No connection

Search Results

Crypto Score 45 Neutral

Ethereum-Funded Initiative Unmasks North Korean Infiltrators in Web3

Apr 17, 2026 05:20 UTC
ETH
Medium term

The Ketman Project has identified 100 North Korean operatives embedded within blockchain organizations under false identities. The effort, supported by the Ethereum Foundation, aims to mitigate systemic security risks posed by state-sponsored actors.

  • 100 DPRK operatives identified across 53 Web3 projects
  • Funded via Ethereum Foundation's ETH Rangers stipend program
  • Detection based on GitHub metadata and behavioral patterns
  • Collaboration with Security Alliance to create industry standards
  • Development of open-source tools to flag suspicious developer activity

A security initiative funded by the Ethereum Foundation has successfully exposed a network of North Korean IT workers operating under false identities within the Web3 sector. The Ketman Project, which received support through the foundation's ETH Rangers program, identified 100 operatives and alerted 53 different projects regarding the presence of DPRK personnel. The ETH Rangers program was established in late 2024 to provide stipends for public goods security work. The Ketman Project specifically targeted 'fake developers,' a known vector for state-sponsored actors from the Democratic People's Republic of Korea (DPRK) to gain access to sensitive infrastructure and corporate environments. Operatives were identified through a combination of behavioral patterns and technical red flags. These included the reuse of avatars and metadata across multiple GitHub accounts, accidental exposure of unlinked emails during screen shares, and language settings—such as Russian—that contradicted the workers' claimed nationalities. Beyond identifying individuals, the project developed an open-source detection tool for suspicious GitHub activity and co-authored a standardized framework for identifying DPRK workers in collaboration with the Security Alliance. This effort addresses a critical vulnerability, as North Korean hacking groups, including the Lazarus Group, have historically stolen billions in digital assets from the crypto ecosystem.

Sign up free to read the full analysis

Create a free account to unlock full AI-curated market articles, personalized alerts, and more.

Share this article

Related Articles

Stay Ahead of the Markets

Join thousands of traders using AI-powered market intelligence. Get personalized insights, real-time alerts, and advanced analysis tools.

Home
Terminal
AI
Markets
Profile