h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

The Insider Was on Payroll: Crypto’s North Korea Post-Mortem

North Korea turned crypto hiring into its most profitable exploit, from the $285M Drift heist to salaried developers who wrote their own backdoors. A post-mortem of the insider threat, and how to catc

In August 2026, two security researchers stood on a stage at DEF CON in Las Vegas and described a company that never existed. Mauro Eldritch of BCA LTD and Heiner García of NorthScan, working with the malware-analysis firm ANY.RUN, had built a fake DeFi startup called Ballena Azul, posted developer job listings, and waited to see who applied. Within weeks they had hired three engineers. All three, the researchers concluded, were suspected North Korean operatives, presented as part of the cluster known as Famous Chollima that sits under the wider Lazarus umbrella, according to The Hacker News.

The hires arrived through the most ordinary channel imaginable. A recruiter found the first developer on GitHub; that developer vouched for a friend; the friend vouched for a third. They passed interviews, signed contracts, and were handed access to work machines. Only because every session was recorded did the pattern surface: a developer who claimed to live in Pasadena, Texas but produced a California driver’s license and a New York bank account; profile photos carrying Google Gemini processing traces and SynthID watermarks; and, on day one, a burst of system-profiling commands followed by the quiet installation of Chrome Remote Desktop and an Astrill VPN. The recruiters had done nothing wrong. They had simply hired the people who applied.

That experiment is the cleanest illustration yet of the attack vector that dominated crypto losses in 2026. It is not a smart-contract bug, a bridge misconfiguration, or a phished signature. It is a hire. This is a post-mortem of that vector: how North Korea turned the crypto industry’s own hiring pipeline into an exploit, what it has cost, and why the fix looks less like an audit and more like counterintelligence.

The startup that hired three of its own attackers

The Ballena Azul sting works as a post-mortem lede precisely because the victims were experts who were actively hunting for exactly this outcome. Eldritch and García were not a naive team that fell for a slick resume; they built the trap, controlled the environment, and recorded every keystroke. And they still ended up with three suspected operatives on the books, brought in one by one through a referral chain in which each new hire vouched for the next. Referrals between operatives are a documented tactic, because a warm introduction skips the scrutiny a cold applicant would draw.

The tells were there for anyone recording closely enough. The first hire’s identity documents did not agree with each other across state lines. The second used a Texas license, a valid Social Security number, and a Kansas City bank account. The third submitted a New York license belonging to someone else. Profile images showed the fingerprints of generative-AI tooling. Within hours of gaining access, all three ran reconnaissance commands and installed remote-desktop software so a second person, somewhere else, could take the wheel. If a purpose-built honeypot run by specialists caught this only on the recordings, the implication for an ordinary startup that is not looking is grim: the funnel is compromised by default.

Why the hiring pipeline is the exploit

The security desk has spent 2026 documenting a single migration: value has moved from breaking code to breaking the people and systems around it. Reviewing the Drift hack, Chainalysis put it bluntly, warning that the greatest risks are no longer just in smart contracts, but in the systems, and people, that surround them. The North Korean IT-worker program is the purest expression of that shift. Every other attacker in this cluster spends time and money trying to acquire privileged access: phishing a signature, stealing an admin key, compromising a build server. The IT worker is handed all of it on the first day of employment, along with a laptop and a Slack invite.

That is what makes this a post-mortem and not a hack story. A hack has a moment of intrusion you can point to. Here, the intrusion is the onboarding email. The root cause is not a line of Solidity or a misconfigured verifier; it is an organizational process that was designed to be welcoming rather than adversarial. And like the recurring bugs the industry keeps re-discovering, this failure repeats because the incentive that drives it, a sanctioned state that needs hard currency, never goes away. You cannot patch a hiring funnel the way you patch a contract. You can only make it harder to abuse.

The scale: a nation-state on the org chart

The aggregate numbers explain why this stopped being a curiosity and became the industry’s dominant loss category. In its 2026 crime report, Chainalysis attributed about $2.02 billion of 2025 crypto theft to North Korea, a 51 percent jump year over year and roughly 60 percent of all funds stolen, pushing the lower-bound lifetime tally to about $6.75 billion. TRM Labs, measuring the current year, found North Korea behind roughly two-thirds of all crypto stolen in the first half of 2026, about $643 million, with $577 million coming from just two April attacks on DeFi platforms. TRM also charts the trend line that matters most: North Korea’s share of global crypto hack losses climbed from below 10 percent in 2020 and 2021 to 22 percent in 2022, 37 percent in 2023, 39 percent in 2024, and 64 percent in 2025.

Theft is only one revenue line. The salaries themselves are the other. The on-chain investigator ZachXBT traced more than $16.58 million in payments since January 1, 2025, or about $2.76 million per month, flowing to North Korean IT workers hired as developers at various projects. With monthly salaries running from $3,000 to $8,000, that implies somewhere between 345 and 920 compromised roles, spread across at least six clusters he monitors. He has also warned that operatives increasingly control verified accounts on major U.S. exchanges such as Robinhood and Coinbase, the same custody-grade infrastructure that a growing number of users now treat as a wallet, a shift covered in HOGE Wire’s look at account abstraction and the exchange-as-wallet model.

MetricFigureSource
North Korea share of global crypto hack losses, 2020-2021Below 10%TRM Labs
2022 / 2023 / 2024 / 2025 share22% / 37% / 39% / 64%TRM Labs
First-half 2026 shareAbout two-thirds (~$643M)TRM Labs
North Korea crypto theft, 2025~$2.02 billion (+51% YoY)Chainalysis
Lifetime attributed theft~$6.75 billionChainalysis
Salary payments to DPRK devs, H1 2025>$16.58 million (~$2.76M/month)ZachXBT
Estimated compromised developer roles345 to 920ZachXBT

Anatomy of a fraudulent hire

The mechanics are now well documented, most thoroughly by Google’s Mandiant threat-intelligence team, whose analysts have tracked the operation as it expanded in scope and scale. The core of it is identity fraud at industrial volume. Operatives apply using stolen or synthetic identities, frequently the real details of American citizens, sometimes paired with profile photos altered by AI. They lean on non-North-Korean facilitators for the parts of the scheme that require a physical or legal presence in the target country. Mandiant’s guidance on mitigating the DPRK IT-worker threat notes that one American facilitator alone compromised more than 60 U.S. identities, touched over 300 companies, and generated $6.8 million between October 2020 and October 2023.

Once hired, the operative rarely sits where the paperwork says. A company laptop is shipped to a facilitator’s home, plugged into an IP-based keyboard-video-mouse device or loaded with remote-administration tools such as AnyDesk, TeamViewer, RustDesk, or Chrome Remote Desktop, and driven from abroad, usually through an Astrill VPN routed from China or Russia. To hold down several jobs at once, operatives run mouse-jiggler utilities that keep each machine looking active. They are reluctant to appear on camera, favor virtual backgrounds, and host fake LinkedIn profiles built on stolen executive photos. None of these tells is conclusive on its own. Stacked together, they are a signature.

TechniqueWhat it doesThe tell
Stolen or synthetic identityPasses background and I-9 checks using a real person’s detailsID, home address, and bank account in different states
Laptop farmGives an overseas worker a domestic corporate laptopShip-to address differs from stated residence
Remote-admin tools / IP-KVMLets an operative abroad drive a machine at homeAnyDesk, RustDesk, or Chrome Remote Desktop installed early
Astrill VPNMasks the true China or Russia originLogin geolocation inconsistent with claimed home
Mouse-jiggler softwareKeeps multiple jobs looking active at onceIdle-avoidance utilities such as Caffeine
AI-altered photos and deepfakesDefeats visual identity matchingSynthID watermarks or generative-AI artifacts in images

Drift: when the trusted outsider gets the keys

The emblematic incident of 2026 shows the vector in its most expensive form. Drift, a Solana perpetual-futures venue of the kind analyzed in HOGE Wire’s guide to who takes the other side of your trade on a perp DEX, lost about $285 million on April 1, 2026, by PeckShield’s count, roughly $280 million by the team’s own estimate, and more than half of the protocol’s total value locked. The attackers did not find a bug in the code. According to Chainalysis, they posed as a quantitative trading firm, approached Drift contributors at major crypto conferences, and maintained contact for roughly six months across Telegram, working sessions, and in-person meetings.

Then they weaponized trust. In the final week they abused Solana’s durable nonce feature, which lets a transaction be signed in advance and executed later, to get two of the five Security Council members to blindly pre-sign dormant transactions that quietly transferred admin control. On April 1 the attackers fired the pre-signed transactions; the largest withdrawals landed within the first few minutes, and drainage continued for about two and a half hours, according to Chainalysis’s review of the incident. On-chain indicators are consistent with previously attributed DPRK operations, though formal attribution remains pending. The signers were not operatives on payroll, but the mechanism is identical to the insider threat: they became trusted enough to hand over signatures without understanding what they were authorizing.

Drift matters for a second reason. A five-member Security Council multisig is exactly the kind of control the industry recommends, and it did nothing here, because the humans were the target, not the threshold. Good key management still helps; blind pre-signing does not. As HOGE Wire’s explainer on MuSig2 and FROST multisig stresses, the security of a signing scheme collapses the moment a signer approves something they cannot actually read.

Munchables: the developer who buried the backdoor

If Drift shows a trusted outsider getting the keys, Munchables shows what happens when the operative is on the team from the start. In March 2024, Munchables, an NFT game on the Blast layer-2 network, lost about $62.5 million. The root cause was not an external attacker at all. The project had hired a developer, working under the alias Werewolves0943, to write its smart contracts. That developer, later identified by ZachXBT as one of four personas likely run by a single suspected North Korean actor, had quietly built vulnerabilities into the contracts and then used that access to assign themselves a balance of one million ETH.

The ending was unusually clean: after ZachXBT tied the personas together and to the Lazarus Group, the developer returned almost all of the funds without demanding a ransom. But the lesson should have landed two years before Drift. Munchables was not breached; it was authored to be breachable, by someone the founders had paid to secure it. An audit of the deployed contracts would have had to catch a flaw that the contracts’ own author designed to be missed. The call was coming from inside the codebase, and the industry mostly filed it as an oddity rather than a warning.

Ronin: recruitment as the weapon

The hiring surface can also be run in reverse, with the fake job offered rather than applied for. The clearest case predates the current wave and remains one of the largest thefts in the industry’s history. In March 2022, the Ronin bridge behind Axie Infinity lost about $625 million. The vector was recruitment. Lazarus operatives approached a senior Sky Mavis engineer with a lavish, fictitious job offer, walked him through several rounds of interviews, and sent a malware-laced document dressed up as a formal offer letter. Opening it compromised his machine and, eventually, enough of the validator keys securing the bridge to authorize withdrawals.

Ronin and the IT-worker program are two faces of the same coin. One dangles a job to plant malware; the other takes a job to plant a person. Both exploit the fact that hiring, whether you are the candidate or the employer, is a process built on optimism and speed. Recruiters are measured on filling seats, and engineers are flattered by a good offer. Adversaries have learned to price both.

Laptop farms: the enablers next door

None of this scales without domestic help. A developer in Pyongyang, or a proxy in China, cannot receive a company laptop at a U.S. address, pass an employment-eligibility check with live U.S. credentials, or open an American bank account. That gap is filled by facilitators who run laptop farms: rows of company-issued machines in an ordinary home, each logged in and remotely accessible, each standing in for a remote employee who is actually overseas.

  • Host company laptops and keep them online for remote access from abroad
  • Lend or sell stolen U.S. identities for employment verification
  • Receive salaries and convert them to crypto for routing home
  • Provide access to U.S. banking and financial systems

The emblematic case is Christina Chapman of Litchfield Park, Arizona, sentenced in July 2025 to 102 months, about eight and a half years, for helping North Korean workers land remote IT jobs at more than 300 U.S. companies and generating over $17 million; she had pleaded guilty to wire fraud, money laundering, and identity theft, according to the Justice Department. Chapman was not an outlier. A June 2025 sweep under the DOJ’s DPRK RevGen: Domestic Enabler Initiative searched 29 suspected laptop farms across 16 states and seized roughly 200 computers, 21 fraudulent websites, and 29 financial accounts.

How Kraken caught one during the interview

The vector is not unstoppable, and the best counterexample doubles as a template. In May 2025, the exchange Kraken disclosed that a job applicant using the name Steven Smith had advanced deep into its hiring process before the security team recognized what they were dealing with. The resume was tied to a GitHub account whose email had turned up in an old data breach, and the applicant’s primary identification appeared altered, likely assembled from an identity stolen two years earlier. Rather than quietly reject him, Kraken advanced the candidate on purpose.

The final round was a casual chemistry interview with Chief Security Officer Nick Percoco and several colleagues, which was in fact a trap. On camera, the team asked the candidate to verify his location, hold up a government-issued ID, and recommend a few restaurants in the city where he claimed to live. The interview happened to fall on Halloween; asked what he would do when trick-or-treaters showed up at his door, he had nothing to offer. He failed every check. Percoco’s takeaway, published in Kraken’s account of the episode, was a familiar crypto maxim turned into an HR policy: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age.” He added that state-sponsored attacks “aren’t just a crypto, or U.S. corporate, issue; they’re a global threat.” Treating the interview as a control surface rather than a formality is, in effect, red-teaming applied to recruiting, the same offensive mindset HOGE Wire examined in its piece on why firms like Halborn break in before hackers do.

The deepfake escalation

The tells that caught Kraken’s applicant and Ballena Azul’s hires are exactly what the operators are now automating away. At the end of July 2026, agencies from eleven countries, led by the U.S. State Department and FBI and joined for the first time by several European governments including France, Italy, and the Netherlands, issued a joint alert warning that DPRK IT workers increasingly use real-time deepfakes during video interviews to impersonate the stolen identity on their application.

The Ballena Azul photos, processed through Google Gemini and stamped with SynthID watermarks, are the low-budget version of this. The high-budget version is a live, face-swapped candidate who holds up a convincing document and answers unscripted questions in real time. The camera-on control that worked against Steven Smith in 2025 is already degrading, which is why the joint alert stresses layered verification rather than any single check. The FBI framed the underlying problem as durable: North Korea continues to rely on a network of skilled personnel who use false identities, third-party proxies, and steadily more sophisticated methods to generate revenue for its weapons programs.

Salaries that fund missiles

What separates this from ordinary employment fraud is where the money goes. Two revenue streams flow from the same infiltration. The first is wages: the salaries, funneled through facilitators, converted to crypto, and routed home. The U.S. Treasury has estimated that the IT-worker program alone generated close to $800 million in 2024, and independent analysts put annual revenue from it in the hundreds of millions of dollars. The second is theft and extortion, the Drift-and-Munchables outcome, where privileged access is turned into a nine-figure withdrawal.

Mandiant has documented a third, uglier turn: beginning around late 2024, outed or laid-off operatives started extorting former employers, threatening to leak stolen source code or customer data unless paid. The pivot coincided with heightened law-enforcement pressure, suggesting the operators grew more aggressive as their easier revenue dried up. U.S. and allied governments are unambiguous about the destination of all of it. The proceeds, they say, ultimately fund the regime’s nuclear and ballistic-missile programs. That is why a fraudulent hire is not just a payroll problem; it is a sanctions and national-security exposure that sits on the balance sheet.

The law comes for the enablers

Because the operatives themselves sit beyond reach, U.S. enforcement has concentrated on the domestic enablers and the money. On November 14, 2025, the Justice Department announced a coordinated action that seized more than $15 million in virtual currency tied to the schemes. Assistant Attorney General for National Security John A. Eisenberg said the actions demonstrated the Department’s comprehensive approach to disrupting North Korean efforts to finance their weapons program on the backs of Americans. FBI Counterintelligence Assistant Director Roman Rozhavsky was blunter: “No matter who or where you are, if you support North Korea’s efforts to victimize U.S. businesses and citizens, the FBI will find you and bring you to justice.”

The sentencings have piled up. The July 2026 joint alert noted that eight people had already been sentenced that year for their roles, including facilitators handed terms of 108 and 92 months, and the Treasury’s sanctions office has layered on designations against individuals and entities that move the money. The exposure runs toward employers, too. A U.S. company that pays a North Korean worker, even unwittingly, may be transacting with a sanctioned jurisdiction, and OFAC sanctions are effectively strict-liability, so not knowing is not a complete defense. For public companies, an infiltration that becomes a material incident also triggers the Securities and Exchange Commission’s cybersecurity disclosure rule, adopted in July 2023, which requires reporting a material cybersecurity incident on Form 8-K within four business days. The compliance question is no longer only whether the code was audited; it is whether the company knows who it hired.

The fix: treating hiring as a security perimeter

The controls now recommended by Mandiant and adopted by exchanges reframe human resources as a security function. Pre-hire, that means biometric identity verification and notarized proof of identity before onboarding, camera-on interviews that match a live face to the document and to the profile, AI-image detection on submitted photos, and training recruiters on the specific tradecraft rather than leaving detection to instinct. In production, it means confirming that a corporate laptop’s geolocation matches the employee’s stated home, checking laptop serial numbers at onboarding, restricting remote-administration tools and IP-KVM devices, requiring hardware-based multi-factor authentication, and monitoring for mouse-jiggler software and Astrill VPN traffic.

For teams that hold keys, Drift argues for signing hygiene that assumes the signer is being manipulated: no blind pre-signing, hardware-backed keys, and clear-signing so a human can actually see what a transaction does before approving it, the kind of guardrails discussed in HOGE Wire’s coverage of smart-account wallets and the module economy. The deeper shift is cultural. The hiring funnel deserves the same adversarial testing as a smart contract. Red-team the recruiters, not just the repository.

Red flagControl
Applicant avoids camera or uses a virtual backgroundRequire live on-camera ID match and unscripted local-knowledge questions
ID, home address, and bank account in three different statesVerify consistency; require a U.S. bank account tied to the verified identity
Ship-to address differs from claimed residenceConfirm laptop geolocation matches the stated home
Requests to route pay to a processor or a different nameBlock and escalate to security
Remote-admin tool installed on day oneAlert, restrict installation, and review
Profile photo shows AI-processing artifactsRun AI-image detection before advancing the candidate

What the post-mortem actually changes

The recurring-bug problem the security desk keeps returning to applies here with a twist. This is not a defect a patch closes. As long as remote hiring exists and North Korea needs hard currency, the applicant pool will contain operatives, and every incremental defense will be met by a better deepfake or a fresh identity. The realistic goal is not elimination but friction and detection: raise the cost of each successful placement, shorten the time from onboarding to discovery, and keep dismantling the enablers who let the scheme run at scale.

Each actor in the response covers part of the ground. The DOJ can jail laptop farmers, the Treasury can sanction facilitators, and investigators like Chainalysis and ZachXBT can trace the payroll on-chain long after the fact. But the first and cheapest control sits with every hiring manager who opens a resume. In 2026, “did you verify who you hired” became a security question with a nine-figure downside, and for a painful number of protocols the honest answer, learned the hard way, was no. The value of a post-mortem is that it turns that answer into a checklist before the next team has to write its own.

Frequently Asked Questions

How do North Korean IT workers get hired at crypto companies?

They apply for remote roles using stolen or synthetic identities, often the real details of American citizens paired with AI-altered photos, and pass standard interviews, sometimes with real-time deepfakes. U.S.-based facilitators host their company laptops, lend identities, and receive their pay. Referrals between operatives are common, with one vouching for the next to skip scrutiny.

How much has North Korea made from infiltrating crypto?

Chainalysis attributes about $2.02 billion of 2025 crypto theft to North Korea, roughly 60 percent of the global total, and about $6.75 billion all-time. TRM Labs found North Korea behind about two-thirds of losses in the first half of 2026. Separately, ZachXBT traced more than $16.58 million in salary payments to DPRK developers in the first half of 2025 alone.

What was the Drift hack, and was North Korea responsible?

On April 1, 2026, attackers drained about $285 million from the Solana perpetual-futures exchange Drift. They spent roughly six months posing as a quantitative trading firm, then abused Solana’s durable nonce feature to get two of five Security Council members to blindly pre-sign transactions that handed over admin control. On-chain indicators are consistent with DPRK operations, though formal attribution remains pending.

Is it illegal for a U.S. company to accidentally hire a North Korean worker?

Paying a North Korean worker can violate U.S. sanctions even if the employer did not know, because OFAC sanctions are effectively strict-liability. Companies also risk wire-fraud and identity-theft exposure, and public companies may owe the SEC a disclosure if an infiltration becomes a material cybersecurity incident. Enforcement so far has focused on the U.S.-based facilitators who make the scheme possible.

How can a company detect a North Korean IT-worker applicant?

Warning signs include an ID, address, and bank account in different states, reluctance to appear on camera or a persistent virtual background, profile photos with AI-processing artifacts, requests to ship the laptop elsewhere or route pay to a third party, and remote-admin tools installed on day one. Effective controls include on-camera ID verification, laptop geolocation checks, hardware MFA, and restricting remote-access software.

Anneke de Vries is HOGE Wire’s security desk editor.

Share 𝕏 Post Telegram