A CoinDesk investigation found that more than a dozen blockchain and crypto firms — including exchanges, infrastructure providers and DeFi projects — have unknowingly hired North Korean IT workers who concealed their identities to access codebases, backend systems and corporate networks. According to the report, these workers operated as remote engineers or contractors using forged identities, proxy “mules” and third‑party staffing platforms, in some cases handling critical roles like smart contract development and infrastructure maintenance. CoinDesk’s findings align with warnings from U.S. law enforcement and cybersecurity researchers that North Korea has built a large, organized remote‑work operation where IT workers abroad generate hard‑currency revenue and technical access for the regime. U.S. and U.N. authorities say these activities violate sanctions and can help fund North Korea’s weapons and nuclear programs, while also creating serious cybersecurity risks, including theft of crypto assets, insertion of backdoors, and misuse of insider access. The case highlights how standard remote‑hiring practices, lax vendor oversight, and pseudonymous work in Web3 have allowed sanctioned actors to blend in as high‑skilled developers, prompting calls for stricter KYC for employees and contractors, deeper background checks on remote engineers, and closer attention to OFAC and U.N. sanctions exposure for crypto firms.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on North Korea

Comments