- North Korean developers have allegedly contributed to popular DeFi protocols, according to Taylor Monahan, Co-founder of MyEtherWallet.
- The Lazarus Group has reportedly stolen over $7 billion from the crypto market since 2017.
- Instances of North Korean agents infiltrating crypto projects under false pretenses are increasing, highlighting the need for heightened security measures.
North Korean Developers’ Involvement in Crypto Protocols
In a startling revelation, Taylor Monahan, co-founder of MyEtherWallet and an employee at MetaMask, asserted that developers from North Korea have been involved in creating well-known cryptocurrency protocols since the era known as “DeFi Summer.” These developers often claim “seven years of blockchain experience” on their resumes—a statement that might very well be true.
Projects Potentially Compromised
Monahan highlighted several projects where these developers might have had a hand. Notable names include Sushi, Thorchain, Yam, Pickle, Harvest, Ankr, Fantom, Yearn, and others. Among these, Yearn stands out for its unique security approach—trusting no one outside its team.
Lazarus Group’s Tactics and Impact
The revelations came in response to a post by Tim Ahl, founder of Solana aggregator Titan. Ahl shared that his team unwittingly interviewed a candidate who was later identified as an agent of the Lazarus Group. This candidate participated in video calls and displayed high qualifications but refused an offline meeting—a red flag that led to the withdrawal of their candidacy. Subsequent investigations revealed this individual’s name among data leaks associated with Lazarus.
Crypto researcher ZachXBT explained that Lazarus Group is an umbrella term for multiple cyber divisions funded by the North Korean state. Their tactics range from basic phishing attacks via job listings on LinkedIn or Zoom to more sophisticated operations executed by subgroups like TraderTraitor and AppleJeus.
The Scale of Cyber Attacks
Since 2017, Lazarus Group has reportedly pilfered approximately $7 billion from the crypto market. Analyst jussy mentioned that in 2025 alone, Bybit suffered a loss of around $1.5 billion due to a major breach by the group. In just the first three months of 2026, they launched 18 attacks on crypto projects.
The stolen funds are believed to fund North Korea’s nuclear program. Recent events underscore this threat: decentralized exchange Drift was hacked for $280 million shortly after these revelations surfaced.
These insights into North Korea’s involvement in cryptocurrency highlight critical vulnerabilities within blockchain protocols and emphasize the urgent need for robust security measures across all levels of digital finance infrastructure. As cyber threats evolve rapidly, only those prepared with resilient defenses will navigate safely through this perilous landscape.
