How North Korean spies infiltrate US crypto firms, posing as remote workers; UN says the country has stolen billions of dollars' worth of crypto from exchanges
Washington (CNN)Devin, the founder of a cryptocurrency startup based in San Francisco, woke up one day in February to the most bizarre phone call of his life. Tweets: @kyleworton , @snlyngaas , @silvermanjacob , and @elisegaro Tweets: Kyle Orton / @kyleworton : It is wrong to say that cryptocurrency has entirely useless “in real life”. The organised criminal community has had a whale of a time, and one such group, which happens to control #North_Korea, has done especially well out of it. https://cnn.com/... Sean Lyngaas / @snlyngaas : New —> US officials say 1000s of North Koreans are landing jobs at tech firms overseas, offering a critical source of funding for DPRK weapons programs. I spoke to 1 crypto entrepreneur who, the FBI told him, had a North Korean on the payroll for months. https://www.cnn.com/... Jacob Silverman / @silvermanjacob : Besides hacking crypto exchanges for billions in digital funny money, North Korea has placed operatives in crypto and fintech jobs in the west. I really do wonder how many foreign intel officers (and not just adversaries) work at U.S. tech companies. https://www.cnn.com/... Elise Garofalo / @elisegaro : “North Korean tech workers can earn more than $300,000 annually... and up to 90% of their wages go to the regime” https://twitter.com/...
Context & Ripple Effects
The remote-work infiltration CNN documents is not a new tactic but an escalation of a decade-long playbook. Investigations as far back as 2018 found North Korean operatives using fake identities on services like GitHub, Slack, and PayPal to evade sanctions and earn millions, and defector interviews traced the operation to Pyongyang's Reconnaissance General Bureau, whose hackers were then estimated to have stolen over $650M.
First-order effects
- US crypto firms hiring remote engineers now face a screening problem they did not budget for: some applicants are DPRK assets, meaning every hire is both a potential insider threat and a sanctions violation risk.
- Exchanges holding customer funds absorb direct losses — the UN's 'billions stolen' figure lands on their balance sheets and their users' trust.
Second-order effects
- The FBI and DOJ's later finding that thousands of North Korean IT workers funneled millions in US wages home forces crypto companies into costly identity-verification and background-check regimes across their entire contractor pipeline.
- Rival jurisdictions marketing themselves as crypto-friendly inherit the compliance burden too — one lax hire can make an exchange radioactive with US regulators.
Third-order effects
- If the pattern holds, remote hiring in crypto bifurcates: firms either build state-grade vetting or restrict hiring geography, eroding the borderless workforce the industry was built on — and pushing DPRK revenue operations toward the job-offer phishing wave documented by Reuters' research with victims and execs.
- Sustained state-scale theft strengthens the case for treating crypto custody as critical infrastructure subject to banking-style oversight, deepening the industry's [[/concepts#crypto-legitimacy-gap|legitimacy gap]].
The trend: North Korea is industrializing crypto theft and wage infiltration as core regime financing, forcing the crypto industry to adopt the kind of counterintelligence screening normally reserved for defense contractors.