For crypto companies, the most consistent North Korean threat this year has not arrived through a contract exploit. It arrived through a job application.
US authorities have continued to bring indictments and sanctions tied to North Korean nationals who obtain remote software jobs using stolen or fabricated identities, funneling salaries back to weapons programs. Several US-based facilitators who ran "laptop farms" — hosting company-issued machines so the work appeared to originate domestically — have pleaded guilty.
The economics explain the persistence. A single placed engineer earns a six-figure salary with no operational risk, and a placement inside a firm holding customer funds provides something considerably more valuable: legitimate access to code, infrastructure and, occasionally, signing procedures.
Detection has moved to the mundane. Firms report catching candidates through inconsistencies in timezone behavior, reluctance to appear on camera in unscripted settings, payroll routed through third-party processors and identity documents that pass automated verification but not human scrutiny.
Remote-first hiring is what makes the sector vulnerable, and few crypto companies will abandon it. The realistic mitigation is layered: verified identity at onboarding, least-privilege access for new engineers, and mandatory review before any code touches production.
Regulators have begun asking about it directly. Examiners now request hiring and access-control documentation as part of routine supervision, which turns a security practice into a compliance obligation.
