North Korea Has Secretly Reached Into About 20% of Crypto Companies

Cryptocurrencies are considered a high-risk asset class. Investing in them may result in the loss of part or all of your capital. The content on this website is intended solely for informational and educational use and should not be interpreted as financial or investment advice.
Why Trust Us
Why Trust Us
North Korea Has Secretly Reached Into About 20% of Crypto Companies

Pablo Sabatella, a member of the security firm SEAL, issued a stark warning this week, revealing that North Korea’s infiltration of the global cryptocurrency industry is far more severe than previously believed.

Speaking at an industry event in Buenos Aires, Sabatella shared new data showing that 15–20% of crypto companies have North Korean operatives embedded internally without realizing it.

He added that 30–40% of job applications submitted to crypto firms originate from North Korean-linked individuals who disguise their identities and bypass hiring processes using increasingly sophisticated techniques.

North Korean Operatives Are Becoming More Sophisticated

According to Sabatella, North Korean agents are now using foreign nationals as fronts, most commonly individuals based in the United States, to mask their operations.

These agents obtain local U.S. IP addresses and pose as non-English-speaking Chinese applicants, requesting special interview accommodations.

They also infect the front person’s computer with malware, enabling remote access that makes it appear as though the operative is working from within the U.S.

Once hired, Sabatella explained, they work diligently and quietly, raising no suspicions while slowly acquiring access to critical systems and sensitive internal data.

The U.S. Treasury Department estimates that North Korea has stolen over USD 3 billion in cryptocurrency over the past three years, and funds believed to be used for its weapons and nuclear programs.

Crypto Industry’s Security Culture Called “The Worst in Tech”

Sabatella criticized the crypto industry’s lax security environment, calling it “the worst in the computer industry.” Founders often overshare personal details online, creating ideal conditions for social engineering attacks, he said.

The industry’s culture of openness and transparency, which is intended to build trust, ironically provides attackers with the information they need to infiltrate projects.

Sabatella recommended that companies strengthen identity verification procedures and enhance internal security training. One unconventional tactic he mentioned: “Ask applicants to criticize Kim Jong-un.”

North Korean operatives cannot openly criticize their leader, making it a potential filtering tool.

Investors Also Need Better Security Practices

Sabatella stressed that individual users and investors must also take precautions, including:

  • Using secure wallets to store digital assets offline
  • Avoiding suspicious links and phishing sites
  • Understanding common crypto scam tactics
  • Enabling two-factor authentication (2FA)
  • Selecting reputable, security-focused Bitcoin wallets

He warned that without stronger defensive habits, both companies and individuals remain highly vulnerable to North Korean cyber theft.

 

By Patrick Johnson

Patrick Johnson is a seasoned crypto journalist and analyst with a sharp eye for emerging trends in blockchain, DeFi, NFTs, and Web3 innovation. With a background in tech writing and years of experience tracking digital assets, Patrick breaks down complex topics into clear, actionable insights for investors, builders, and curious readers alike. His work spans market analysis, crypto regulation, decentralized finance ecosystems, and interviews with founders shaping the next phase of the internet. Patrick's writing has appeared in leading crypto publications and has earned a reputation for depth, clarity, and a no-hype approach to crypto journalism. When he’s not decoding the latest protocol upgrade or reporting on DAO governance shifts, you’ll find him experimenting with smart contracts or hiking off-grid, because even crypto authors need to unplug sometimes.