Home EntertainmentThis Is How Secret North Korean Agents Infiltrated...
Entertainment⭐ Featured

This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims

North Korea‑connected operatives have spent years quietly embedding themselves inside crypto companies and DeFi projects. A Long-Standing Crypto-Infiltration Saga News and reports from the Democratic People’s Republic of Korea tend to have a particular conspiracy theory-action movie feel to them. However, they also have the tendency to be true and not over exaggerated at all. […]

6 April 2026 at 04:04 pm
1 views
This Is How Secret North Korean Agents Infiltrated Top Crypto Protocols, Researcher Claims

In a recent revelation that has sent shockwaves through the cryptocurrency community, security researcher and MetaMask developer Taylor Monahan has claimed that North Korean agents have been infiltrating top crypto protocols and DeFi projects for years. Monahan's assertion, made in a series of posts on the social network X, paints a chilling picture of state-sponsored actors quietly embedding themselves within the very systems they are supposed to protect.

The Democratic People’s Republic of Korea (DPRK) has a history of producing news and reports that often feel like they could be plotted straight from a conspiracy theory or an action movie. However, as Monahan's claims highlight, these stories are not always exaggerated. This time, the researcher alleges that North Korean operatives have been working covertly inside crypto companies and DeFi projects for over seven years, contributing to several major, widely used protocols.

Monahan's posts suggest that these North Korean IT workers have been hired under false pretenses, using stolen or synthetic identities. They have managed to infiltrate more than 40 DeFi projects, including some of the most well-known protocols that gained prominence during DeFi summer. Among the projects named are Sushi, ThorChain, Yam, Pickle, Harvest, Reclaim, Swing, Paid, Naos, Shezmu, Qrolli, Saffron, Sifu, Napier, Harmony, Blueberry, Stable, Onering, Elemental, Divvy, La Token, ImperMax, Kira, Cook, Fantom, Ankr, Gamerse, MetaPlay, Spice, Beanstalk, and DeltaPrime.

These North Korean agents often have legitimate blockchain development experience, with seven years of on-chain work listed on their resumes. However, their true allegiance lies with the DPRK, and they have been operating under the radar, plugging into teams through normal hiring channels. Monahan's claims come as a response to a tweet from "tim," a pseudonymous builder and public face of Titan, a Solana-based DEX aggregator and routing project. Tim claimed that they had interviewed an extremely qualified candidate who turned out to be a Lazarus operative, the North Korea-affiliated group known for funneling billions of dollars in stolen cryptocurrency through various networks.

The implications of Monahan's allegations are profound. If true, they would mean that North Korean agents have had significant influence over the development and implementation of critical DeFi protocols. This infiltration could have allowed them to plant backdoors, gather intelligence, or even sabotage systems at will. The fact that these operatives have been able to operate for so long without detection raises questions about the security measures in place at these projects and the overall state of cryptocurrency security.

The cryptocurrency community has been on high alert regarding security threats, particularly from state-sponsored actors. The hacking of the Poly Network in 2021, for instance, was linked to Lazarus Group operatives. Monahan's claims add another layer of complexity to this landscape, suggesting that infiltration and covert operations have been taking place at a more insidious level.

As the community grapples with these allegations, questions about the vetting processes of developers and the transparency of DeFi projects come to the forefront. How could such a sophisticated infiltration go undetected for so long? What steps can be taken to prevent such breaches in the future? These are some of the pressing issues that the cryptocurrency community must address as it continues to evolve and grow.

In the meantime, the revelations serve as a stark reminder of the ongoing battle between state-sponsored actors and the cryptocurrency ecosystem. As the technology becomes more integral to global finance and beyond, the stakes for both sides will only continue to rise. The question now is whether the community can learn from these allegations and strengthen its defenses against such threats.

📰 Related News
Bloom Energy (BE) Surges 22.9% on CFO Appointment, Earnings Prep
Bloom Energy (BE) Surges 22.9% on CFO Appointment, Earnings Prep
Bloom Energy Corp. (NYSE:BE) is one of the 10 Stocks Powering Portfolios by Double Digits. Bloom Energy rallied by 22.9 percent week-on-week, as investors...
13 Apr
He Spent 8 Years Working Nights And Weekends Rehabbing Properties While Working Full Time. Now He's Facing A Separation And A $400K Tax Hit
He Spent 8 Years Working Nights And Weekends Rehabbing Properties While Working Full Time. Now He's Facing A Separation And A $400K Tax Hit
A real estate investor who spent nearly a decade building a property portfolio from the ground up is now facing a painful dilemma: walk away from his...
13 Apr
Customs collections hit record high in Q1
Customs collections hit record high in Q1
The Bureau of Customs said it collected P239.05 billion in revenue in the three months of 2026, marking its highest first-quarter collection in history, fueled by a series of public auctions and stronger reforms.
7 Apr
UI backwards compatibility
UI backwards compatibility
About once a month, an app that I regularly use will change its UI in a way that breaks muscle memory, basically tricking the user into doing things they don’t want. Zulip In recent memory, Zulip (a slack competitor) changed its newline behavior so that ctrl + enter sends a message instead of inserting a new line. After this change, I sent a number of half-baked messages and it seemed like some other people did too. Around the time they made that change, they made another change such that a series of clicks that would cause you to send a private message to someone would instead cause you to send a private message to the alphabetically first person who was online. Most people didn’t notice that this was a change, but when I mentioned that this had happened to me a few times in the past couple weeks, multiple people immediately said that the exact same thing happened to them. Some people also mentioned that the behavior of navigation shortcut keys was changed in a way that could cause people to broadcast a message instead of sending a private message. In both cases, some people blamed themselves and didn’t know why they’d just started making mistakes that caused them to send messages to the wrong place. Doors A while back, I was at Black Seed Bagel, which has a door that looks 75% like a “push” door from both sides when it’s actually a push door from the outside and
7 Apr
Former Cathay cinema operator gets 4-month extension for debt moratorium
Former Cathay cinema operator gets 4-month extension for debt moratorium
A previous plan to raise S$14 million via a placement of 1.9 billion shares had fallen through.
7 Apr
Press Start on April: GeForce NOW Brings 10 Games to the Cloud
Press Start on April: GeForce NOW Brings 10 Games to the Cloud
No joke — GFN Thursday is skipping the tricks and heading straight into the games. April kicks off with ten new titles, bringing fresh adventures to GeForce NOW, including the launch of Capcom’s highly anticipated PRAGMATA. A dozen new games are available to stream this week, including Arknights: Endfield, which expands the acclaimed series into a full […]
7 Apr
A new way to express yourself: Gemini can now create music
A new way to express yourself: Gemini can now create music
The Gemini app now features our most advanced music generation model Lyria 3, empowering anyone to make 30-second tracks using text or images.
7 Apr
Gemini 3.1 Flash-Lite: Built for intelligence at scale
Gemini 3.1 Flash-Lite: Built for intelligence at scale
Gemini 3.1 Flash-Lite is our fastest and most cost-efficient Gemini 3 series model yet.
7 Apr
The Great Filter Comes For Us All
The Great Filter Comes For Us All
With a 13 billion year head start on evolution, why haven’t any other forms of life in the universe contacted us by now? ( Arrival is a fantastic movie. Watch it , but don’t stop there – read the Story of Your Life novella it was based on
7 Apr
Samsung's latest TV firmware update fixes the Chromecast issue for older models - finally
Samsung's latest TV firmware update fixes the Chromecast issue for older models - finally
Samsung's 2026 TV lineup will feature built-in support for Google Cast, but with the latest firmware, models as far back as 2024 will also get an update.
7 Apr