An open-source detection tool and an industry-standard identification framework — those were among the outputs of a single researcher working on a six-month stipend.
One Researcher, One Stipend, 100 OperativesOver six months, the project tracked down 100 North Korean IT workers embedded in Web3 organizations. About 53 projects were contacted and warned that they may have hired active operatives linked to the Democratic People’s Republic of Korea.
The Ketman Project’s website lays out the tactics these workers use — behavioral patterns, technical habits, and identity tricks that allow them to pass as legitimate developers.
Some of the red flags are surprisingly basic. Workers were caught reusing the same profile photos and metadata across different GitHub accounts.
During screen-sharing sessions, unlinked email addresses were accidentally exposed. In some cases, device language settings — set to Russian — gave away identities that contradicted the nationalities being claimed.
How Operatives Were CaughtA separate framework for identifying DPRK-linked workers was co-authored with the Security Alliance, a nonprofit focused on blockchain security. Both resources are now available for other organizations to use.
A Threat Measured In BillionsNorth Korea’s presence in crypto is not new. State-linked hacking groups, including the well-known Lazarus Group, have been tied to some of the largest thefts in the industry’s history.
According to reports, billions of dollars in digital assets have been stolen by North Korean actors over the years.
The ETH Rangers program was created specifically to address security gaps through stipend-funded individuals doing public-interest work.
The Ketman Project represents one of its first publicly documented results. Whether other grant recipients have produced similar findings has not been disclosed.
Featured image from Chief Learning Officer, chart from TradingView


















