North Korean IT Workers Exposed After Researchers Build Fake DeFi Startup

Getting your Trinity Audio player ready...
  • Researchers created a fake DeFi startup to monitor suspected North Korean IT workers after hiring them.
  • The investigation uncovered forged US credentials, financial accounts, VPN infrastructure and cryptocurrency wallets.
  • AI tools were reportedly used for coding and translation, highlighting new challenges for crypto companies hiring remotely.

Threat intelligence researchers turned the tables on a suspected North Korean cyber operation by creating a fake DeFi company and hiring the operatives they believed were part of a wider IT-worker network. Instead of trying to detect suspicious employees after they entered a real company, the researchers built a controlled environment and watched the recruits operate from inside.

The investigation, involving BCA LTD’s Mauro Eldritch, NorthScan’s Heiner García and ANY.RUN, highlights how remote hiring has become a growing security concern for crypto companies. The case also shows how forged identities, AI tools and cryptocurrency infrastructure can combine to support sophisticated infiltration campaigns.

Fake DeFi Company Becomes Controlled Experiment

Researchers created Ballena Azul LTD, presenting it as a cryptocurrency protocol serving large crypto holders. They established a website, corporate branding and a matching UK registration to make the company appear credible.

After recruiting a developer through GitHub, the researchers saw a referral chain develop. The first worker recommended another developer, who subsequently brought in a third. All three passed interviews before receiving access to virtual desktops operated as monitored environments through ANY.RUN.

The workers were identified in the report as suspected members of Famous Chollima, a group associated with North Korea’s Lazarus-linked operations.

Forged Identities and Financial Accounts Surface

The investigation uncovered several indicators that raised concerns during onboarding. The suspected workers supplied what researchers described as fraudulent US identification documents, including driver’s licenses and stolen Social Security numbers.

Financial accounts connected to Lead Bank, Citibank and Wise were also identified. One driver’s license contained metadata suggesting it had been processed using Google Gemini and included a SynthID watermark, providing researchers with an additional clue that the document was fabricated.

The researchers also traced VPN infrastructure and servers associated with providers including AstrillVPN, Vultr and Gorilla Servers. Cryptocurrency wallets linked to the investigation contained transaction histories that provided further visibility into the network.

AI Adds Another Layer to the Hiring Threat

Artificial intelligence was another notable element of the operation. Researchers said the developers used ChatGPT to assist with programming tasks they appeared unable to complete independently. Translation software was also used during interviews and workplace meetings.

The findings matter because a successful infiltration can give an operative legitimate access rather than requiring an immediate technical breach. That access could expose source code, internal systems, intellectual property and established business processes.

North Korean cyber groups have already been heavily linked to cryptocurrency theft. According to the supplied research, DPRK-linked crews accounted for 76% of crypto hacking losses through April 2026, while theft attributed to North Korean actors reached $2 billion in 2025.

The investigation therefore points to a broader challenge for crypto firms: cybersecurity defenses may need to begin before an employee receives system access. Robust identity checks, credential verification and monitoring of remote work environments could become increasingly important as North Korean IT-worker campaigns evolve.

Also Read: Solana Hits 171M Transactions as MoneyGram, USDT and DeFi Momentum Accelerate

The fake DeFi startup experiment demonstrates how difficult these campaigns can be to identify through conventional hiring processes alone. By combining fraudulent identities, financial accounts, AI assistance and established infrastructure, suspected North Korean IT workers can potentially enter organizations through legitimate channels rather than forced entry.

Disclaimer: The information in this article is for general purposes only and does not constitute financial advice. The author’s views are personal and may not reflect the views of Chain Affairs. Before making any investment decisions, you should always conduct your own research. Chain Affairs is not responsible for any financial losses.

Andrew Chen

I'm a crypto enthusiast with a background in finance. I'm fascinated by the potential of crypto to disrupt traditional financial systems. I'm always on the lookout for new and innovative projects in the space. I believe that crypto has the potential to create a more equitable and inclusive financial system.

More From Author

VIRTUAL Price Surges 10% as Volume Explodes 180%: Is $0.68 Next?

ChainAffairs

We deliver the latest cryptocurrency news, analysis, and insights — helping investors stay ahead in the fast-moving digital asset markets.

Quick Links

Your ad here.

Put your brand in front of web3 decisions. Advertise here.
Lets Get Started