North Korea operates three distinct but converging pipelines to extract value from the cryptocurrency ecosystem: direct protocol hacks, covert IT worker placement, and software supply chain compromises. Combined, these operations generated an estimated $2.8 billion or more in 2025 alone, accordin...
"We anticipate they will try to leverage the credentials and system access they recently obtained in this software supply chain attack to target and steal cryptocurrency from enterprises." — Charles Carmakal, Chief Technology Officer, Mandiant (Google)
North Korea operates three distinct but converging pipelines to extract value from the cryptocurrency ecosystem: direct protocol hacks, covert IT worker placement, and software supply chain compromises. Combined, these operations generated an estimated $2.8 billion or more in 2025 alone, according to data from Chainalysis, the U.S. Treasury, and the FBI. The Ethereum Foundation's ETH Rangers program, whose final report was published on April 16, 2026, provides the first systematic mapping of the IT worker infiltration vector, identifying 100 suspected DPRK operatives embedded across 53 Web3 projects.
This report compares the three attack vectors side by side — their economics, operational methods, and countermeasures — drawing on OFAC enforcement actions, Chainalysis crime data, the Drift Protocol post-mortem, and the Ketman Project's detection framework. The data suggests that while direct hacking captures headlines, the IT worker pipeline may pose a more persistent and harder-to-detect systemic risk.
According to Chainalysis's 2026 Crypto Crime Report, North Korean-linked actors stole $2.02 billion in cryptocurrency during 2025 — a 51% increase year-over-year and approximately 59% of the $3.4 billion total stolen across the industry. DPRK-attributed attacks accounted for 76% of all service compromises, per the same report.
The cumulative total since 2017 now stands at $6.75 billion in stolen crypto assets. That figure does not include revenue from the IT worker programs, which the U.S. Treasury estimates generated approximately $800 million in 2024 alone. Adding the FBI's broader estimate of $600 million to $1 billion over the past five years from IT worker salaries, the aggregate DPRK extraction from the crypto ecosystem likely exceeds $8 billion.
These funds flow to the DPRK's weapons of mass destruction and ballistic missile programs, according to designations issued by OFAC on March 12, 2026.
Direct hacking remains the highest-yield single-event attack vector. The February 2025 Bybit exploit — $1.5 billion stolen in approximately 30 minutes — stands as the largest crypto theft on record. The FBI attributed it to North Korea's Lazarus Group (also tracked as TraderTraitor, APT38).
The attack methodology at Bybit involved compromising a Safe{Wallet} developer machine to gain access to an exchange-operated account. Within 48 hours, over $160 million had been funneled through illicit channels. By February 26, 2025, more than $400 million had been moved, according to TRM Labs.
The Drift Protocol exploit of April 1, 2026 — $285 million — demonstrated an evolution in technique. According to Drift's post-mortem, published and analyzed by The Record, the operation began six months prior at a cryptocurrency conference. North Korean operatives used intermediaries with "fully constructed identities including employment histories, public-facing credentials and professional networks" to approach Drift contributors. The technical attack exploited Solana's durable nonce feature to trick Security Council members into pre-signing transactions that transferred admin control. The attackers then whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH.
Elliptic and Chainalysis attributed the attack with medium confidence to UNC4736, a North Korean state-affiliated group also tracked as AppleJeus, Citrine Sleet, and Golden Chollima.
The Drift case illustrates the convergence of social engineering and technical exploitation — blending the IT worker infiltration model with direct hacking. The six-month relationship-building phase mirrors the patience observed in the IT worker programs.
The Ethereum Foundation published the final recap of its ETH Rangers program on April 16, 2026. The program, launched in late 2024 in partnership with Secureum, The Red Guild, and the Security Alliance (SEAL), provided stipends to 17 security researchers for public-goods work. Across all recipients, the program recovered or froze over $5.8 million, cataloged 785 vulnerabilities, and coordinated 36 security incident responses.
The most significant finding came from one recipient's initiative: the Ketman Project. Over six months, Ketman identified approximately 100 DPRK IT workers active within Web3 organizations and alerted 53 projects that had unknowingly employed them. The project coordinated the freezing of mid-six-figure amounts in funds received by those workers and notified 30+ teams directly.
The infiltration methodology is systematic. DPRK operatives create fabricated identities complete with fake GitHub profiles, manufactured employment histories, and AI-generated profile photos. Technical red flags documented by Ketman include:
Individual DPRK IT workers can earn up to $300,000 annually, according to FBI estimates. Salaries are typically paid in stablecoins — USDC and USDT — routed through cryptocurrency to circumvent sanctions. The scale is industrial: the U.S. Treasury stated on March 12, 2026 that DPRK IT worker fraud schemes generated approximately $800 million in 2024.
The Ketman Project developed an open-source detection tool, gh-fake-analyzer, now available on PyPI, designed to flag suspicious GitHub activity. The project also co-authored the DPRK IT Workers Framework with SEAL, which has become an industry-standard reference document.
On March 31, 2026, CNN reported that suspected North Korean hackers had compromised the Axios open-source software package — used by thousands of U.S. companies — in a supply chain attack. According to Mandiant (Google), the hackers gained three-hour access to a developer's account and pushed malicious updates to any organization that downloaded the software during that window.
Security researcher John Hammond of Huntress identified approximately 135 compromised devices belonging to roughly 12 companies as a first snapshot, with the full victim pool expected to grow significantly. Mandiant's CTO Charles Carmakal stated the attackers would likely leverage the credentials obtained to target cryptocurrency holdings.
Supply chain attacks represent a lower-frequency but potentially higher-blast-radius vector. Unlike direct protocol exploits, they can compromise hundreds of organizations simultaneously. Unlike IT worker infiltration, they require no sustained human presence inside target organizations. The tradeoff is uncertainty — the attacker gains broad access but must then identify and exfiltrate crypto assets from among many possible targets.
| Metric | Direct Hacking | IT Worker Infiltration | Supply Chain Attacks | |---|---|---|---| | Largest Single Event | $1.5B (Bybit, Feb 2025) | ~$800M annually (OFAC, 2024) | Unknown (Axios, Mar 2026) | | 2025 Known Total | $2.02B (Chainalysis) | $600M-$1B est. (FBI, 5-yr avg.) | Data inconclusive | | Operational Timeline | Hours to months of prep; minutes of execution | 6+ months continuous employment | Hours of access window | | Detection Difficulty | High (post-event forensics) | Very high (blends with legitimate work) | Moderate (software integrity checks) | | Attribution Confidence | Medium to high | Medium | Medium | | Known Countermeasures | Multisig, circuit breakers, time-locks | Identity verification, SEAL framework | Software signing, dependency auditing | | Persistence | One-time events | Continuous, renewable | Brief access windows |
The data indicates that IT worker infiltration is the most persistent revenue stream — it produces ongoing income rather than one-time payouts and is harder to detect because operatives function as legitimate employees. Direct hacking produces the largest single payoffs but is episodic and triggers immediate responses. Supply chain attacks occupy a middle ground with broad potential impact but uncertain yield.
Enforcement actions have accelerated in 2026. Key actions include:
OFAC Designations (March 12, 2026): Treasury sanctioned six individuals and two entities — Amnokgang Technology Development Company and Quangvietdnbg International Services Company Limited — for facilitating DPRK IT worker fraud. The designations included 21 cryptocurrency addresses across multiple blockchains.
DOJ Sentencing (April 16, 2026): Two U.S. citizens, Kejia Wang and Zhenxing Wang, received sentences of seven-and-a-half and nine years respectively for operating "laptop farms" in New Jersey. The farms allowed North Korean operatives to appear to be working from U.S. locations. The scheme involved stolen identities of 80+ Americans and placement at over 100 U.S. corporations, including Fortune 500 companies, generating approximately $5 million.
FBI RevGen Initiative: Launched in March 2024 by the National Security Division and FBI Cyber and Counterintelligence Divisions, this ongoing initiative targets U.S. persons facilitating DPRK remote IT work. The DOJ has also filed civil forfeiture complaints against over $7.74 million laundered on behalf of the North Korean government.
Despite these actions, the enforcement gap remains wide. The $5 million recovered in the Wang case represents a fraction of the estimated $800 million generated annually. The Ketman Project's mid-six-figure fund freezes, while meaningful for affected protocols, are similarly small relative to the scale of operations.
The ETH Rangers program produced several concrete tools and frameworks:
For direct hacking, the Drift post-mortem highlighted specific technical countermeasures: reviewing durable nonce usage in multisig governance, implementing time-delayed execution for governance actions, and requiring independent verification of transaction payloads.
For supply chain attacks, standard mitigations include software signing, dependency pinning, and real-time monitoring of package registry activity. The Axios incident demonstrated that a three-hour compromise window is sufficient to affect thousands of downstream organizations.
The fundamental challenge across all three vectors is that DPRK operations are state-sponsored with the full resources of a national intelligence apparatus. Individual Web3 projects — often small teams with limited security budgets — face a structural asymmetry.
The data shows three converging DPRK attack vectors operating at different time scales and yield profiles. Direct hacking produces episodic, high-value events. IT worker infiltration generates persistent, steady-state revenue. Supply chain compromises offer broad access with variable returns. The Drift Protocol case — where social engineering and technical exploitation merged over a six-month timeline — suggests these vectors are increasingly difficult to separate.
The Ketman Project and ETH Rangers represent a first-generation detection capability funded at stipend level. Whether the ecosystem invests proportionally to the threat — measured in billions, not stipends — remains an open question. The structural asymmetry between state-sponsored attackers and decentralized protocol teams is, by the available data, widening.