Unchained
Unchained

How North Koreans Infiltrated the Crypto Industry to Fund the Regime - Ep. 715

The crypto community is facing a new kind of threat—North Korean devs are infiltrating crypto companies to steal millions and funnel funds back to the regime in order to bypass sanctions. In this episode, Sam Kessler, CoinDesk’s deputy managing editor for tech and protocols, and Taylor Monahan, secu

Featured Speakers

Taylor Monaghan GuestSam Kessler Guest

Topics Discussed

Episode Summary

Executive Summary: The episode examines how North Korean actors are infiltrating crypto through fake IT-worker identities and social engineering, then leveraging that access for hacks and laundering. Sam Kessler and Taylor Monaghan explain how widespread the problem is, why crypto’s open, remote, pseudonymous culture makes it vulnerable, and what projects should do: rigorous background checks, strict access controls, and multi-signer security.

Main Topics: North Korean IT-worker infiltration of crypto (Priority: 5/5): Sam describes an investigation showing North Korean workers using fake identities and resumes to get hired by crypto companies, with wages funneled back to the regime. Why crypto is uniquely vulnerable (Priority: 5/5): The guests argue crypto’s remote, pseudonymous, informal hiring norms and key-based asset custody create an ideal environment for infiltration and theft. How hiring and social engineering work (Priority: 5/5): They detail patterns like Discord DMs, text-only interviews, fake IDs, camming up late, inconsistent biographies, and quick trust-building that leads to employment. On-chain tracing and laundering (Priority: 4/5): Taylor and Sam explain how payroll payments consolidate into wallets, then move through laundering networks, often in two-week cycles, making the activity visible on-chain. Connection to later hacks and exploits (Priority: 5/5): The conversation links infiltrated employees to later compromises of treasuries, private keys, admin rights, and smart contracts, often after trust has been established. Defensive practices for protocols (Priority: 5/5): The guests recommend professional background checks, ID verification, access revocation, multiple signers, and no single person having full control over keys or code. Broader trend in crypto crime (Priority: 4/5): They conclude that crypto crime is still rising, especially North Korean activity, and that the industry must learn from repeated failures rather than assume problems are solved.

Key Arguments: North Korean IT workers have been infiltrating crypto for years, using fake identities and resumes to earn wages and route money back to Pyongyang. The problem is widespread: Sam says he identified about a dozen crypto companies affected, including recognizable projects like Cosmos Hub, Injective, Yearn, and Sushi. These workers are often actual developers, not just generic IT staff, and some later become vectors for hacks by gaining access to code, admin rights, or private keys. Crypto’s culture of anonymous hiring, Discord-based recruiting, and weak background checks makes it easier to hire malicious actors unnoticed. On-chain data can reveal payroll patterns and laundering funnels, especially when payments go to consolidated addresses every couple of weeks. The most common attacks are social-engineering based rather than sophisticated technical exploits; a single compromised person can open the door to broader theft. Even if a company is not clearly hacked by North Korea, hiring these workers can still expose it to delayed, dormant exploits that may trigger later. The best defense is not just identity vetting but structural security: strict role separation, key management, access revocation, and multiple approvals for sensitive actions.

Data Points: North Korean hacks traced to IT workers in 2024: About half - Chainalysis said about half of North Korea’s largest crypto attacks in 2024 were perpetrated or aided by North Korean IT workers. Crypto companies identified as affected: Around a dozen - Sam said he independently identified roughly 12 crypto companies that had unwittingly hired North Korean developers. TrueFlation workers identified as North Korean: 5 total - In the TrueFlation story, four other employees plus one main worker were identified as North Korean IT workers. TrueFlation company size: About 12–15 people - The founder described TrueFlation as a small team, making the infiltration especially striking. North Korean share of wages retained: 10% to 30% - Taylor cited UN estimates that only a minority of wages go to the actual workers, with the majority returned to the regime. Annual funds sent to North Korea from IT-worker activity: $250 million to $600 million - Sam cited a UN estimate of total annual funds flowing to the regime from these workers across industries. Monthly crypto-related flow to North Korea: About $500,000 per month - Taylor said the crypto-side payments alone are roughly half a million dollars per month. North Korea crypto theft in 2023: About $1 billion - Taylor referenced Chainalysis estimates for North Korean crypto theft over the prior year. North Korea crypto theft in 2024 year-to-date: About $600 million to $700 million - Taylor said 2024 was already approaching another billion-dollar year with several months left. Sushi hack loss: Around $3 million - Sam used Sushi as an example of a later exploit linked to compromised access and social engineering. TrueFlation theft: $5 million - Sam said TrueFlation ultimately lost $5 million after the hiring/infiltration episode. Delta Prime loss: $7 million - Sam noted Delta Prime lost $7 million in a separate but related incident. CZ-style exchange loss example: $600 million versus $20 million - Taylor contrasted a fully compromised system with a partially contained hack to show the value of segmented controls.

Pivotal Quotes: "if they're not sure and if they haven't done an audit, a specific audit with an eye to these sorts of problems, do that audit and make sure their code is safe." — Unknown speaker (opening narration): Sets the episode’s central warning that dormant compromises may exist for years before being exploited. "it really does resemble some of those old systems that we've seen." — Taylor Monaghan: Taylor compares wage diversion to exploitative labor structures, emphasizing the ethical dimension. "What I'm concerned about is that this has been going on for years and years." — Sam Kessler: Sam closes by stressing the long-running nature of the threat and the need for proactive audits.

Implications: Crypto projects should treat hiring and access control as security-critical. The episode suggests the industry still underestimates North Korean infiltration, and that better identity checks, access segmentation, and code audits are now essential to reduce future losses.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained