Consumer Protection Tuesday: How Coinbase Detects and Disrupts Sophisticated Hiring Threats

North Korea (DPRK) linked actors are actively targeting U.S. companies across every industry, using increasingly sophisticated methods to infiltrate organizations through fraudulent hiring schemes. These operations often involve real people, sometimes U.S. based, with legitimate identities and backgrounds, who allow their access to be used by others, whether wittingly or not. This makes them exceptionally difficult to catch through identity verification or background checks alone, since the person passing those checks may not be the one actually doing the work.
In the spirit of transparency, and because we believe the industry is stronger when we share what we learn, we want to walk through a real example of how this played out at Coinbase and why partnerships with independent security researchers are such a critical part of how these networks get exposed.
What Happened
Late last year, Coinbase engaged a short-term, U.S.-based contractor for engineering work. During the engagement, our systems flagged anomalous technical activity associated with the contractor's setup and his access was cut while our team reviewed. Separately, the contractor's performance and responsiveness did not meet expectations, and Coinbase did not renew the engagement, ending it within 30 days of onboarding.
Some time later, we were contacted by independent security researcher Vangelis Stykas, from Kumio, who shared intelligence suggesting this contractor may have been part of a broader DPRK-linked infiltration effort, and that a small amount of insignificant code had been pushed to their own private, internal repository. We investigated immediately and confirmed that the code involved was not sensitive, was unrelated to customer data, and posed no security risk to Coinbase or its customers.
We were able to confirm that the contractor was located in the United States and passed security clearance processes. We also found no evidence confirming that he was working with someone located in North Korea or affiliated with DPRK. But the pattern identified was inconsistent with our security practices, which are also designed to protect against known DPRK infiltration tactics, in which intermediaries, witting or unwitting, provide identity, credentials, and access on behalf of overseas operators.
Stykas's research reflected a level of visibility well beyond what is publicly available, and his outreach allowed us to close the loop on this case with confidence. We're grateful for his work, and for researchers like him who choose to partner directly with companies rather than simply publicizing findings. That kind of collaboration is one of the most effective tools the industry has for staying ahead of these threats, and it's exactly why Coinbase invests heavily in these relationships.
How Coinbase Disrupts and Guards Against DPRK-Linked Threats
Infiltration attempts are one of many tactics DPRK-linked actors use against companies and Coinbase has built layered defenses at every stage of an individual's interaction with the company, from application through employment, to prevent, detect, and respond to it. We also work with U.S. national security and law enforcement agencies to track and disrupt state-sponsored actors targeting the crypto industry, and we share intelligence on known DPRK threat actors with peer companies.
Hiring and screening. We automatically screen all applicants against indicators of compromise associated with known DPRK actors, drawing on open-source intelligence, external partners, intelligence-sharing communities, and our own investigations. When new indicators emerge, we re-screen both new applicants and current employees. Hiring and interview personnel receive dedicated threat-actor awareness training to catch suspicious behavior that automated screening might miss.
Onboarding and identity verification. All full-time employees and contractors undergo enhanced pre-hire identity verification and fraud screening through an external provider. We also monitor for anomalies such as address changes or requests to redirect company-issued equipment.
Continuous monitoring. We run active detections, spanning technical and behavioral indicators, to monitor known DPRK and other bad actor tactics across all employees. Alerts are reviewed in real time by our dedicated insider threat team.
Ecosystem protection. Dedicated security teams monitor external threats attributed to the DPRK, and we conduct proactive investigations to identify DPRK-linked wallet addresses, tactics, and indicators, work that protects the broader crypto ecosystem, not just Coinbase. We track incidents where DPRK-affiliated actors have exploited other protocols and validate that our own architecture mitigates those same attack vectors.
Private-sector and government collaboration. We share threat intelligence through channels including CryptoISAC, which Coinbase co-founded, and through voluntary arrangements under Section 314(b) of the USA PATRIOT Act. We share intelligence with sanctions regulators to strengthen designations and prevent evasion. When we determine individuals are associated with the DPRK, we refer those cases to law enforcement for criminal investigation. We also work directly with the U.S. State Department and other agencies, including through multilateral initiatives like the U.S.–Japan–Republic of Korea Trilateral Diplomatic Working Group on DPRK Cyber Threats, which Coinbase joined in June 2026 to help coordinate responses to DPRK cryptocurrency theft, IT worker infiltration, and related cyber activity.
Our Commitment
Threat actors, state-sponsored and otherwise, will keep evolving their tactics, and so will we. We'll continue investing in the people, technology, and partnerships needed to stay ahead of this threat, including relationships with researchers, whose work benefits not just Coinbase, but the entire industry. We'll keep sharing what we learn, collaborating with peer companies and government partners, and building the defenses needed to protect the broader ecosystem.




