The ETH Rangers Program Just Exposed 100 North Korean Operatives Inside Web3 — And Recovered $5.8 Million

For six months, a small team of independent researchers funded by the Ethereum Foundation quietly mapped one of the most sophisticated infiltration operations ever documented in crypto. When the ETH Rangers Program wrapped up on April 16, 2026, the results were striking: 100 North Korean state-sponsored operatives identified across 53 Web3 organizations, $5.8 million in funds recovered or frozen, and a new open-source toolkit that is already becoming the industry standard for detecting fake developer identities.

What the ETH Rangers Program Actually Was

In late 2024, the Ethereum Foundation partnered with three security organizations — Secureum, The Red Guild, and the Security Alliance (SEAL) — to launch a stipend program for independent researchers doing public goods security work. The idea was straightforward: identify talented people already contributing to Ethereum’s security ecosystem, fund them for six months, and let them build whatever they thought the ecosystem needed most.

Seventeen researchers received stipends. What they built over those six months ranged from vulnerability research tools and formal verification frameworks to threat intelligence databases and security education programs. The breadth of the output is what makes the program’s final recap, published on the official Ethereum Foundation Blog on April 16, 2026, genuinely worth reading in full.

The headline numbers are impressive on their own. But the more interesting story is in the details of how the DPRK infiltration was discovered, documented, and disrupted — and what it reveals about the scale of North Korea’s crypto operation.

The Ketman Project: Mapping North Korea’s Web3 Workforce

One ETH Rangers recipient used their stipend to build and scale the Ketman Project, a dedicated investigation into North Korean (DPRK) IT workers who have infiltrated blockchain projects under forged identities. The name comes from a Polish novel about the art of concealment — fitting for an operation built around fake personas, fabricated work histories, and carefully constructed GitHub profiles designed to pass standard hiring checks.

Over the stipend period, the Ketman Project reached out to approximately 53 projects and identified around 100 different DPRK IT workers operating within Web3 organizations. These were not peripheral contributors — they were embedded developers, auditors, and protocol engineers with access to codebases, private repositories, and in some cases, multisig wallets. The team published investigative articles on ketman.org that reached over 3,300 active users and 6,200 page views, covering topics including account takeover tactics, freelance platform infiltration methods, and documented connections between DPRK IT networks and Russian infrastructure.

The team also developed and open-sourced gh-fake-analyzer, a GitHub profile analysis tool for detecting suspicious activity patterns that is now available on PyPI. More significantly, they co-authored the DPRK IT Workers Framework with SEAL — a structured reference document that has already become a standard resource for security teams trying to identify and remove North Korean workers from their organizations. Their work was featured in a presentation at DEF CON, one of the world’s largest security conferences.

The Numbers Behind the Operation

The scale of what the ETH Rangers program produced across all 17 recipients is worth seeing in aggregate. The program’s final recap laid out the consolidated outcomes clearly.

MetricResult
Funds recovered or frozen$5.8 million+
Vulnerabilities, bugs, and PoCs reported785+
DPRK operatives identified~100 across 53 projects
Views and users reached with threat content209,000+
Teams engaged in security challenges800+
Workshops and educational resources delivered80+
Incident responses handled36+
Open source tooling repositories developed7+
ETH Rangers Program consolidated outcomes, April 2026. Source: Ethereum Foundation Blog

The $5.8 million figure deserves some unpacking. A significant portion came from the work of Nick Bax, a security researcher who contributed to over 36 SEAL 911 incident response tickets during the program. His most notable contribution was assisting with the Loopscale exploit incident response — a case that resulted in the full return of $5.8 million in stolen funds. Separately, as part of a team, Bax identified and notified more than 30 organizations that they were employing DPRK IT workers, and coordinated the freezing of mid-six-figures in funds that had already been paid out to those workers.

How North Korea Gets Inside Crypto Projects

The mechanics of DPRK IT worker infiltration are more sophisticated than most people in the industry realize. These are not opportunistic hackers scanning for vulnerabilities from the outside. They are long-term embedded operatives who apply for legitimate jobs, pass technical interviews, contribute real code, and collect salaries — often for months or years — before either exfiltrating funds or disappearing when their cover is blown.

Nick Bax’s work during the ETH Rangers program produced one of the most widely shared awareness resources on this threat: a video about DPRK “Fake VC” scams that received 200,000 views on X, with multiple crypto executives publicly crediting it for helping them avoid being compromised. The scam involves North Korean operatives posing as venture capitalists or business development contacts, scheduling video calls, and using the interaction to deliver malware or extract sensitive information.

Bax also identified and disclosed a homoglyph attack used by the “ELUSIVE COMET” threat group to evade Zoom’s suspicious name detection — a vulnerability that was subsequently patched. He represented SEAL at a US Department of Treasury roundtable on DPRK hacker mitigations and spoke at Interpol Headquarters in Lyon. The threat is being taken seriously at the highest levels of international law enforcement.

“These ETH Rangers Program results demonstrate the reality that securing a decentralized network requires a decentralized defense.”

— Ethereum Foundation Protocol Security Team and Grants Management Team, April 16, 2026

Industry estimates suggest the problem is larger than any single program can address. Security researchers tracking DPRK activity in crypto have estimated that between 15% and 20% of crypto firms currently employ at least one North Korean IT worker, and that between 30% and 40% of job applications at some Web3 companies come from DPRK-linked agents. Those numbers, if accurate, represent a systemic risk to the ecosystem that goes well beyond individual exploits.

Beyond DPRK: The Broader Security Work

The DPRK story dominated headlines, but it was only one thread in a much larger program. SunSec and DeFiHackLabs built an Incident Explorer platform for searching and analyzing DeFi incidents with proof-of-concept exploits and root cause analysis, cataloging over 620 PoCs to date. They ran a PoC Summer Contest that received 43 new submissions from the community and delivered six workshop sessions at Korea University covering smart contract bug classes, auditing, and attack case analysis.

Guild Audits ran intensive smart contract security bootcamps across Africa, Asia, Europe, and the Americas, training researchers who went on to report over 110 vulnerabilities across major audit contest platforms including Sherlock, Code4rena, Codehawks, Cantina, and Immunefi — with several students ranking in the top 10 on leaderboards. Guild Audits also hosted Africa’s first Web3 Security Summit on November 8, 2025, bringing together security researchers, auditors, and developers from across the continent.

The security infrastructure being built around Ethereum is directly relevant to the broader institutional adoption story. As explored in our coverage of the CLARITY Act and Ethereum’s regulatory trajectory, the path to mainstream institutional adoption runs directly through security credibility. Programs like ETH Rangers are part of what makes that credibility possible.

What This Means for Web3 Hiring and Security Practices

The practical implications for any organization building on Ethereum are significant. The tools and frameworks produced by the ETH Rangers program — the DPRK IT Workers Framework, the gh-fake-analyzer tool, the Ketman Project’s investigative methodology — are all publicly available and designed to be used by teams that lack dedicated security resources.

The core lesson from the Ketman Project’s work is that standard hiring checks are insufficient for detecting DPRK operatives. These individuals have real GitHub histories, real code contributions, and real references — often because they have genuinely worked on other projects before. The detection requires pattern analysis across multiple signals: contribution timing, communication patterns, IP and device fingerprinting, and cross-referencing against known DPRK-linked accounts.

The ETH Rangers program also demonstrated something important about how decentralized security can work at scale. Rather than building a centralized security team within the Ethereum Foundation, the program funded independent researchers who built infrastructure that benefits the entire ecosystem. The 800+ teams engaged in security challenges, the 209,000+ users reached with threat awareness content, and the 7+ open source tooling repositories created are all persistent resources that continue generating value long after the stipend period ended. For a deeper look at how Ethereum’s on-chain activity has been evolving alongside these security developments, our analysis of Ethereum’s Q1 2026 transaction records provides useful context on the scale of the network being protected.

Key Takeaways

The ETH Rangers Program recap is one of those documents that rewards careful reading. On the surface, it is a summary of a six-month security initiative. Underneath, it is a detailed map of the threat landscape facing Ethereum’s developer ecosystem — and a proof of concept for how decentralized, community-funded security can produce results that rival or exceed what centralized security teams achieve.

The DPRK infiltration story is the most dramatic element, but the 785 vulnerabilities documented, the 36 incident responses handled, and the security education infrastructure built across multiple continents represent a more durable contribution. These are not one-time fixes. They are capabilities that compound over time as more researchers are trained, more tools are adopted, and more organizations learn to recognize and respond to the threats the program has mapped.

The real question the program raises is not whether North Korea is a threat to Web3 — that is now well established. The question is whether the ecosystem’s security infrastructure is scaling fast enough to keep pace with the sophistication of the attacks. The ETH Rangers program suggests the answer is yes, but only if the funding and the talent continue to show up. Whether the Ethereum Foundation and its partners sustain this model into a second program cycle will be worth watching closely.

Anna Vilasot

Anna Vilasot is a crypto content specialist with a strong focus on Ethereum and the broader blockchain ecosystem. With several years of experience writing news, in-depth guides, and analysis pieces, she combines technical accuracy with clear, reader-friendly explanations. Anna has worked on specialized crypto and iGaming projects, developing content that balances SEO performance with genuine value for both beginners and advanced users. Her interest in cryptocurrencies goes beyond work — she closely follows industry trends, DeFi developments, and on-chain innovations. Anna’s approach is professional yet approachable, aiming to make complex crypto topics accessible, engaging, and trustworthy for a global audience.

Latest News

More News