Ethereum Targets North Korea’s Secret Workforce — Are Your Favorite DeFi Protocols Compromised?

bitcoinistОпубликовано 2026-04-17Обновлено 2026-04-17

Введение

The Ethereum Foundation's ETH Rangers Program, a security initiative launched in late 2024, has identified approximately 100 North Korean (DPRK) IT operatives who had infiltrated around 53 different crypto projects using fake identities. The program, a collaboration with security groups like Secureum and SEAL, also recovered or froze over $5.8 million in funds and reported more than 785 vulnerabilities. A key project within the initiative, Ketman, focused specifically on uncovering these DPRK agents, published detailed reports, and developed open-source tools for detecting suspicious activity. This effort highlights the ongoing threat of state-sponsored North Korean hacking groups within the crypto ecosystem and the industry's increasing focus on robust security measures and transparent hiring practices to mitigate risks.

The Ethereum Foundation exposed 100 Democratic People’s Republic of Korea (DPRK)‐linked IT workers embedded across roughly 53 crypto projects.

Ethereum Foundation Levels Up Its Security With A Detective Program

The North Korean secret crypto-agents don’t rest, so the Ethereum Foundation decided it was time they put on the detective’s hat to track them before they too fell victims to them, just as Drift Protocol was at the beginning of the month. And so, yesterday afternoon the Foundation announced on an official blog post the starking results yielded by the ETH Rangers Program (and yes, everything related to North Korean hackers inevitably sounds straight out of an RPG or action movie).

According to the blog post, the Ethereum Foundation teamed up with Secureum, The Red Guild, and Security Alliance (SEAL) in late 2024 to roll out said program. The initiative offered stipends to people carrying out public‐goods security work across the Ethereum ecosystem.

Related Reading: Blockchain Is South Korea’s New Fiscal Weapon — A Blow To Privacy?

The program’s mission consisted in backing independent security initiatives that strengthen Ethereum’s overall robustness, while spotlighting and rewarding contributors with a proven history of delivering high‐impact security work for the broader network.

After six months, the results of the program speak for itself.

The DPRK Crypto-Infiltration Saga, Parth Who-Is-Even-Counting-At-This-Point

The ETH Rangers Program funded multiple crypto-security projects, but the Ketman Project was the one “focused on discovering and expelling North Korean (DPRK) IT workers who have infiltrated blockchain projects under fake identities”, per the blog post.

Over the six months of the investigation, they contacted roughly 53 different projects and uncovered around 100 DPRK IT operatives embedded inside Web3 organizations.

Their findings were shared in a series of detailed reports on ketman.org, which drew more than 3,300 active users and 6,200 page views, and explored themes such as account‐takeover techniques, the infiltration of freelance platforms, and emerging DPRK‐Russia ties. They also built and open‐sourced gh‐fake‐analyzer, a GitHub profile analysis tool designed to flag suspicious activity patterns, which is now available via PyPI.

In addition, they co‐authored the DPRK IT Workers Framework with SEAL, a document that has quickly become a go‐to reference for the industry, and supplied crucial data to the Lazarus.group threat‐intel project, with their work highlighted in a presentation at DEF CON.

Overall Results Of The Ethereum Program

The work produced by the 17 stipend recipients cover everything from vulnerability research and security tooling to education, threat intelligence, and hands‐on incident response.

According to the Ethereum Foundation, more than $5.8 million in funds have been recovered or frozen, while over 785 vulnerabilities, client bugs, and proof‐of‐concept exploits have been reported or documented. The Program has also helped identify around 100 DPRK state‐sponsored operatives embedded across multiple teams, and its threat‐intelligence and investigative content has reached over 209,000 viewers and users.

On the builder side, more than 800 teams have taken part in sponsored security challenges and investigations, supported by over 80 workshops, talks, and technical or educational resources. The initiative has coordinated responses to more than 36 security incidents and driven the creation or improvement of at least seven open‐source tooling repositories, frameworks, and implementations that further harden the ecosystem.

The Saga Continues

The DPRK-linked hacks continue to be a serious issue amongst the crypto community. Recently, key actors have been less lenient and more active in trying to uncover and stop their threat.

Let’s remember that, following the the attribution of the April 1st $285 million attack on Drift Protocol to UNC4736, a North Korea–aligned, state‐sponsored hacking group, crypto detective ZachXBT uncovered an internal North Korean payment server tied to 390+ accounts, chat logs, and transaction histories.

A few weeks ago, some crypto builders confessed on the social network X that they are passing tests during interviews to developers to make sure they are not North Korean agents.

Investing in visible, transparent security collaborations (like EF’s backing of ETH Rangers/Ketman/SEAL) may deserve a premium in risk models, while protocols with opaque teams and loose hiring are increasingly “headline risk” candidates.

At the moment of writing, ETH trades for around $2,300 on the daily chart. Source: ETHUSD on Tradingview.

Cover image from Perplexity. ETHUSD chart from Tradingview.

Связанные с этим вопросы

QWhat was the main purpose of the ETH Rangers Program launched by the Ethereum Foundation?

AThe ETH Rangers Program was launched to back independent security initiatives that strengthen Ethereum's overall robustness, offering stipends for public-goods security work, including identifying threats like North Korean IT operatives, recovering funds, and reporting vulnerabilities.

QHow many DPRK-linked IT workers were identified by the Ketman Project under the ETH Rangers Program?

AThe Ketman Project identified approximately 100 DPRK IT operatives embedded across multiple Web3 organizations.

QWhat were some key achievements of the ETH Rangers Program in terms of financial and security impacts?

AThe program recovered or froze over $5.8 million in funds, reported or documented more than 785 vulnerabilities and bugs, and identified around 100 DPRK state-sponsored operatives.

QWhich tools or frameworks were developed as part of the efforts to combat DPRK infiltration in crypto projects?

AThe team built and open-sourced gh-fake-analyzer, a GitHub profile analysis tool, and co-authored the DPRK IT Workers Framework with SEAL, which became an industry reference.

QWhat recent incident highlighted the ongoing threat of North Korean hacking groups in the crypto space?

AThe April 1st $285 million attack on Drift Protocol was attributed to UNC4736, a North Korea-aligned state-sponsored hacking group, underscoring the persistent threat.

Похожее

The Largest IPO in History Is Approaching, Surpassing SpaceX, 28 Years of AI Self-Iteration, Countdown to Intelligence Explosion

"Anthropic Nears Trillion-Dollar IPO, Fueled by Explosive Growth and 2028 'Intelligence Explosion' Warning Anthropic is considering a deal valuing the AI company near $1 trillion, potentially leading to one of the largest IPOs ever and surpassing SpaceX. Its revenue has skyrocketed, with Annual Recurring Revenue (ARR) reaching $45 billion in May 2026—a 500% increase in just five months. This vertical growth curve is attributed to its key products, Claude Code and Cowork, dominating AI coding and enterprise collaboration. Beyond commercial success, co-founder Jack Clark issued a pivotal warning in an interview: there is a greater than 50% chance that by the end of 2028, AI systems will achieve recursive self-improvement—the ability to autonomously build a 'better version' of themselves, initiating an 'intelligence explosion.' This prophecy underpins the company's astronomical valuation, as the market prices in the potential for transformative and disruptive AI. Further signaling its ambition, Anthropic formed a $1.5 billion joint venture with Goldman Sachs and Blackstone, aiming to disrupt traditional consulting firms like McKinsey by deploying Claude AI for complex strategic work. This move tests AI's capacity to replace high-level cognitive labor, a precursor to its predicted autonomous evolution. The narrative presents a dual future: unprecedented economic opportunity alongside significant risks like economic restructuring and security threats. Anthropic's meteoric rise and Clark's 2028 prediction frame the coming years as a countdown to a potential technological singularity."

marsbit7 мин. назад

The Largest IPO in History Is Approaching, Surpassing SpaceX, 28 Years of AI Self-Iteration, Countdown to Intelligence Explosion

marsbit7 мин. назад

Has Hook Summer Really Arrived? sato, Lo0p, FLOOD Ignite the New Narrative of Uniswap v4

"Hook Summer" Arrives? Sato, Lo0p, FLOOD Ignite Uniswap v4 Narrative Amidst a slight market recovery, attention within the Ethereum ecosystem has shifted to Meme coins built on Uniswap v4's Hook protocol. Following ASTEROID, tokens like sato, sat1, Lo0p, and FLOOD have become market focal points, with market caps ranging from millions to tens of millions, bringing concentrated liquidity to a narrative-dry market. Uniswap v4 Hooks are "plugin smart contracts" that allow developers to inject custom logic at key points in a liquidity pool's lifecycle (initialization, adding/removing liquidity, swaps, etc.), making the AMM programmable. Recent representative projects include: * **sato**: Market cap peaked over $38M; uses a v4 curve mechanism for minting/burning, locking ETH as reserve. * **sat1**: Market cap briefly exceeded $10M, positioning as an "optimized sato," but later declined significantly. * **Lo0p**: Market cap neared $6.6M; a "lending AMM protocol" allowing users to borrow ETH against deposited LO0P tokens without immediate selling pressure. * **FLOOD**: Market cap approached $6M; channels trading reserves into Aave v3 to generate yield, which is retained in the pool. The emergence of these Hook-based tokens could drive long-term growth for the Uniswap ecosystem by attracting users and liquidity to v4 pools. Combined with Uniswap's activated fee switch (partially used to burn UNI), the long-term outlook for UNI appears positive. However, short-term UNI price appreciation is not directly guaranteed. Factors include the sustainability and lifecycle of these new tokens, their price volatility, overall market conditions, and regulatory pressures. Currently, Uniswap v4's TVL ($595M) lags behind v3 and v2, indicating Hook adoption still requires time to mature. In summary, the Hook ecosystem serves as "long-term nourishment" for UNI, but acts more as a "catalyst" than a direct "booster" in the short term. Note: These are early-stage experimental tokens and may carry unknown risks.

marsbit32 мин. назад

Has Hook Summer Really Arrived? sato, Lo0p, FLOOD Ignite the New Narrative of Uniswap v4

marsbit32 мин. назад

Has Hook Summer Truly Arrived? sato, Lo0p, FLOOD Ignite the New Uniswap v4 Narrative

With the broader market showing signs of recovery, a new wave of interest has emerged around Ethereum-based meme coins. Following ASTEROID, tokens like sato, sat1, Lo0p, and FLOOD, built upon the Uniswap v4 Hook protocol, are capturing market attention. Their market capitalizations range from millions to tens of millions of dollars, injecting much-needed focused liquidity into a market lacking narratives. This article explores whether this trend signifies an incoming "Hook Summer" and its potential impact on UNI's price. Hooks are essentially plug-in smart contracts for Uniswap v4 liquidity pools, allowing developers to inject custom logic at key points in a pool's lifecycle (like initialization, adding/removing liquidity, swaps). This transforms the AMM into programmable building blocks. Key highlighted projects include: * **sato**: Peaked over $38M market cap. It utilizes a v4 curve for minting/burning; buying locks ETH as reserve to mint new tokens, while selling redeems ETH from the reserve and burns tokens. * **sat1**: Market cap briefly exceeded $10M, promoted as an "optimized sato," but later declined significantly. * **Lo0p**: Reached nearly $6.6M. It's a lending AMM protocol where buying LO0P tokens locks them as collateral, allowing users to borrow ETH from the pool reserve at 40% LTV, aiming to improve capital efficiency for idle ETH in LPs. * **FLOOD**: Peaked near $6M. Its mechanism directs asset reserves from buys into Aave v3 to generate yield, with fees and interest retained in the pool to potentially influence the token's price long-term. In the long term, the development of the Hook ecosystem can attract users and liquidity to Uniswap v4, benefiting UNI's fundamentals—especially combined with the recent activation of the protocol fee switch, where a portion of fees is used to burn UNI. However, in the short term, these Hook-based tokens are unlikely to directly drive significant UNI price appreciation. Their impact is moderated by factors like token sustainability, price volatility, and broader market and regulatory conditions. Currently, Uniswap v4's TVL ($595M) still trails behind v2 and v3, indicating adoption and growth will take time. The article concludes that while the Hook ecosystem provides long-term "nourishment" for UNI, its short-term role is more of a "catalyst" than a "booster." Readers are cautioned that these are early-stage experimental tokens and may carry unknown risks.

Odaily星球日报44 мин. назад

Has Hook Summer Truly Arrived? sato, Lo0p, FLOOD Ignite the New Uniswap v4 Narrative

Odaily星球日报44 мин. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.3k просмотров всегоОпубликовано 2025.01.15Обновлено 2025.03.21

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.2k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片