North Korea has built what 38 North, the Johns Hopkins SAIS research program, calls a "state-run digital kleptocracy" — a sovereign wealth fund denominated in stolen cryptocurrency and shielded from traditional sanctions enforcement. The numbers quantify the scale: $6.75 billion in cumulative cry...
"I don't care where they live. If I'm paying someone and they're forced to send their entire paycheck to their boss, that makes me very uncomfortable. And if their boss is the North Korean regime, that makes me even more uncomfortable." — Taylor Monahan, Security Researcher, MetaMask
North Korea has built what 38 North, the Johns Hopkins SAIS research program, calls a "state-run digital kleptocracy" — a sovereign wealth fund denominated in stolen cryptocurrency and shielded from traditional sanctions enforcement. The numbers quantify the scale: $6.75 billion in cumulative crypto theft through 2025, according to Chainalysis; $2.02 billion stolen in 2025 alone, a 51% increase year-over-year; and IT worker fraud schemes generating an estimated $800 million in 2024.
In April 2026, the Ethereum Foundation disclosed results from its six-month ETH Rangers Program: approximately 100 DPRK-linked IT workers identified across 53 crypto projects, $5.8 million in funds recovered, and 785-plus security vulnerabilities cataloged. The findings arrived weeks after OFAC designated six individuals and two entities tied to North Korean IT worker fraud on March 12, 2026, and one month after the $285 million Drift Protocol exploit — the largest DeFi hack of 2026 — was attributed to UNC4736, a DPRK-aligned state-sponsored hacking group.
The data describes a two-track operation: direct theft through sophisticated hacking campaigns, and a slower-burn infiltration of the crypto labor market through IT worker placement. Both tracks funnel revenue toward the DPRK's weapons of mass destruction programs. The crypto industry is now developing ad hoc countermeasures, but the structural conditions that enable infiltration — remote-first hiring, pseudonymous contribution, and minimal background verification — remain largely unchanged.
According to Chainalysis's annual Crypto Crime Report, total cryptocurrency theft reached $3.4 billion in 2025. North Korean-attributed theft accounted for $2.02 billion of that total — 59% of all stolen funds globally. DPRK-linked attacks represented 76% of all service compromises by value, according to the same report.
The concentration of losses is increasing. The top three hacks of 2025 accounted for 69% of total losses, and the ratio between the largest single hack and the median incident crossed the 1,000x threshold for the first time. A single attack on Bybit in February 2025 accounted for $1.5 billion — the largest individual crypto hack on record.
Cumulative DPRK crypto theft now stands at $6.75 billion, according to Chainalysis's lower-bound estimate. 38 North's January 2026 analysis recommended that U.S. and allied sanctions architecture "formally treat DPRK crypto-theft proceeds as weapons of mass destruction financing."
On the IT worker side, the U.S. Treasury estimated these schemes generated approximately $800 million in 2024. Individual IT workers can earn around $300,000 annually; coordinated teams can generate over $3 million, according to government advisories. The January 2026 State Department report on DPRK sanctions violations characterized these operations as a systematic revenue stream funding weapons programs.
The $285 million Drift Protocol exploit on April 1, 2026, illustrates the current state of DPRK hacking methodology. According to incident analysis published by The Hacker News and corroborated by Chainalysis, TRM Labs, and Elliptic, the attack was the culmination of a six-month social engineering campaign that began in the fall of 2025.
UNC4736 — also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces — deployed operatives posing as a quantitative trading firm. These individuals attended conferences across multiple countries, built relationships with Drift contributors, and deposited over $1 million in the protocol before executing the attack. Drift's post-mortem stressed that the individuals appearing at conferences were not North Korean nationals; DPRK threat actors at this level deploy third-party intermediaries for face-to-face operations.
The technical execution involved social engineering Drift Security Council members into signing transactions that transferred administrative control to an attacker-controlled address. Once in control, the attackers whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH.
Separately, on March 31, 2026, CNN reported that suspected North Korean hackers compromised the account of a developer maintaining Axios, an open-source software package used by thousands of U.S. companies. For three hours, any organization downloading the package received malicious updates. Mandiant, the Google-owned cyber intelligence firm, identified a DPRK-linked group as responsible. Security firm Huntress identified approximately 135 compromised devices across 12 companies in an initial assessment, with the total expected to grow.
According to Chainalysis, the DPRK shows clear preferences for Chinese-language money laundering services, bridge protocols, and mixing services, with a standard 45-day laundering cycle following major thefts. The Korea Herald reported in April 2026 that North Korea has stolen $2.84 billion in crypto since 2024, with China aiding the cash-out process.
MetaMask security researcher Taylor Monahan has documented DPRK IT workers embedded in DeFi projects dating back to 2020's "DeFi Summer." According to Monahan, North Korean workers contributed legitimate code to projects including SushiSwap, THORChain, Yearn Finance, Harmony, Ankr, and Shiba Inu, among others. The years of blockchain development experience listed on their resumes were often genuine — reflecting real technical contributions rather than fabricated credentials.
The infiltration methodology has evolved over time, according to the Ketman Project's framework co-authored with the Security Alliance (SEAL):
Phase 1 (2018–2022): Direct job applications using stolen or fabricated identities, often with AI-generated profile photos. The approach relied on the industry's remote-first culture and minimal background verification.
Phase 2 (2023–present): Operatives now impersonate recruiters for prominent Web3 and AI firms, orchestrating fake hiring processes culminating in "technical screens" designed to harvest credentials, source code, and VPN or SSO access to the victim's current employer.
Technical red flags identified by the Ketman Project include: reusing avatars and profile metadata across multiple GitHub accounts, exposing unlinked email addresses during accidental screen sharing, and default language settings (often Russian) that contradict claimed nationalities.
The U.S. Department of Justice has secured convictions in related cases. Two individuals who facilitated DPRK IT worker placement in U.S. companies received multi-year prison sentences.
The Ethereum Foundation disclosed full results of its ETH Rangers Program on April 16, 2026, via its official blog. The program ran for six months in partnership with Secureum, The Red Guild, and the Security Alliance (SEAL), funding 17 stipend recipients.
Consolidated outcomes:
Two recipients drove the DPRK-specific results:
The Ketman Project identified approximately 100 DPRK operatives across 53 projects, reaching 3,300 active users and 6,200 page views on its threat documentation platform. The team open-sourced gh-fake-analyzer (available on PyPI), a tool for detecting fabricated GitHub profiles, and co-authored the DPRK IT Workers Framework with SEAL. The work was featured at DEF CON.
Nick Bax contributed to 36 SEAL 911 incident response tickets, assisted with the Loopscale exploit response (which accounted for the $5.8 million recovery), and notified 30-plus teams employing DPRK-linked workers, coordinating the freezing of hundreds of thousands of dollars already paid to operatives. Bax's awareness video documenting DPRK "Fake VC" scams received 200,000 views. He presented findings at a U.S. Treasury roundtable and at Interpol Headquarters.
Additionally, the program's execution client DoS research discovered 14 bugs across five major Ethereum clients (Geth, Besu, Erigon, Nethermind, Reth), finding asymmetric CPU consumption up to 4x in some cases.
On March 12, 2026, the U.S. Treasury's Office of Foreign Assets Control designated six individuals and two entities for roles in DPRK IT worker fraud schemes. According to Chainalysis's analysis of the designation:
Designated individuals: Nguyen Quang Viet, Do Phi Khanh, Hoang Van Nguyen, Yun Song Guk, Hoang Minh Quang, and York Louis Celestino Herrera.
Designated entities: Amnokgang Technology Development Company (a DPRK IT company managing overseas worker delegations) and Quangvietdnbg International Services Company Limited (owned or controlled by designee Nguyen Quang Viet).
The designation included 21 cryptocurrency addresses across multiple blockchains, highlighting the multi-chain fund movement approach. OFAC also updated the entry for previously designated Sim Hyon Sop, a China-based representative for Korea Kwangson Banking Corp, adding 11 new cryptocurrency addresses across Ethereum and Tron networks.
According to the Treasury, between mid-2023 and mid-2025, Nguyen alone converted approximately $2.5 million into cryptocurrency for the regime, including illicit earnings from IT workers associated with Amnokgang. The BanklessTimes reported the total scheme value at $800 million.
The crypto industry's response has been largely ad hoc. The most widely discussed screening method — the so-called "Kim Jong Un test" — involves asking job candidates to insult North Korea's leader during video interviews. The technique exploits the severe ideological conditioning under which DPRK operatives are trained; criticizing the country's leader is illegal in North Korea and carries the risk of severe punishment.
According to reporting from CyberSecurityNews and NewsBTC in April 2026, a widely shared video showed a candidate abruptly disconnecting during such a prompt. Crypto founder Pav, who focuses on real-world asset development, has used the tactic since 2024 after discovering he had interviewed a DPRK agent in 2022. Security researcher Paolo Caversaccio, who has dealt with DPRK IT workers for more than three years, has described the filter as "very strong."
More systematic approaches include:
These tools address detection after infiltration. Prevention remains structurally difficult in an industry built on pseudonymous, permissionless contribution.
The conditions that enable DPRK infiltration are not incidental to crypto — they are foundational to how the industry operates. Remote-first hiring, pseudonymous contribution, minimal KYC in developer onboarding, and decentralized governance structures all create attack surface.
The Drift exploit demonstrated that even protocols with multi-signature security councils can be compromised through social engineering of individual signers. The Axios supply chain attack showed that even non-crypto open-source infrastructure used by crypto firms creates exposure.
The Cloud Security Alliance published a research note in 2026 characterizing the DPRK's approach as a "dual-track cyber doctrine" — combining direct theft with long-term supply chain infiltration to create systemic risk across DeFi infrastructure.
38 North's January 2026 analysis noted that recent reporting of a Chinese trader selling over 2,000 PCs and graphics cards to North Korea should be read "as a training signal, not a gaming build-out" — classroom-scale machines for teaching coding, intrusion, and crypto development.
The data describes an asymmetric threat: a nation-state with an estimated GDP of $28 billion has extracted $6.75 billion from a single industry over approximately seven years. The DPRK's dual-track approach — combining high-impact hacking with persistent IT worker infiltration — exploits the structural characteristics that define crypto: open-source development, remote-first teams, and pseudonymous participation.
The ETH Rangers Program demonstrated that detection is possible with dedicated resources. But the program operated for six months with 17 stipend recipients — modest resources relative to the scale of the threat. The 100 operatives identified across 53 projects represent what one program found in six months; the total embedded workforce remains unknown.
OFAC sanctions and DOJ prosecutions create friction, but the DPRK's use of third-party intermediaries, multi-chain fund movement, and Chinese-language laundering services provides substantial operational resilience. The 45-day laundering cycle documented by Chainalysis suggests the conversion pipeline from stolen crypto to usable funds is well-optimized.
For the crypto industry, the implications are concrete: any protocol with remote contributors, pseudonymous governance participants, or open-source dependencies has potential exposure. The economic incentives for the DPRK are clear and growing. Absent structural changes in how the industry verifies contributors and secures governance processes, the threat profile will persist.