Skip to main content

Ethereum Targets North Korea’s Secret Workforce — Are Your Favorite DeFi Protocols Compromised?

The Ethereum Foundation exposed 100 Democratic People’s Republic of Korea (DPRK)‑linked IT workers embedded across roughly 53 crypto projects.

Ethereum Foundation Levels Up Its Security With A Detective Program

The North Korean secret crypto-agents don’t rest, so the Ethereum Foundation decided it was time they put on the detective’s hat to track them before they too fell victims to them, just as Drift Protocol was at the beginning of the month. And so, yesterday afternoon the Foundation announced on an official blog post the starking results yielded by the ETH Rangers Program (and yes, everything related to North Korean hackers inevitably sounds straight out of an RPG or action movie).

According to the blog post, the Ethereum Foundation teamed up with Secureum, The Red Guild, and Security Alliance (SEAL) in late 2024 to roll out said program. The initiative offered stipends to people carrying out public‑goods security work across the Ethereum ecosystem.

Related Reading: Blockchain Is South Korea’s New Fiscal Weapon — A Blow To Privacy?

The program’s mission consisted in backing independent security initiatives that strengthen Ethereum’s overall robustness, while spotlighting and rewarding contributors with a proven history of delivering high‑impact security work for the broader network.

After six months, the results of the program speak for itself.

The DPRK Crypto-Infiltration Saga, Parth Who-Is-Even-Counting-At-This-Point

The ETH Rangers Program funded multiple crypto-security projects, but the Ketman Project was the one “focused on discovering and expelling North Korean (DPRK) IT workers who have infiltrated blockchain projects under fake identities”, per the blog post.

Over the six months of the investigation, they contacted roughly 53 different projects and uncovered around 100 DPRK IT operatives embedded inside Web3 organizations.

Their findings were shared in a series of detailed reports on ketman.org, which drew more than 3,300 active users and 6,200 page views, and explored themes such as account‑takeover techniques, the infiltration of freelance platforms, and emerging DPRK‑Russia ties. They also built and open‑sourced gh‑fake‑analyzer, a GitHub profile analysis tool designed to flag suspicious activity patterns, which is now available via PyPI.

In addition, they co‑authored the DPRK IT Workers Framework with SEAL, a document that has quickly become a go‑to reference for the industry, and supplied crucial data to the Lazarus.group threat‑intel project, with their work highlighted in a presentation at DEF CON.

Overall Results Of The Ethereum Program

The work produced by the 17 stipend recipients cover everything from vulnerability research and security tooling to education, threat intelligence, and hands‑on incident response.

According to the Ethereum Foundation, more than $5.8 million in funds have been recovered or frozen, while over 785 vulnerabilities, client bugs, and proof‑of‑concept exploits have been reported or documented. The Program has also helped identify around 100 DPRK state‑sponsored operatives embedded across multiple teams, and its threat‑intelligence and investigative content has reached over 209,000 viewers and users.

On the builder side, more than 800 teams have taken part in sponsored security challenges and investigations, supported by over 80 workshops, talks, and technical or educational resources. The initiative has coordinated responses to more than 36 security incidents and driven the creation or improvement of at least seven open‑source tooling repositories, frameworks, and implementations that further harden the ecosystem.

The Saga Continues

The DPRK-linked hacks continue to be a serious issue amongst the crypto community. Recently, key actors have been less lenient and more active in trying to uncover and stop their threat.

Let’s remember that, following the  the attribution of the April 1st $285 million attack on Drift Protocol to UNC4736, a North Korea–aligned, state‑sponsored hacking group, crypto detective ZachXBT uncovered an internal North Korean payment server tied to 390+ accounts, chat logs, and transaction histories.

A few weeks ago, some crypto builders confessed on the social network X that they are passing tests during interviews to developers to make sure they are not North Korean agents.

Investing in visible, transparent security collaborations (like EF’s backing of ETH Rangers/Ketman/SEAL) may deserve a premium in risk models, while protocols with opaque teams and loose hiring are increasingly “headline risk” candidates.

Ethereum, ETH, ETHUSD

Cover image from Perplexity. ETHUSD chart from Tradingview.



from Bitcoinist.com https://ift.tt/AKOuZem

Comments

Popular posts from this blog

Bitcoin Goes Official: Texas Becomes 1st US State With BTC Reserve

Everything is big in Texas, many would say. Today, the state is looking past its current state of finances by adding Bitcoin to its coffers–and making things bigger in terms of its economic implications. Texas became the first US state to establish a crypto reserve . On March 7, 2025, legislators passed Senate Bill 21, which gives the green light to the state to direct public funds toward Bitcoin and other digital assets. The action has elicited both support and concern, with some viewing it as a prudent financial hedge and others warning of potential pitfalls. A Push For Bitcoin In The Lone Star State For months, Texas has been seeing increasing favor for the idea of a Bitcoin reserve. Senator Charles Schwertner introduced SB 778, a measure that proposes establishing a strategic stockpile. Including the top crypto asset into the state’s financial reserves was meant to help cushion inflation and economic uncertainty. Texas officials, especially Lieutenant Governor Dan Patrick, wh...

Liczba milionerów kryptowalutowych wzrosła o 40%. Rynek przekracza 3,3 biliona dolarów

Rozwój rynku kryptowalut widać również bo liczbie osób, których portfel kryptowalutowy przekroczył milion dolarów. Według najnowszego raportu Henley & Partners, liczba inwestorów posiadających majątek przekraczający milion dolarów w cyfrowych aktywach wzrosła o 40% w ciągu ostatniego roku. Aktualnie na świecie jest już 241 700 milionerów, jeśli chodzi o waluty cyfrowe. Wzrost ten zbiegł się z historycznym momentem, gdyż w połowie 2025 roku kapitalizacja całego rynku kryptowalut przekroczyła 3,3 biliona dolarów . Bitcoin wciąż liderem wzrostów Największy udział w tworzeniu nowych fortun ma niezmiennie Bitcoin. Liczba posiadaczy portfeli BTC, których wartość przekracza milion dolarów, wzrosła aż o 70% rok do roku i wynosi dziś 145 100 . Jeszcze bardziej imponująco wygląda grupa tzw. Centymilionerów, czyli inwestorów posiadających ponad 100 milionów dolarów w Bitcoinie. Ich liczba wzrosła o 63% , osiągając poziom 254 osób. Co więcej, liczba miliarderów BTC podskoczyła do 17, notu...

Slow And Steady Wins? Bitcoin To Hit $1M Via ‘Pump’ And ‘Consolidate’ Pattern: Expert

The bull cycle was deemed over when the price of Bitcoin tragically fell toward $75,000 earlier in March 2025. Having notched an all-time high of above $100,000, most investors feared that the premier cryptocurrency had already reached its top for the current cycle. Contrary to popular belief, the price of Bitcoin has since forged multiple new all-time highs, with the current record high at around $122,800. Interestingly, the now-popular market consensus is that it is only a matter of time before the BTC price reaches a seven-figure valuation. How Will Bitcoin Hit $1 Million In 10 Years? In a recent post on the X platform, Blockware Bitcoin analyst Mitchell Askew has joined a growing list of experts to put forward a $1 million projection for the premier cryptocurrency. According to the analyst, the price of BTC is expected to achieve this major milestone over the next 10 years. What’s interesting is that Askew expects the Bitcoin price to reach a $1 million valuation in the next ...