Lazarus 2.0: How North Korea Infiltrates DeFi from the Inside

📋 En bref (TL;DR)

  • North Korea’s Lazarus Group has infiltrated over 40 DeFi platforms since 2020, with developers posing as Western freelancers. ZachXBT identified 21 North Korean developers earning $300,000-$500,000 per month. The Stabble DEX discovered its former CTO was a Pyongyang agent. In total, North Korea has stolen $6.75 billion in cryptocurrency, including $285 million through the Drift hack in 2025.

Lazarus Group: from hackers to infiltrated DeFi developers

The Lazarus Group, a cyber warfare unit under North Korea’s Reconnaissance General Bureau, has undergone a profound evolution. Long confined to frontal attacks — exchange hacks, targeted phishing, vulnerability exploits — the group made a strategic shift since DeFi Summer 2020: human infiltration of blockchain projects.

According to blockchain investigator ZachXBT, at least 21 North Korean developers currently operate under false identities within the crypto ecosystem. These agents present themselves as Western freelancers on platforms like GitHub, Discord, and LinkedIn, apply for developer positions, and gradually integrate into DeFi protocol technical teams.

Taylor Monahan, security researcher at MetaMask, estimates that over 40 DeFi platforms have been infiltrated by North Korean agents since 2020, a figure far exceeding initial FBI estimates.

21 North Korean developers unmasked: the ZachXBT investigation

In March 2026, on-chain investigator ZachXBT published the results of a months-long investigation revealing a structured network of 21 developers linked to Kim Jong-un’s regime. These individuals worked simultaneously for multiple crypto projects, using fabricated identities with AI-generated photos and falsified resumes.

Each developer generated between $300,000 and $500,000 in monthly revenue, largely funneled to North Korea’s nuclear weapons program. The FBI and CISA (Cybersecurity and Infrastructure Security Agency) confirmed this network’s existence, estimating that 3,000 to 7,000 North Korean IT workers operate worldwide, with a significant portion in the crypto sector.

The modus operandi is well-rehearsed: infiltrated developers gradually gain access to private keys, governance systems, and critical smart contracts. Once in position, they can either directly exfiltrate funds or install backdoors for later exploitation by Lazarus hackers.

Stabble: when a DEX’s CTO is a Pyongyang agent

The most spectacular case of 2026 involves Stabble, a decentralized exchange (DEX) on Solana. The team discovered that its former Chief Technology Officer (CTO) was actually a North Korean agent operating under a false identity. The individual had access to the protocol’s smart contracts, admin keys, and complete source code for several months.

Stabble published a detailed post-mortem revealing the ignored red flags: refusal to join video calls, offset working hours, use of multiple VPNs, and reluctance to provide identity documents. This case illustrates the structural vulnerability of DeFi projects, often managed by small distributed teams that recruit without thorough identity verification.

$6.75 billion stolen: North Korean cyberattacks by the numbers

North Korea’s cyber theft program now totals an estimated $6.75 billion stolen across all targets (crypto, banks, corporations). In crypto alone, major attacks include:

The Ronin Network hack (Axie Infinity) in 2022 for $620 million, the Harmony Bridge breach for $100 million, and more recently the Drift Protocol hack in 2025 for $285 million. Each time, funds are laundered through mixers like Tornado Cash — which Lazarus modified over 250 times according to US Department of Justice documents — then converted to fiat currencies through financial mule networks in Southeast Asia.

The US Treasury Department estimates that North Korea’s cyber program funds approximately 40% of the country’s ballistic missile program, making crypto a direct national security concern.

How North Korea launders stolen cryptocurrency

Lazarus’ laundering process follows a pattern now well documented by law enforcement. Stolen funds are first sent to hundreds of intermediary wallets via automated transactions. They then pass through mixers (primarily Tornado Cash, with custom modifications to evade sanctions) before being converted to Bitcoin.

The Bitcoin is then routed to OTC (over-the-counter) brokers in China and Southeast Asia, who convert it to yuan or dollars. Operation Nisos, conducted by a cybersecurity firm of the same name, managed to trap several of these intermediaries by creating fake crypto recruiter profiles to identify North Korean agents.

Despite these efforts, authorities estimate recovering only 5-10% of stolen funds, with the remainder successfully laundered within 48-72 hours of each attack.

How to protect yourself against North Korean infiltrations

The FBI and CISA have published joint alerts detailing protection measures for crypto projects and investors. For DeFi protocols, recommendations include: thorough identity verification (developer KYC) for any contributor with access to critical code, multi-signature wallets for treasury management, and regular source code security audits.

For individual investors, the direct risk is limited but real: an infiltrated protocol can lose all user funds. It’s recommended to favor protocols audited by recognized firms (Certik, Trail of Bits, OpenZeppelin), diversify DeFi positions, and verify that project teams are publicly identified (doxxed).

Glossary
Lazarus Group: a cyber warfare unit under North Korea’s Reconnaissance General Bureau, responsible for billions of dollars in crypto thefts.
DeFi (Decentralized Finance): an ecosystem of financial services built on blockchains, without centralized intermediaries (banks, brokers).
DEX (Decentralized Exchange): a decentralized trading platform that allows exchanging cryptocurrencies without a trusted third party.
Tornado Cash: a mixing protocol on Ethereum that anonymizes transactions by breaking the link between source and destination addresses.
Multisignature (multisig): a security mechanism requiring multiple signatures (private keys) to authorize a transaction, reducing theft risk.
On-chain: refers to analysis or data directly from the blockchain, verifiable by all and immutable.
Smart contract: a self-executing computer program deployed on a blockchain that automatically executes agreement terms.

Frequently Asked Questions

How much cryptocurrency has North Korea stolen?

North Korea’s cyber theft program has stolen an estimated $6.75 billion total, including major attacks like Ronin Network ($620M), Drift ($285M), and Harmony Bridge ($100M). These funds reportedly finance about 40% of the country’s ballistic missile program.

How does Lazarus infiltrate DeFi projects?

North Korean agents pose as Western freelance developers with fake identities (AI-generated photos, falsified resumes). They apply on GitHub and Discord, join technical teams, then gradually gain access to private keys and critical smart contracts to exfiltrate funds.

How can you tell if a DeFi project has been infiltrated?

Red flags include: developers refusing video calls, offset working hours, use of multiple VPNs, and reluctance to provide identity documents. Favor protocols whose teams are publicly identified and audited by recognized firms (Certik, Trail of Bits).

Are crypto investors at risk from Lazarus hacks?

Yes, indirectly. If you deposit funds on an infiltrated DeFi protocol, you risk losing your entire investment. It’s recommended to diversify positions, use audited protocols, and never concentrate all funds on a single protocol.

What are authorities doing to counter North Korean hackers?

The FBI, CISA, and US Treasury have published joint alerts and sanctioned Tornado Cash. Operation Nisos trapped intermediaries. However, authorities estimate recovering only 5-10% of stolen funds, with the rest laundered within 48-72 hours.

The simplest way to buy, swap and manage your crypto

Join the first users and get priority access. No seed phrase, fees 3.5x lower, built-in DeFi yield.

Get early access →