Close Menu
    Facebook X (Twitter) Instagram
    Cloud Tech ReportCloud Tech Report
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Cloud Tech ReportCloud Tech Report
    Home»Crypto News»Ethereum»Ethereum Foundation Exposes 100 North Korean Operatives Infiltrating Crypto Companies
    Ethereum

    Ethereum Foundation Exposes 100 North Korean Operatives Infiltrating Crypto Companies

    April 17, 2026
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Ethereum Foundation Exposes 100 North Korean Operatives Infiltrating Crypto Companies
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email
    murf


    Key Takeaways

    • Six-month investigation identifies 100 North Korean agents working in cryptocurrency companies
    • Ethereum Foundation-backed research exposes covert developer network across blockchain industry
    • DPRK-linked infiltrators discovered operating under false identities in Web3 development teams
    • Blockchain organizations confronting heightened security threats from state-sponsored operatives
    • Investigation uncovers systematic, long-term North Korean presence throughout crypto sector

    A comprehensive security investigation supported by the Ethereum Foundation has uncovered a significant breach involving covert agents embedded within Web3 organizations. The extensive six-month research operation successfully identified 100 individuals with connections to North Korea working inside cryptocurrency development teams. These revelations underscore an escalating operational security challenge throughout the Ethereum network.

    Systematic Research Uncovers Widespread Web3 Infiltration Network

    The Ethereum Foundation supported this comprehensive security assessment through its ETH Rangers program, which began operations in late 2024. This initiative provided funding for independent security researchers dedicated to enhancing ecosystem protection through focused public infrastructure projects. Consequently, one recipient established the Ketman Project specifically to monitor questionable developer behavior patterns.

    The Ketman Project concentrated its efforts on uncovering fraudulent developers embedded in Web3 companies who utilize multiple layered false identities. Throughout the six-month investigation period, researchers successfully identified 100 individuals connected to North Korea currently working within cryptocurrency organizations. The investigation team reached out to 53 different blockchain projects that potentially hired these concealed operatives without awareness.

    The foundation validated that these discoveries reveal a substantial operational security vulnerability impacting Ethereum-based development infrastructure. Researchers developed an open-source detection platform designed to identify suspicious patterns in GitHub contributor activity. This program represents expanded commitments toward reinforcing security measures across the broader ecosystem.

    coinbase

    Extended North Korean Operations Connected to Massive Cryptocurrency Thefts

    Investigative evidence demonstrates that developers linked to North Korea have maintained active roles within cryptocurrency development teams spanning multiple years. These operatives participated in project development while concealing their true identities behind credible technical contributions. Security analysts connected numerous operations to the Lazarus Group, a state-sponsored cybercrime organization.

    Industry reports calculate that North Korean-affiliated entities have successfully stolen approximately $7 billion from cryptocurrency platforms beginning in 2017. These criminal activities encompass significant security breaches including the Ronin Bridge compromise and the WazirX security incident. The magnitude of financial damage demonstrates coordinated and continuous cyber warfare operations.

    Cybersecurity experts observed that these embedded developers frequently demonstrate legitimate blockchain development expertise despite operating under fabricated identities. Numerous decentralized finance protocols throughout the ecosystem have historically depended on such contributors. This infiltration problem extends well beyond individual isolated incidents into fundamental infrastructure vulnerability.

    Straightforward Deception Methods Enable Long-Term Successful Infiltration

    Researchers discovered that numerous infiltration strategies depend on uncomplicated yet highly effective deception techniques. These approaches include standard job applications, professional LinkedIn networking, and remote interview processes designed to establish credibility within development teams. Through these methods, operatives successfully integrate themselves into standard development operations.

    The Ketman Project documented recurring red flags evident across developer accounts and system interactions. These warning indicators include recycled profile images, contradictory language configuration settings, and inadvertent exposure of unrelated email accounts. Discrepancies frequently emerge during screen-sharing sessions or when examining code repository activity histories.

    The research initiative partnered with the Security Alliance to establish a comprehensive framework for detecting suspicious developer participants. This collaborative effort enhanced threat detection capabilities through coordinated intelligence sharing throughout the cryptocurrency industry. Blockchain organizations now possess improved resources to minimize vulnerability to concealed security threats.



    Source link

    livechat
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    These Data Points Suggest Ether Price Could Soon Rally to $3K

    May 1, 2026

    Ethereum Pulls $1B in Buy Volume on Binance as ETH Drops Below $2,300 Amid Fed Rate Hold

    April 30, 2026

    Stablecoin Transfer Volume Drops 19% as Supply Rises

    April 29, 2026

    Ethereum Bullish Divergence Signals Strong Buyer Demand as ETH Holds Near $2,300

    April 28, 2026

    BitMine Expands ETH Holdings Despite $6.5B in Unrealized Losses

    April 27, 2026

    Ethereum Foundation Unstakes $48.9M in ETH Through Lido Finance

    April 26, 2026
    kraken
    Latest Posts

    Salesforce launches Agentforce Operations to fix the workflows breaking enterprise AI

    May 1, 2026

    Cybersecurity is DEAD? I built an AI Hacker to find out…

    May 1, 2026

    DeFi’s Lose-Lose Problem on Freezing Stolen Funds

    May 1, 2026

    Analyst Calls it a Buy Setup

    May 1, 2026

    Shinhan Card Partners with Solana for Stablecoin Payments, DeFi Infrastructure

    May 1, 2026
    murf
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    Crypto VC Funding Plunges to $659M in April, Hits 2024 Lows

    May 2, 2026

    XRP’s Sentiment Turns Bullish, But What Is Stopping a Price Breakout?

    May 1, 2026
    murf
    Facebook X (Twitter) Instagram Pinterest
    © 2026 CloudTechReport.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 78,312.00
    ethereum
    Ethereum (ETH) $ 2,305.64
    tether
    Tether (USDT) $ 0.999815
    xrp
    XRP (XRP) $ 1.39
    bnb
    BNB (BNB) $ 616.73
    usd-coin
    USDC (USDC) $ 0.999796
    solana
    Solana (SOL) $ 83.92
    tron
    TRON (TRX) $ 0.33162
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.03
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05