ETH Rangers Expose 100 North Korean Hackers

Author

Ahmed Barakat

Author

Ahmed Barakat

Part of the Team Since

Aug 2025

About Author

Ahmed Balaha is a journalist and copywriter based in Georgia with a growing focus on blockchain technology, DeFi, AI, privacy, digital assets, and fintech innovation.

Last updated: 

The Ketman Project, operating under the Ethereum Foundation’s ETH Rangers security program, has in the latest Ethereum news, identified approximately 100 North Korea Crypto IT operatives embedded inside Web3 companies using fabricated identities, the result of a six-month investigation that ended with one of the most detailed public tallies of DPRK insider infiltration in the sector’s history.

The threat model has shifted. Where North Korea’s state-level crypto operations once centered on remote exploits and exchange hacks, the 2025 pattern is coordinated workforce infiltration, operatives passing HR screenings, accessing internal repositories, and sitting inside product teams for months before detection.

Key Takeaways:

  • Operatives identified: ~100 DPRK IT workers found using fake identities inside Web3 firms
  • Investigation duration: Six months, conducted by the Ketman Project with ETH Rangers support
  • Program scope: ETH Rangers funded 17 independent researchers, recovered or froze $5.8M in exploited funds, traced 785+ vulnerabilities, handled 36 incident responses
  • DPRK theft scale: $2.02 billion stolen in 2025 alone – a 51% increase from 2024 – pushing cumulative haul to $6.75 billion
  • Drift Protocol hack: DPRK-linked attackers executed a $285 million exploit on April 1, 2026, the largest DeFi hack of the year
  • Real-world case: Exchange Stabble issued a withdrawal alert after a DPRK IT worker infiltrated its leadership team
  • Watch: Investigators are actively tracking Drift exploit proceeds; regulatory scrutiny on DeFi employment vetting expected to intensify
Read More:  Maxi Doge Presale Approaches $5M

Discover: The best crypto to diversify your portfolio with

Ethereum News: How the ETH Rangers Crypto Investigation Actually Worked – and What 100 North Korea Operatives Really Means

ETH Rangers launched in late 2024 through a partnership between the Ethereum Foundation, Secureum, The Red Guild, and the Security Alliance (SEAL), deploying 17 independent security researchers across a six-month mandate to strengthen the Ethereum ecosystem defenses.

Read More:  Goldman Sachs In, Can BTC Break $90K?

The Ketman Project was one of those funded efforts, and its output went well beyond the typical audit or bug bounty scope.

Source: Ketman

Identifying 100 operatives means matching fabricated identities to known DPRK tradecraft patterns: inconsistent work histories, communication behaviors suggesting time-zone masking, payment routing through specific intermediaries, and technical fingerprints that recur across unrelated applicants. That’s intelligence work, not just security research.

It requires sustained monitoring across job boards, GitHub activity, hiring pipelines, and behavioral signals inside existing teams.

The broader ETH Rangers program delivered material results beyond the Ketman work: participants recovered or froze over $5.8 million in exploited funds, traced 785+ vulnerabilities and proof-of-concept exploits, ran 36 incident responses, and delivered more than 80 security training sessions.

Read More:  BMIC Crypto Presale Nears $600K – A Look Inside the First Quantum-Native Wallet

Open-source outputs included a DeFi incident analysis platform, a GitHub suspicious account detector, and a client-side DoS testing framework.

That GitHub tool is relevant here. Suspicious account detection is precisely the capability needed to surface DPRK-linked developers operating under cover – accounts with manufactured contribution histories, coordinated activity patterns, or anomalous repository access. The Ketman findings likely drew on exactly this tooling.

What “100 operatives” doesn’t mean: that those individuals were necessarily running exploits in real time. DPRK IT worker infiltration serves multiple functions: revenue generation for the regime through legitimate salaries, intelligence collection on protocols and codebases, and pre-positioning for future attacks.

The immediate financial damage may be limited; the long-term exposure is structural.

Discover: The best pre-launch token sales


Facebook Comments Box
spot_img

Explore more

spot_img

Crypto traders spend $9.7B on fees as the next Bitcoin drawdown...

Make CryptoSlate preferred on Users paid $9.7 billion in on-chain fees in the first half of 2025, up...

XRP Price Prediction: Ripple Leads This Week

Morgan Stanley’s $116M Bitcoin ETF debut is tiny next to $1.9T,...

Make CryptoSlate preferred on Morgan Stanley launched its spot Bitcoin ETF on Apr. 8 on NYSE Arca, calling...

Crypto traders drive $500M oil bets on Hyperliquid as Hormuz closure...

Make CryptoSlate preferred on Crypto traders traded more than $500 million in synthetic oil futures over the weekend...

Bitcoin network activity just hit an 8-year low — has Wall...

Make CryptoSlate preferred on Bitcoin's network just recorded its lowest activity in eight years, and the price has...

SEC removes huge pattern day trader barrier to allow retail investors...

Make CryptoSlate preferred on The SEC has approved a rule change that eliminates one of Wall Street's most...

White House accuses banks of ‘greed’ in escalating clash over CLARITY...

Make CryptoSlate preferred on A White House digital assets official has slammed the traditional banking sector's continued opposition...

Charles Schwab is bringing uninsured Bitcoin to 39M clients

Make CryptoSlate preferred on Charles Schwab announced this week that it will begin selling Bitcoin and Ethereum directly...