Skip to content

WT快讯

WeTrying | 币圈快讯早知道

Menu
  • 首页
  • 快讯
  • 港股
  • 美股
  • A股
  • 工具包
Menu

North Korean workers have been infiltrating DeFi for 7 years: Researcher

Posted on 2026年4月7日

North Korean IT workers have been embedding themselves in crypto companies and decentralized finance projects for at least seven years, according to a cybersecurity analyst.

“Lots of DPRK IT workers built the protocols you know and love, all the way back to DeFi summer,” said MetaMask developer and security researcher Taylor Monahan on Sunday.

Monahan claimed that over 40 DeFi platforms, some being well-known names, have had North Korean IT workers working on their protocols.

The “seven years of blockchain dev experience” on their resume is “not a lie,” she added.

The Lazarus Group is a North Korean-affiliated hacking collective that has stolen an estimated $7 billion in crypto since 2017, according to analysts at creator network R3ACH.

It has been linked to the industry’s highest-profile hacks, including the $625 million Ronin Bridge exploit in 2022, the $235 million WazirX hack in 2024 and the $1.4 billion Bybit heist in 2025.

Monahan’s comments came just hours after the Drift Protocol said it had “medium-high confidence” that the recent $280 million exploit against it was carried out by a North Korean state-affiliated group.

DeFi execs speak up on DPRK infiltration attempts

Tim Ahhl, founder of the Titan Exchange, a Solana-based DEX aggregator, said that in a previous job, “we interviewed someone who turned out to be a Lazarus operative.”

Ahhl said the candidate “did video calls and was extremely qualified.” He declined an in-person interview and they later discovered his name in a Lazarus “info dump.”

The US Office of Foreign Assets Control has a website where crypto businesses can screen counterparties against updated OFAC sanctions lists and be alert to patterns consistent with IT worker fraud.

Lazarus Group attack timeline. Source: R3ACH Network

Related: Drift Protocol says $280M exploit took ‘months of deliberate preparation’

Drift Protocol targeted by DPRK third-party intermediaries

Drift Protocol’s postmortem on last week’s $280 million exploit also pointed to North Korean-affiliated hackers for the attack.

However, it said the face-to-face meetings that eventually led to the exploit were not with North Korean nationals, but rather “third-party intermediaries” with “fully constructed identities including employment histories, public-facing credentials, and professional networks.”

“Years later, and it seems Lazarus now has non-NKs [North Koreans] working for them to con people in person,” said Ahhl.

Threats via job interviews are not sophisticated

Lazarus Group is the collective name for “all DPRK state-sponsored cyber actors,” explained blockchain sleuth ZachXBT on Sunday.

“The main issue is that everyone groups them all together when the complexity of threats is different,” he added.

ZachXBT said that threats via job postings, LinkedIn, email, Zoom, or interviews are “basic and in no way sophisticated … the only thing about it is they’re relentless.”

“If you or your team still falls for them in 2026, you’re very likely negligent,” he said.

There are two types of attack vectors, one more sophisticated than the other. Source: ZachXBT

Magazine: No more 85% Bitcoin collapses, Taiwan needs BTC war reserve: Hodler’s Digest


分享到:

  • 在 Facebook 上共享(在新窗口中打开) Facebook
  • 共享到 X(在新窗口中打开) X
  • 共享到 Threads(在新窗口中打开) Threads
  • 共享到 Bluesky(在新窗口中打开) Bluesky
  • 共享到 Telegram(在新窗口中打开) Telegram
  • 共享到 Nextdoor(在新窗口中打开) 隔壁
  • 分享到 Tumblr (在新窗口中打开) Tumblr
  • 共享到 Mastodon(在新窗口中打开) Mastodon

赞过:

赞 正在加载……

相关

发表评论取消回复

近期文章

  • European Central Bank Backs EU’s Plan For Centralized Crypto Firms Oversight
  • Federal court blocks Arizona crackdown on Kalshi’s event contracts
  • 【研报】苹果 AAPL一年净赚1120亿美元!股价却比高点低20%,是机会还是陷阱?
  • 【蔚来NIO】首次季度盈利背后:千亿亏损何时能填平?
  • Bitwise edges closer to Hyperliquid ETF launch with second amended filing

归档

  • 2026 年 4 月
  • 2026 年 3 月
  • 2026 年 2 月
  • 2026 年 1 月
  • 2025 年 12 月
  • 2025 年 11 月
  • 2025 年 10 月
  • 2025 年 9 月
  • 2025 年 8 月
  • 2025 年 7 月
  • 2025 年 6 月
  • 2025 年 5 月
  • 2025 年 4 月

分类

  • 1kx (1)
  • 21Shares (1)
  • a16z (1)
  • Aave (3)
  • ai16z (1)
  • Alameda Research (1)
  • Alpaca (1)
  • Arbitrum (1)
  • Ark Invest (1)
  • Arkham (1)
  • Avail (1)
  • Azuki (1)
  • A股 (13)
  • Base (1)
  • Berachain (1)
  • Bitget (8)
  • BlackRock (3)
  • Brian Armstrong (1)
  • BTC (5)
  • Bybit (2)
  • Canary (1)
  • Cathie Wood (1)
  • Coinbase (3)
  • Coinbase Prime (2)
  • Coinbase Ventures (3)
  • CoinDesk (2)
  • CoinGecko (1)
  • Cointelegraph (1)
  • COMP (1)
  • Compound (1)
  • DAO (1)
  • DATA (2)
  • DeAI (1)
  • DePIN (1)
  • DEX (3)
  • EARN (1)
  • Eliza (1)
  • ETF (4)
  • ETH (4)
  • Ethos Network (1)
  • Fartcoin (2)
  • FDUSD (1)
  • FLock.io (1)
  • FLUID (1)
  • FUEL (1)
  • Gas (2)
  • GPU (1)
  • Grayscale (1)
  • IEO (1)
  • Inception (1)
  • IOG (1)
  • Jupiter (1)
  • Kairos (1)
  • Kaito (1)
  • Launchpool (1)
  • Layer2 (1)
  • Liquidity (1)
  • Magicblock (1)
  • Mango Markets (1)
  • Mechanism Capital (1)
  • Meebits (1)
  • Meme (3)
  • Netflix (1)
  • NVIDIA (1)
  • Ondo (1)
  • OpenAI (2)
  • Paradigm (1)
  • Polygon (3)
  • Pudgy Penguins (1)
  • pump.fun (1)
  • Raydium (2)
  • Robert Leshner (1)
  • Robinhood (1)
  • Sam Altman (1)
  • SEC (4)
  • Securitize (1)
  • SideKick (1)
  • SNX (1)
  • SOL (1)
  • Solana (3)
  • Stani Kulechov (1)
  • StarkWare (1)
  • STO (1)
  • Stripe (1)
  • SunDog (1)
  • SunPump (1)
  • Synthetix (1)
  • TechFlow (40,604)
  • The Block (2)
  • Tron (2)
  • TRX (1)
  • Upbit (1)
  • USDC (3)
  • WBTC (2)
  • Web3 (4)
  • WLD (1)
  • WOO X (1)
  • Xai (1)
  • Zora (1)
  • 交易所动态 (8)
  • 人工智能 (1)
  • 以太坊 (4)
  • 以太坊基金会 (1)
  • 信托 (1)
  • 借贷 (2)
  • 公链 (1)
  • 基础设施 (1)
  • 大额投融资 (1)
  • 存储 (2)
  • 孙宇晨 (2)
  • 安全 (2)
  • 富达 (1)
  • 工具 (2)
  • 币安 (7)
  • 快讯 (41,028)
  • 托管 (1)
  • 指数 (1)
  • 支付 (1)
  • 数据 (6)
  • 数据追踪 (4)
  • 智能合约 (1)
  • 未分类 (322)
  • 模块化 (1)
  • 欧洲 (1)
  • 欧盟 (1)
  • 比特币 (7)
  • 永续合约 (1)
  • 治理 (1)
  • 波场 (1)
  • 港股 (5)
  • 游戏 (3)
  • 火币 (1)
  • 灰度 (1)
  • 特朗普 (5)
  • 社交 (2)
  • 稳定币 (3)
  • 空投 (6)
  • 纳斯达克 (1)
  • 美国 (6)
  • 美国证券交易委员会 (3)
  • 美股 (2)
  • 英伟达 (2)
  • 英国 (1)
  • 萨尔瓦多 (1)
  • 融资 (3)
  • 行情异动 (7)
  • 贝莱德 (1)
  • 质押 (4)
  • 赵长鹏 (1)
  • 跨链 (3)
  • 跨链桥 (1)
  • 迪拜 (1)
  • 重要消息 (45)
  • 金库 (1)
  • 钱包 (4)
  • 阿根廷 (1)
  • 阿里云 (1)
  • 隐私 (2)
  • 项目重要进展 (9)
  • Bluesky
  • Mail
©2026 WT快讯 | Design: Newspaperly WordPress Theme
%d