North Korea has infiltrated up to 20% of crypto firms, security expert says
Up to one-fifth of all crypto companies may have North Korean workers embedded in their operations, a security expert warned at Devconnect in Buenos Aires.
- Up to 20% of crypto companies may unknowingly have North Korean workers embedded.
- An estimated 30–40% of crypto job applicants are DPRK attempts to infiltrate firms.
- North Korea has stolen over $3B in crypto in three years, funding nuclear programs.
Pablo Sabbatella, who founded web3 audit firm Opsek and serves as a Security Alliance member, shared estimates that suggest the problem extends far beyond isolated incidents.
Job applications flooding into crypto firms show an even more troubling picture. Sabbatella estimates that roughly 30% to 40% of applicants are North Korean attempts at gaining employment.
Sanctions evasion through identity theft schemes
International sanctions prevent North Koreans from applying for jobs under their real identities. The workaround involves recruiting people in other countries to serve as fake employees.
Freelance platforms like Upwork and Freelancer have become hunting grounds for these recruiters, who target workers in Ukraine, the Philippines, and similar nations.
The arrangement splits earnings 80-20, with the North Korean agent taking the larger share. Collaborators provide verified credentials or allow remote use of their identity.
U.S. companies face particular targeting. North Korean agents claim to be non-English speaking Chinese applicants who need interview assistance.
The “front person” gets their computer infected with malware during this process and grants the agent access to American IP addresses and overall internet access than North Korea allows.
Companies often retain these workers long-term. “They work well, they work a lot, and they never complain,” Sabbatella told local news. Performance keeps suspicions low while access to sensitive systems grows.
Weak security practices enable massive theft operations
Pyongyang’s cyber operations have netted over $3 billion in stolen cryptocurrency across three years, according to U.S. Treasury Department figures from November.
The stolen funds flow directly into North Korea’s nuclear weapons development programs.
Sabbatella placed blame squarely on industry practices. Crypto companies show weaker operational security than any other computing sector, he argued.
Founders publicly reveal their identities, mishandle private keys, and succumb to manipulation tactics.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Assessing KITE’s Price Prospects After Listing as Institutional Interest Rises
- Kite Realty Group (KRG) reported Q3 2025 earnings below forecasts but raised 2025 guidance, citing 5.2% ABR growth and 1.2M sq ft lease additions. - Institutional investors showed mixed activity, with Land & Buildings liquidating a 3.6% stake while others increased holdings, reflecting valuation debates. - Technical indicators suggest bullish momentum (price above 50/200-day averages) but a 23.1% undervaluation vs. 35.1x P/E, exceeding sector averages. - KRG lags peers like Simon Property in dividend yie

Evaluating How the MMT Token TGE Influences Crypto Ecosystems in Developing Markets
- MMT's volatile TGE highlights tokenized assets' dual role as liquidity engines and speculative risks in emerging markets. - Institutional investors allocate up to 5.6% of portfolios to tokenized assets, prioritizing real-world integration and cross-chain utility. - Regulatory fragmentation and smart contract risks demand CORM frameworks to mitigate operational vulnerabilities in DeFi projects. - MMT's deflationary model and institutional backing face macroeconomic challenges, requiring hedging against gl

Trust Wallet Token's Latest Rally and Growing Institutional Interest: Driving Sustainable Value
- Trust Wallet Token (TWT) surged in 2025 due to institutional partnerships, utility upgrades, and real-world asset (RWA) integrations. - Collaborations with Ondo Finance (tokenizing $24B in U.S. Treasury bonds) and Onramper (210M+ global users) expanded TWT's institutional-grade utility. - Governance upgrades, FlexGas payments, and Binance co-founder CZ's endorsement boosted TWT's credibility and institutional appeal. - Analysts project TWT could reach $5.13 by year-end, driven by cross-chain integrations

Clean Energy Market Fluidity and the Emergence of REsurety's CleanTrade Solution
- CFTC's 2025 approval of REsurety's CleanTrade as a SEF marks a regulatory breakthrough for clean energy trading infrastructure. - The platform addresses $16B+ in pent-up demand by providing liquidity, transparency, and institutional-grade safeguards for VPPAs, PPAs, and RECs. - CleanTrade's integration of carbon tracking analytics and ESG alignment tools enables institutional investors to quantify environmental impact alongside financial returns. - By resolving counterparty risks and enabling cross-asset

