Crypto: North Korea recruits abroad to infiltrate US companies
Summarize this article with:

North Korea is expanding its system of infiltration of American companies. According to an NBC investigation, IT workers based in particular in Iran and Lebanon are recruited to sit for interviews in place of North Korean operators. Some would have received $500 per month in crypto to play “interview associates”. Once the contract is won, the position can be taken over by a worker linked to Pyongyang. US authorities had already documented the growing use of third parties to circumvent recruitment controls.

A fake candidate by videoconference hides several digital identities linked to an American crypto company.

In brief

  • Foreign freelancers would be recruited to interview in place of North Korean operators.
  • Some were reportedly offered $500 per month in crypto.
  • Pyongyang-linked groups have been linked to $2.02 billion in digital asset thefts in 2025.

Crypto: $500 per month to interview

The process adds an additional layer to the fake profiles already used by Pyongyang. NBC reports that foreign IT workers have been approached on LinkedIn. Their mission: to appear for interviews for remote jobs in American companies. Some were reportedly offered around $500 per month in cryptocurrencies for this part-time work. Once hired, the accesses can then be used by North Korean operators.

This mechanism resembles that which allowed a developer linked to North Korea to join the Consensys teams. The company discovered in July that a consultant using the identity “Tyler Knapp” had worked on some of its systems for about a month.

The NBC report, however, brings a new element: Pyongyang no longer depends solely on its own operators and false identities. It can also use a real person located in a third country to pass the most difficult part of recruitment.

The international alert published on July 31 by the United States and several governments confirms this development. It says North Korean workers are increasingly using third parties to create accounts, participate in interviews and even physically meet an employer to build trust.

The document does not cite the $500 payment or the Iranian and Lebanese cases. These details come from the NBC investigation.

Secure your cryptos with SafePal
This link uses an affiliate program

Fake employees are already a major problem for the crypto industry

The method is not just for earning a salary. The July 31 alert warns that these workers can become an insider threat: data extraction, theft of sensitive information and theft of crypto are directly among the risks identified. The targeted jobs also include the development of software, mobile applications and blockchain applications.

The Ethereum Foundation already knows about the problem. In April, Tremplin.io reported that it had helped identify around 100 North Korea-linked workers across 53 crypto projects.

CrowdStrike gives an idea of ​​the amount at stake. Its 2026 report on financial threats attributes to actors linked to North Korea $2.02 billion in theft of digital assets in 2025, or 51% more than in 2024. The PRESSURE CHOLLIMA group is notably associated with a theft of $1.46 billion. Other North Korean groups have used fake recruitersAI-generated identities and synthetic video conferencing environments.

Chainalysis arrives at the same amount: $2.02 billion stolen in 2025, for an estimated cumulative $6.75 billion attributed to North Korean hackers over the years. This strategy sometimes avoids traditional hacking altogether. No need to find a loophole in a smart contract if the operator directly obtains a developer position and internal access. This is precisely what is increasingly worrying crypto companies.

Washington now targets entire recruiting infrastructure

The United States is also pursuing the people who make these infiltrations possible. In March, the U.S. Treasury sanctioned six individuals and two entities for their participation in North Korean IT worker networks. OFAC estimates that these devices generated nearly $800 million in 2024 to finance Pyongyang’s weapons of mass destruction programs in particular.

The Department of Justice has also documented “laptop farms.” In one case, two American citizens helped North Korean workers pose as employees based in the United States. The scheme used the stolen identities of at least 80 people and landed jobs with more than 100 U.S. companies. More than $5 million was reportedly generated for the North Korean regime.

Business computers were physically kept in the United States. North Korean operators then accessed it remotely, giving the employer the impression that its developer was working from the country.

The international alert now recommends stricter controls: thorough document checks, in-person interviews where possible, monitoring for frequent changes in identity or banking details, and special attention to applicants using unusual payment methods. In particular, North Korean workers can request their salary via transfer services or in crypto.

The sector already knows the threat. In 2025, CZ warned of 60 fake North Korean developers identified in the crypto ecosystem. The novelty is elsewhere: fake profiles can now have a real face during the interview. A recruiter can therefore check the camera, chat with the candidate and think they have confirmed their identity. The worker who logs in a few days later may be someone else. For American companies and crypto exchanges, remote recruitment thus becomes an attack surface in its own right.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts