Fake DeFi Startup Exposes North Korean IT Workers: A New Tactic in Cybersecurity

In a bold cybersecurity experiment, researchers built a fake DeFi startup to hire and monitor North Korean IT workers from within. This inside-out approach uncovered significant security risks to the crypto industry.
Could the crypto industry's greatest threat come not from outside hackers, but from those hired to work within? This intriguing question is at the heart of a recent cybersecurity operation where threat intelligence experts turned the tables on North Korean IT workers by creating a fake DeFi startup to monitor them from the inside.
The Raw Data
The operation involved the creation of a fictitious company known as Ballena Azul LTD, built to serve cryptocurrency whales. Through a detailed façade complete with a website, corporate branding, and UK company registration, researchers Mauro Eldritch, Heiner García, and ANY.RUN set up a convincing front. The hired IT workers, suspected members of North Korea's notorious Lazarus Group, submitted fraudulent US credentials including driver's licenses and stolen Social Security numbers. These operatives were granted access to virtual desktops that served as controlled recording environments.
Context: A Dangerous Precedent
Why does this matter? North Korean hacking units, such as the Lazarus Group, have long been associated with crypto theft. In 2025 alone, their activities contributed to $2 billion in losses. The infiltration tactic employed by these workers presents a new dimension of risk. By posing as engineers and securing remote jobs within crypto firms, these operatives have the potential to gain legitimate access to sensitive systems and data. Once inside, they're not just a threat to intellectual property but to the very core of a company’s security infrastructure.
Insider Perspectives
Traders and security experts are closely watching these developments. According to the report, the tactics used by North Korean IT workers highlight vulnerabilities in global hiring practices. With 100 suspected operatives identified in 53 crypto projects, the threat is staggering. A key question emerges: How can crypto companies protect themselves from such sophisticated infiltration? The need for strong verification processes and heightened security protocols is more urgent than ever.
What's Next?
So, where do we go from here? The need for stringent verification processes isn't just a recommendation. it's a necessity. Companies will need to invest in advanced technologies to detect forged documents and increase their awareness of potential infiltration tactics. We can expect increased scrutiny from regulatory bodies and possibly an uptick in guidance issued by cybersecurity agencies. The crypto industry's response will likely include a blend of technology-driven solutions and strategic policy shifts. The passporting question is where this gets interesting. As global hiring transcends borders, ensuring security without stifling growth is a balancing act that crypto firms must master.