context. It represents organizations where Ketman confirmed active DPRK operatives with sufficient confidence to issue alerts — not a comprehensive count of all infiltrated projects. The actual number of compromised organizations across the broader Web3 ecosystem is likely higher.
The U.S. government's enforcement response has escalated in 2026:
March 12, 2026 — OFAC Designations: Treasury sanctioned six individuals and two entities for IT worker fraud:
February 2026 — Treasury Sanctions on DPRK Bankers: Eight additional individuals and two entities sanctioned. Jang Kuk Chol managed $5.3 million in cryptocurrency. The Korea Mangyongdae Computer Technology Company (KMCTC) and Ryujong Credit Bank were designated for facilitating sanctions evasion.
Ongoing DOJ Actions: The DPRK RevGen: Domestic Enabler Initiative continues to target U.S.-based facilitators. The DOJ filed civil forfeiture complaints for more than $15 million in seized USDT from APT38 actors in March 2025.
The two pipelines exhibit fundamentally different economic profiles:
| Metric | Direct Hacking | IT Worker Infiltration | |--------|---------------|----------------------| | 2025 estimated yield | $2.02B | ~$800M | | All-time cumulative | $6.75B+ | $2.5B–4.0B (est.) | | Revenue per incident | $10M–$1.5B | $50K–$200K per worker/year | | Detection latency | Hours to days | Months to years | | Recovery rate | Low (<5% typical) | Near-zero (wages spent) | | Attribution confidence | High (on-chain forensics) | Moderate (identity verification) | | Operational risk | High (immediate response) | Low (persistent access) | | Secondary value | None | Internal reconnaissance |
The hacking pipeline produces larger, lumpier returns but triggers immediate incident response. The IT worker pipeline produces smaller, steadier yields with the added benefit of insider intelligence that can facilitate future exploits. The Drift attack illustrates the convergence: a six-month social engineering operation that combined the persistence of the infiltration model with the scale of a direct exploit.
From a value-capture perspective — applying the economic framework of analyzing where fees, revenue, and resources actually flow in blockchain ecosystems — DPRK operations represent a systematic extraction of economic value from Web3 protocols. The $2.8 billion extracted in 2025 alone exceeds the total annual fee revenue of most Layer-1 networks. This is not peripheral fraud; it is a material line item in the ecosystem's economic outflows.
1. Identity verification is now a security requirement, not a compliance checkbox. The Ketman findings demonstrate that standard KYC for contributors is insufficient. Behavioral analysis of development activity — commit patterns, timezone consistency, platform cross-referencing — is emerging as a necessary supplement.
2. Multi-signature governance remains vulnerable to social engineering. The Drift exploit bypassed technical security by compromising the human layer of governance. Protocols relying on multi-sig security councils face exposure to long-duration infiltration campaigns.
3. Compliance costs are rising. OFAC's designation of 21 crypto addresses creates screening obligations for any entity touching those addresses. As designations accumulate, compliance infrastructure becomes a non-trivial cost center for protocols — a dynamic consistent with PYMNTS's observation that "compliance is crypto's new cost of doing business."
4. The composability risk is systemic. Drift's $285 million exploit disrupted at least 20 dependent protocols. The economic interconnectedness of DeFi means that a single compromised protocol can generate cascading losses across the ecosystem.
DPRK's crypto operations are not a series of isolated incidents. They constitute a state-directed, dual-track extraction system operating at industrial scale. The hacking pipeline — now exceeding $6.75 billion in cumulative theft — targets protocols and exchanges for large, one-time payouts. The IT worker pipeline — estimated at $800 million annually — generates persistent, low-visibility revenue while providing internal reconnaissance that can enable future hacking operations.
The Ketman Project's April 17 disclosure marks the first systematic, open-source effort to catalog and counter the infiltration pipeline at scale. Combined with OFAC's March 2026 sanctions and ongoing DOJ prosecutions, the enforcement and detection infrastructure is expanding. Whether it expands fast enough to match the threat is an open question. Q1 2026 data — $309 million stolen in three months, with the Drift attack demonstrating an increasingly sophisticated convergence of infiltration and exploitation — suggests the offensive capability continues to outpace defensive measures.
For Web3 protocols, the economic calculus is straightforward. The cost of identity verification, behavioral monitoring, and governance hardening is non-trivial but quantifiable. The cost of a DPRK exploit — measured in hundreds of millions per incident, plus cascading ecosystem damage — is larger by orders of magnitude.