Fake Crypto Startup Deceived North Korean IT Workers, Cointelegraph Investigation Reveals
Key Takeaways
- •Cointelegraph Magazine said a fake cryptocurrency startup successfully deceived North Korean IT workers.
- •The report describes the startup as a nonexistent company that still appeared convincing enough to be treated as a real employer.
- •North Korea’s use of IT workers under false identities remains a documented source of revenue despite international sanctions.
- •U.S. and allied authorities have issued warnings about North Korean IT worker activity and recommended stronger verification measures for remote hiring.
- •The case shows that fabricated identities can be used against both employers and applicants in the crypto sector.

A Cointelegraph Magazine investigation has detailed how a fabricated cryptocurrency startup was used to deceive North Korean IT workers, demonstrating that the same impersonation tactics those operatives typically rely on can be turned against them. The report frames the case as a study in how a constructed business identity fooled the very actors known for infiltrating legitimate crypto firms.
North Korea's deployment of IT workers under false identities to foreign employers is a documented revenue channel for a state under extensive international sanctions. U.S. government advisories estimate that individual workers can earn hundreds of thousands of dollars annually in wages routed back to Pyongyang, making the scheme a persistent priority for Western law enforcement and intelligence agencies.
The account comes from Cointelegraph's Magazine investigation, which centers on a fake crypto startup rather than a verified first-hand operation conducted by the publisher. The core question the piece explores is not simply that a deception occurred, but how it succeeded against a target group already skilled in online impersonation.
Because the reporting is investigative journalism, the specifics rest on the outlet's own account. The central claim is straightforward: a startup that did not actually exist was convincing enough to attract North Korean IT workers who believed they were engaging with a genuine crypto employer.
How a Fabricated Startup Identity Carried the Deception
The framing of a "fake crypto startup" implies a constructed business identity, complete with the surface signals a real early-stage crypto company would present. In a hiring or contracting context, those signals are precisely what make an unknown entity appear legitimate to a remote applicant.
A crypto startup cover is a plausible one because the sector routinely hires distributed, pseudonymous talent for short engagements, which lowers the scrutiny applied to any single employer. That environment is exactly what North Korean IT workers have exploited to embed themselves inside firms — and it is what the fake-startup approach appears to have used against them. U.S. and allied authorities have identified thousands of such workers deployed across technology and finance sectors worldwide, placing the risk at the industry level rather than at individual firms.
Beyond the reversal documented in this case, the broader pattern of deception aimed at crypto users is well documented. Such schemes include malware campaigns that target investors through fake GitHub apps and fraudulent products such as an alleged fake Bitcoin app that drew a federal lawsuit against Apple. The common thread is a fabricated identity engineered to appear credible.
Why the Case Matters for Crypto Hiring and Security
The story sits at the intersection of cryptocurrency, employment, and deliberate deception, which is why it carries weight beyond a single unusual episode. For crypto companies, it underscores that identity verification during remote hiring cuts both ways.
Governments have repeatedly flagged the underlying threat. The U.S. State Department issued an alert to countries, companies, and other entities regarding North Korean IT workers, and partner governments echoed the concern in a joint statement on North Korean IT workers. Those advisories outline specific indicators for detecting workers operating under false identities and recommend vetting measures such as live video verification and scrutiny of payment-routing requests.
Security researchers have also tracked the operational side of these schemes, including an investigation by ANY.RUN into IT worker activity linked to the Lazarus group. That reporting reinforces why due diligence on remote talent has become a recurring theme for crypto firms.
The practical takeaway for the crypto sector is that trust signals in startup ecosystems can be manufactured by either side of a hiring relationship. The Cointelegraph investigation documents one instance where a fake company, rather than a fake employee, served as the tool of deception. With U.S. authorities continuing to publish updated guidance and the Treasury Department expanding sanctions targeting entities that facilitate these networks, the case is a reminder that verifying counterparties remains an open challenge for a sector built on pseudonymous, remote collaboration.