Expert Says North Korean IT Workers Helped Build Top Protocols During DeFi Summer
North Korean-linked IT workers have been embedded within major DeFi protocols since 2020, contributing genuine technical work to projects including SushiSwap, THORChain, Yearn, and Harmony while positioning themselves for later exploitation, according to cybersecurity researcher Taylor Monahan. The discovery carries acute risk for institutional investors whose custody, exchange, and protocol exposures may harbour state-backed operatives with multi-year access to critical systems.
- North Korean IT workers contributed real technical expertise to six major DeFi protocols during 2020’s DeFi summer boom, per Monahan’s analysis of developer resumes.
- State-backed actors extracted an estimated $6.7 billion from crypto during the infiltration period, with 2025 alone seeing $2.02 billion stolen, a 51% year-on-year increase.
- Tactics have evolved to use non-North Korean proxies for in-person interactions and social engineering, making attribution and vetting substantially harder for institutional onboarders.
- $2.02B stolen by DPRK hackers in 2025, up 51% versus 2024
- 76% of all service-related breaches in 2025 attributed to state-backed actors
- $6.7B estimated total extraction across entire DeFi infiltration period
Cybersecurity researcher Taylor Monahan has revealed that North Korean-linked information technology workers have operated inside the decentralized finance sector for years, contributing legitimate technical work to well-known protocols before positioning themselves for coordinated asset theft.
The infiltration strategy, detailed in recent public analysis, represents a departure from conventional hacking and points to a sustained, patient campaign of institutional capture spanning the 2020 DeFi boom and continuing into 2025.
When pressed for specifics, Monahan identified SushiSwap, THORChain, Yearn, Harmony, Ankr, and Shiba Inu as projects touched by these actors, a roster that underscores how deeply the operation penetrated the ecosystem’s infrastructure layer.
Monahan Confirms Genuine Code Contributions Across Six Major Protocols
The most significant finding is that North Korean operatives did not pose as developers with fabricated credentials. Instead, their resume histories of blockchain development experience were authentic, reflecting real and sometimes substantial technical contributions to protocol codebases.
This approach gave the actors legitimacy within teams and access to sensitive systems, repositories, deployment keys, operational infrastructure, that would normally require earned trust.
Monahan’s research identified a spectrum of security postures among affected projects. Yearn Finance emerged as an outlier, maintaining strict peer-review processes, high skepticism toward new contributors, and security-first operational discipline that limited exposure compared to peers.
Other projects, by implication, operated with looser vetting and faster contributor onboarding, creating surface area for insertion. The distinction matters for institutional investors assessing counterparty risk: protocols that resisted rapid scaling and maintained bottlenecks at code review phase faced lower infiltration depth.
The scale of extraction during the infiltration window, estimated at $6.7 billion collectively, suggests these were not isolated incidents of individual developer malfeasance but a coordinated campaign. State-backed actors positioned themselves within projects, earned trust, gained access to keys or deployment authority, and then executed timed exploits.
The patient accumulation of credentials and relationships mirrors tradecraft used in nation-state cyber operations against financial institutions.
2025 Breaches Show 51% Acceleration in Stolen Assets and Proxy Tactics
The infiltration has accelerated sharply in 2025. According to Chainalysis data, North Korean-linked hackers stole at least $2.02 billion in digital assets in 2025 alone, representing a 51% increase from 2024 and accounting for 76% of all service-related breaches in the sector.
Notably, the number of attacks declined even as the scale grew, indicating fewer but larger, more targeted operations, the hallmark of an operation that has refined targeting and maximized per-breach payoff.
Chainalysis attributed this scale to the state-backed groups’ systematic use of infiltrated IT workers embedded within crypto exchanges, custodians, and infrastructure providers. Once inside, operatives gain access before major exploits occur, positioning them to unlock wallets, drain accounts, or disable monitoring.
After theft, the actors typically move assets in tranches under $500,000 to avoid triggering automated threshold alerts, with more than 60% of transfers staying below that amount. This disciplined money movement contrasts with opportunistic hacking and again signals institutional planning.
Monahan’s latest intelligence indicates that tactics have evolved beyond the initial embedded-worker model. Operatives are now using non-North Korean individuals to carry out portions of operations, including in-person interactions with targets.
This layering obscures attribution and makes conventional due diligence, which often relies on detecting geographic inconsistencies or communication patterns, far less reliable. An employee meeting a new contractor in a coffee shop may have no way to verify whether that contractor is a legitimate hire or an infiltrator working on behalf of a state actor.
Fake Video Calls and Telegram Compromise Chains Enable Malware Deployment
The mechanics of initial compromise have been documented by the Security Alliance (SEAL) and point to social engineering that preys on institutional trust structures. Attackers compromise Telegram accounts of known contacts, often current or former employees, and use those hijacked accounts to invite targets to video calls.
The attacker then plays a pre-recorded video designed to appear legitimate before instructing the victim to install a supposed security update.
The “update” is malware that grants the attacker remote access to the target’s device. Once installed, the malware harvests credentials, session tokens, and sensitive files. The attacker then reuses the compromised device to propagate further into the organization, moving laterally through network trust relationships.
This attack chain bypasses perimeter defenses because it originates from inside trusted communication channels and relies on social proof rather than technical exploits.
In March 2025, North Korean-linked hackers were suspected of executing a similar chain against Bitrefill, a major cryptocurrency payment processor. Attackers gained entry through a compromised employee device and extracted credentials that would permit deeper system access. The incident is not isolated; it reflects an operational pattern now understood to be systematic across the sector.
Post-Theft Movement Uses Cross-Chain Bridges and Chinese Financial Networks
Once assets are stolen, the operatives employ a layered laundering strategy designed to obscure the fund trail. Stolen crypto is moved across blockchains using cross-chain bridges, mixed through centralized and decentralized mixing services, and ultimately converted to fiat through Chinese-language financial networks that operate with fewer regulatory compliance barriers than Western exchanges.
This multi-hop approach is time-consuming but effective at breaking on-chain traceability.
The use of Chinese financial networks is notable because it suggests logistical support from within China or from diaspora networks with ties to Chinese financial infrastructure. It also indicates that the operation has solved the “last mile” problem of converting seized crypto to spendable fiat, a known chokepoint for cybercriminals operating from isolated jurisdictions.
The integration with Chinese financial channels suggests either tacit tolerance from Beijing or active operational collaboration.
For institutional investors, this money movement pattern has a direct implication: even if a hack is detected and the stolen address is identified, the probability of asset recovery declines sharply once the funds enter cross-chain bridge protocols and Chinese financial networks. Traditional law enforcement tools have limited reach into those jurisdictions.
Preventive security, vetting, monitoring, access controls, becomes the only reliable line of defense.
Institutional Crypto Investors Face Cascading Exposure Across Custodians and Protocols
The scope of infiltration creates a cascading risk for institutions that hold digital assets. If North Korean operatives maintain persistent access within custodians, exchanges, or protocol infrastructure, then the timing and targeting of exploits may be adversarial, designed to strike when an institution holds large balances or when market conditions maximize the value of stolen assets.
An institution cannot reliably know whether its custodian, exchange counterparty, or protocol dependencies harbor embedded operatives.
This risk is heightened for institutions that were early adopters of DeFi, including those that deployed