Researchers from BCA LTD, NorthScan and ANY.RUN built a fake DeFi startup called Ballena Azul LTD and hired suspected North Korean IT workers into a controlled virtual environment, allowing them to watch the operatives from inside after they passed interviews. The developers, described in the report as suspected members of Famous Chollima linked to Lazarus Group, allegedly submitted forged U.S. credentials including driver’s licenses, stolen Social Security numbers, and accounts at Lead Bank, Citibank and Wise. Metadata on one license showed it had been processed with Google Gemini and carried a SynthID watermark. The researchers said the workers relied heavily on ChatGPT for coding and assignments, used live translation tools during interviews and standups, and operated through infrastructure including AstrillVPN exit nodes, Vultr and Gorilla Servers, and cryptocurrency wallets with transaction history. The report said the scheme is not just a hiring risk because once inside, operatives can gain legitimate access to code, systems, intellectual property and trusted business processes. The findings add to broader concerns over North Korean infiltration of crypto firms, with TRM Labs attributing 76% of 2026 crypto hack losses through April to DPRK crews and theft in 2025 reaching $2 billion. The existing reporting also said a Wall Street Journal investigation found North Korean operatives infiltrated at least eight U.S. companies, while U.S. Treasury data cited by researchers put 2024 proceeds from the remote-worker scheme at nearly $800 million.