/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Investigation: over a dozen crypto companies unknowingly hired North Korean IT workers who used fake IDs, successfully navigated interviews, and passed checks

Sam Kessler / CoinDesk :

CoinDesk Sam Kessler

Context & Ripple Effects

This investigation adds company-level evidence to a recurring remote-work infiltration pattern. Earlier coverage described North Korean operatives posing as remote workers at US crypto firms, while the FBI and DOJ later said false-identity IT workers had sent wages to North Korea through US company employment.

The fact that interview and background-check processes were cleared makes hiring controls—not merely exchange or wallet security—a material exposure for crypto companies.

First-order effects

  • The affected crypto companies must review worker identities, access privileges, code contributions, and payment relationships for potentially compromised engagements.
  • Recruiting and security teams face pressure to strengthen identity verification and continuously monitor remote-worker access after standard interviews and checks proved insufficient.

Second-order effects

  • Crypto employers and staffing vendors may add more stringent verification and access segmentation, increasing hiring friction for legitimate remote candidates.
  • The findings broaden security diligence from defending customer assets to protecting internal engineering, operations, and payroll workflows that an embedded worker could reach.

Third-order effects

  • If repeat cases continue, remote hiring will become a sanctions-compliance and supply-chain-security function, not solely an HR process—especially in crypto's long-running exposure to disguised remote operatives.
  • The pattern could accelerate demand for verifiable worker identity and least-privilege development practices, though the investigation alone does not establish which controls will prove most effective.

The trend: Crypto companies are treating workforce identity as part of the attack surface as state-linked actors exploit remote hiring channels.

Discussion

  • @justinhendrix.bsky.social Justin Hendrix on bluesky
    A scam inside a scam...  [embedded post]
  • @skesslr Sam Kessler on x
    North Korean IT workers with fake identities got jobs at @cosmos, @SushiSwap, @yearnfi, @FantomFDN, @zerolendxyz and several other big-name blockchain protocols. This investigation marks the first time any of these projects have publicly disclosed that they unknowingly hired the
  • @skesslr Sam Kessler on x
    SCOOP: My latest investigation exposes how DPRK IT workers have embedded themselves deep into the fabric of the crypto industry. More than a dozen projects confirmed that they inadvertently hired workers from the DPRK - exposing themselves to massive security and legal risks.