Pillole
BTC $62,966.1 -0.29%
ETH $1,875.58 -0.11%
SOL $75.09 -0.83%
BNB $606 -0.31%
XRP $1 -0.43%
DOGE $0.0698 +0.01%
ADA $0.1796 -0.77%
AVAX $6.42 +0.08%
DOT $0.7605 -1.09%
LINK $8.89 +1.26%
⛽ ETH Gas 28 Gwei
Fear&Greed
29

The Honeypot That Exposed the Ghost in the Machine: How a Fake DeFi Startup Unmasked North Korea's IT Front

Partnerships | MaxMoon |

To own nothing is to feel everything, deeply. But when the code you write is not your own, even the feeling of ownership is a ghost. This is the paradox that unfolded when threat intelligence researchers built a fake Decentralized Finance (DeFi) startup, hired three suspected North Korean IT workers as developers, and watched them from the inside. The operation reversed the usual infiltration playbook. Instead of catching operatives trying to break in, researchers watched them work after they cleared interviews. The first crack in the facade appeared in a metadata trace: a forged US driver’s license, processed with Google Gemini, carrying an embedded SynthID watermark. That watermark was not just a forgery detection; it was a signal that the entire identity infrastructure is compromised.

Context: The Ghost Protocol The investigation was a joint effort by BCA LTD’s Mauro Eldritch, NorthScan’s Heiner García, and ANY.RUN. Researchers registered Ballena Azul LTD as a protocol serving cryptocurrency whales. They gave it a website, corporate branding, and a matching UK company registration to look legitimate. They then posed as founders and a team lead. The researchers used the ANY.RUN sandbox platform as the work environment. It recorded every move of the operatives. Angelo Cruz, a recruiter the team met on GitHub, supplied the first developer. That hire recommended a second, who brought in a third. All three cleared interviews and received access to virtual desktops that were actually controlled recording environments. The operatives are described throughout the report as suspected members of Famous Chollima, a unit linked to North Korea’s Lazarus Group that specializes in placing fake IT workers at Western firms.

This is not a new threat. TRM Labs attributed 76% of 2026 crypto-hack losses through April to DPRK crews. Theft reached $2 billion in 2025. One Ethereum (ETH)-funded project previously identified 100 suspected North Korean IT workers across 53 crypto projects. But the infiltration tactic works differently. North Korean workers pose as engineers to win remote jobs, then steal secrets or plant a way back in. The fake startup was a honeypot designed to watch the ghosts work.

Core: The Machine That Watches the Watchers The developers submitted forged US credentials during onboarding. This includes driver’s licenses, stolen Social Security numbers, and accounts at Lead Bank, Citibank, and Wise. Metadata on one license showed it had been processed with Google Gemini and carried an embedded SynthID watermark. This exposed the forgery almost immediately. “By now, we had fake identities, stolen SSNs, mule bank accounts, possible facilitator safe houses, and cryptocurrency wallets with transaction history,” the researchers wrote.

The workers leaned heavily on artificial intelligence. They used ChatGPT to write code they appeared not to understand and to complete assignments. Live translation tools also ran during interviews and daily standups. The operation also surfaced supporting infrastructure. Researchers logged AstrillVPN exit nodes, servers hosted on Vultr and Gorilla Servers, and cryptocurrency wallets holding transaction history. One operative server was already tagged across threat intelligence feeds, a sign it had been recycled from earlier campaigns. “The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes,” the report read.

I have seen this before. In 2018, amidst the chaos of the ICO boom, I retreated from the hype to audit the underlying Solidity code of a prominent Ethereum-based charity token. I spent six weeks line-by-line reviewing 40,000 lines of code, identifying three critical reentrancy vulnerabilities that could have drained $2.5 million in user funds. While my male peers celebrated token launches, I sat in silence, analyzing the ethical implications of unchecked power in smart contracts. But here, the exploit was not in the code but in the trust layer. The vulnerability was not a reentrancy bug; it was a human trust bug. The researchers’ honeypot was a form of ethical hacking that revealed the fragility of remote verification. The watermark was not just a forgery detection; it was a signal that the entire identity infrastructure is compromised.

During DeFi Summer 2020, I launched “The Value Vault,” a community initiative aimed at educating underrepresented women in Bangalore about yield farming risks. I personally mentored 50 women, helping them navigate early Uniswap and Aave protocols. However, when a popular lending platform suffered a $250,000 exploit due to a governance flaw, I felt a profound sense of betrayal. The technology had failed its most vulnerable users, contradicting my belief in decentralization as an equalizer. The vulnerability of users is not just technical; it’s social. These workers are exploiting social trust. The fake startup operation exposed that the same social engineering that deceives users can also infiltrate the very teams building the infrastructure.

In 2021, I curated a digital art collection titled “Code & Conscience,” featuring 12 works by female crypto-artists, to prove that blockchain could amplify marginalized voices rather than just facilitating speculative trades. We raised $15,000 in ETH, directing 10% to digital literacy programs for rural women. Yet, the subsequent market crash in 2022 left me isolated. The sudden collapse of market value felt like a dismissal of the cultural value I had championed. I retreated into solitude, questioning whether my efforts had merely contributed to a vanity metric rather than genuine societal change. Now, I see a parallel: the fake startup was a vanity project that served a higher purpose—exposing the ghosts in the machine. But the question remains: are we building for genuine human connection, or are we just creating more sophisticated traps?

The use of AI by these operatives highlights a deeper irony. In 2026, as AI and crypto converged, I launched “Human-First Protocols,” a research group evaluating AI agents for trustless collaboration. I identified that 70% of current AI-crypto integrations lacked transparent ownership models, risking a new form of centralized control. I published a deep-dive report on “Algorithmic Accountability in DAOs,” influencing two major governance frameworks to adopt open-source verification standards. But here, the operatives used ChatGPT to write code they appeared not to understand. The AI was a crutch, not a tool of empowerment. It allowed them to fake competence. This is the dark side of AI democratization: it lowers the barrier to entry for bad actors just as easily as for good ones.

Trust is not a transaction; it is a resonance. The researchers’ operation was a masterclass in verifying that resonance. They didn’t just rely on technical checks; they watched the human behavior. The operatives used live translation tools during interviews and standups, a sign that they were not native English speakers. The forged credentials were detected not by a blockchain identity system but by a centralized metadata watermark. This is a contrarian truth: sometimes the old guard of metadata and watermarks is more effective than blockchain-based identity. The SynthID watermark was a message from the future: even the most sophisticated AI-generated content can be traced back to its source. But the operatives were not sophisticated enough to know that.

The Honeypot That Exposed the Ghost in the Machine: How a Fake DeFi Startup Unmasked North Korea's IT Front

Contrarian: The Blind Spot of Trustless Systems We celebrate decentralized identity, but here we see that centralized verification (like Google Gemini) is what caught them. The contrarian truth: sometimes the old guard of metadata and watermarks is more effective than blockchain-based identity. The researchers’ honeypot worked, but it also legitimizes a cat-and-mouse game that will escalate. The true solution is not more surveillance but a redefinition of trust. The blind spot is not the workers but the companies that rely on superficial vetting. In the rush to hire remote talent, we have forgotten that trust is built over time, not through a check box. The fake startup was a mirror held up to the industry: we are all vulnerable to social engineering, and the solution is not just better technology but better human practices.

The soul does not mint; it manifests. In the age of AI-generated code and forged identities, the only true sovereignty is the ability to verify not just the code, but the human behind it. We must build systems that assume no trust, but also recognize that the ghost in the machine is always human. The researchers’ operation showed that the best defense is not a wall but a garden—a carefully curated environment where behavior can be observed. But that is a luxury most projects cannot afford. The takeaway is not to become paranoid but to become intentional. Every line of code is a testament to a human intention. The question is: whose intention?

The Honeypot That Exposed the Ghost in the Machine: How a Fake DeFi Startup Unmasked North Korea's IT Front

Takeaway: The Ghost in the Machine As I reflect on my own journey—from the silent audit of 2018 to the Human-First Protocols of 2026—I see a pattern. The threat is not just external; it is internal. The trust we place in code, in teams, in identities is a fragile thing. The fake DeFi startup was a honeypot, but it was also a gift. It showed us that the ghost in the machine is always human. And the only way to exorcise it is to build systems that are not just technically robust but ethically sound. To own nothing is to feel everything, deeply. But when the code is written by a ghost, who owns the truth? The answer is not in the code but in the community. When we build together, we must verify together. The watermark was a signal; the resonance was the truth. Trust is not a transaction; it is a resonance. And in the end, that resonance is all we have.

The Honeypot That Exposed the Ghost in the Machine: How a Fake DeFi Startup Unmasked North Korea's IT Front

This article is based on the original report by BCA LTD, NorthScan, and ANY.RUN. The views expressed are my own and do not represent any organization.

Market Prices

BTC Bitcoin
$62,966.1 -0.29%
ETH Ethereum
$1,875.58 -0.11%
SOL Solana
$75.09 -0.83%
BNB BNB Chain
$606 -0.31%
XRP XRP Ledger
$1 -0.43%
DOGE Dogecoin
$0.0698 +0.01%
ADA Cardano
$0.1796 -0.77%
AVAX Avalanche
$6.42 +0.08%
DOT Polkadot
$0.7605 -1.09%
LINK Chainlink
$8.89 +1.26%

Fear & Greed

29

Fear

Market Sentiment

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$62,966.1
1
Ethereum
ETH
$1,875.58
1
Solana
SOL
$75.09
1
BNB Chain
BNB
$606
1
XRP Ledger
XRP
$1
1
Dogecoin
DOGE
$0.0698
1
Cardano
ADA
$0.1796
1
Avalanche
AVAX
$6.42
1
Polkadot
DOT
$0.7605
1
Chainlink
LINK
$8.89

🐋 Whale Tracker

🟢
0xcc8c...2634
6h ago
In
2,144,550 USDT
🔴
0xb5ce...ea62
12m ago
Out
15,880 SOL
🟢
0xf1d3...864d
2m ago
In
680,789 USDT

💡 Smart Money

0xbffa...dffb
Top DeFi Miner
+$4.0M
66%
0x82a6...950f
Experienced On-chain Trader
+$2.0M
64%
0xc98e...4c34
Early Investor
+$1.1M
95%