Currencies38488
Market Cap$ 2.25T-1.11%
24h Spot Volume$ 20.73B-5.21%
DominanceBTC56.37%-0.11%ETH10.04%-0.78%
ETH Gas0.09 Gwei
Cryptorank
/

A Fake DeFi Startup Hired 3 Suspected North Korean Developers: What Happened Next?


A Fake DeFi Startup Hired 3 Suspected North Korean Developers: What Happened Next?

Share:

AI Overview

Researchers created a fake DeFi startup, Ballena Azul LTD, and hired three suspected North Korean IT operatives linked to Famous Chollima who used forged US IDs (one showing a Google Gemini SynthID watermark) and AI tools like ChatGPT to pass interviews and gain legitimate access to code, wallets and smart contracts. The report warns this hiring-based infiltration is a major crypto security risk: TRM Labs attributes 76% of 2026 crypto hack losses through April to DPRK crews, thefts reached $2 billion in 2025, and prior analysis found about 100 suspected DPRK workers across 53 crypto projects.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

In Brief

  • Researchers ran a fake DeFi startup and hired suspected North Korean developers.
  • Operatives forged US IDs with Google Gemini and leaned on ChatGPT for coding.
  • Once hired, workers gained legitimate access to code, wallets, and smart contracts.

Threat intelligence researchers built a fake Decentralized Finance (DeFi) startup, hired suspected North Korean IT workers as developers, and watched them from the inside.

The operation reversed the usual infiltration playbook. Instead of catching operatives trying to break in, researchers watched them work after they cleared interviews.

How the Fake Startup Exposed North Korean IT Workers

The investigation was a joint effort by BCA LTD’s Mauro Eldritch, NorthScan’s Heiner García, and ANY.RUN. Researchers registered Ballena Azul LTD as a protocol serving cryptocurrency whales.

They gave it a website, corporate branding, and a matching UK company registration to look legitimate. They then posed as founders and a team lead. 

The researchers used the ANY.RUN sandbox platform as the work environment. It recorded every move of the operatives. Angelo Cruz, a recruiter the team met on GitHub, supplied the first developer. 

That hire recommended a second, who brought in a third. All three cleared interviews and received access to virtual desktops that were actually controlled recording environments.

The operatives are described throughout the report as suspected members of Famous Chollima, a unit linked to North Korea’s Lazarus Group that specializes in placing fake IT workers at Western firms.

Follow us on X to get the latest news as it happens

What the Researchers Found

The developers submitted forged US credentials during onboarding. This includes driver’s licenses, stolen Social Security numbers, and accounts at Lead Bank, Citibank, and Wise. 

Metadata on one license showed it had been processed with Google Gemini and carried an embedded SynthID watermark. This exposed the forgery almost immediately.

“By now, we had fake identities, stolen SSNs, mule bank accounts, possible facilitator safe houses, and cryptocurrency wallets with transaction history,” the researchers wrote.

The workers leaned heavily on artificial intelligence. They used ChatGPT to write code they appeared not to understand and to complete assignments. Live translation tools also ran during interviews and daily standups.

The operation also surfaced supporting infrastructure. Researchers logged AstrillVPN exit nodes, servers hosted on Vultr and Gorilla Servers, and cryptocurrency wallets holding transaction history. One operative server was already tagged across threat intelligence feeds, a sign it had been recycled from earlier campaigns.

“The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes,” the report read.

North Korean hackers have posed a persistent threat to the crypto industry. TRM Labs attributed 76% of 2026 crypto-hack losses through April to DPRK crews. Theft reached $2 billion in 2025.

The infiltration tactic works differently. North Korean workers pose as engineers to win remote jobs, then steal secrets or plant a way back in. One Ethereum (ETH)-funded project previously identified 100 suspected North Korean IT workers across 53 crypto projects.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

Read the article at BeInCrypto
Read the article at BeInCrypto

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

Binance Security Chief Says Quantum Computers Are Not What Steals Crypto Today

Binance Security Chief Says Quantum Computers Are Not What Steals Crypto Today

In Brief Binance CSO Jimmy Su says quantum is not crypto's biggest threat today. Su ...
Harmony Token Falls to Record Low After Exploit Mints 4 Billion ONE

Harmony Token Falls to Record Low After Exploit Mints 4 Billion ONE

In Brief Harmony token crashed to a record low after an unauthorized 4 billion ONE m...