Researcher: North Korean IT workers infiltrated DeFi for 7 years; Drift says $285M+ exploit was six‑month, conference‑based social‑engineering operation by DPRK‑linked impostors
first published 2026-04-06T06:04:46Z
MetaMask developer Taylor Monahan says North Korean IT workers have embedded themselves in crypto firms and DeFi projects for at least seven years, with over 40 DeFi platforms having purported DPRK-linked developers. Analysts link the Lazarus Group to roughly $7 billion in crypto thefts since 2017 — including Ronin Bridge, WazirX and Bybit incidents — and attribute Drift Protocol’s $280 million exploit with medium-high confidence to a North Korean state-affiliated group using intermediaries and in-person social engineering. Industry figures warn recruitment and interview-based infiltration is common and recommend screening counterparties (e.g., OFAC lists).
AI Analysis
Facts: researcher reports seven years of DPRK-linked developers in DeFi and >40 affected platforms; analysts tie Lazarus Group to ~$7B in crypto thefts including Ronin, WazirX and Bybit; Drift’s $280M exploit was attributed with medium-high confidence to a North Korean state-affiliated group using third-party intermediaries and in-person social engineering; industry sources advise screening counterparties (e.g., OFAC) to guard against infiltration.
Expected Investor Sentiment: Very Bearish
Potential Market Impact: High
Source Articles
- North Korean workers have been infiltrating DeFi for 7 years: Researcher - Cointelegraph
- North Korean IT workers operated within DeFi protocols for years, researcher warns - Crypto News
- XRPL Validator Sounds Alarm to XRP Users on Social Engineering Threat - U.Today
- North Korean Hackers Spent Six Months Infiltrating Drift Before $285M Exploit - Decrypt
- Morning Minute: North Korea Hacks Drift for $285M - Decrypt
- ‘Six Months in the Making’: Drift Protocol Says $285,000,000+ Hack Involved North Korean-Backed Impostors at Multiple Crypto Conferences - Daily Hodl