TL;DR - Paying a remote crypto freelancer who turns out to be a North Korean IT worker can breach OFAC sanctions even if you had no idea, so screen the wallet before you send funds.
Hiring a developer online has never been easier, and that is exactly the problem. North Korea runs a large network of IT workers who pose as ordinary remote freelancers, win contracts under false identities, and route their crypto wages back to the regime. If you pay one, the legal exposure lands on you, not on them. This guide explains how the scheme works and how to check a contractor's wallet before money leaves your account.
Who are DPRK IT workers and why are they a sanctions risk?
DPRK is shorthand for North Korea. For years the country has placed thousands of skilled software engineers in remote jobs at companies that believe they are hiring freelancers in other countries. The workers use stolen or borrowed identities, route their traffic through VPNs, and sometimes rely on a paid helper inside the United States to run a laptop farm that masks their true location.
The wages do not stay with the worker. US Treasury actions describe schemes that channeled close to 800 million dollars to the regime in a single year, much of it paid in crypto. Because that money helps fund weapons programs, the Treasury's OFAC has sanctioned a string of individuals, front companies, and the financial facilitators who cash the payments out. A wallet tied to that network is, in effect, a sanctioned destination.
A crypto wage paid to a fake freelancer can travel straight to a sanctioned North Korea wallet.
Can paying a freelancer really break sanctions law?
Yes. US sanctions rules carry strict liability for civil violations, which means you can be held responsible even when you did not know who was on the other end. A payment to a person or wallet tied to North Korea can count as a prohibited transaction on its own.
The risk is not only a fine. Once your company has paid a sanctioned worker, every later move of those funds carries the same taint, and a bank or exchange that spots the link can freeze the balance and file a report. Employers have also faced data theft and extortion after a planted worker gained access to internal systems. The same care that applies before screening a wallet before accepting a payment applies just as much before sending one.
What are the warning signs of a DPRK IT worker?
No single clue is proof, but a cluster of these signs should slow a hire down:
Reluctance to appear on camera, or a video feed that never quite matches the stated identity.
A location or bank that does not line up with the worker's claimed country.
A request to be paid to a fresh crypto wallet, or to switch payout addresses often.
Documents that look reused, and references that cannot be reached directly.
Unusual log-in times and remote-access tools that hint at a shared or proxied machine.
Treat a payout wallet as part of the identity check, not an afterthought. The address is the one detail a worker cannot fake, because its history lives on a public chain that anyone can read.
How do you screen a contractor's wallet before paying?
Start with the free, manual checks, then widen the net:
Search the payout address on the OFAC Sanctions Search portal to confirm it is not directly listed.
Open the address on a block explorer such as Etherscan and look for a sanctioned-entity label on any direct counterparty.
Trace where the wallet's funds came from and went to, watching for links to mixers, sanctioned exchanges, or known North Korea-attributed clusters.
Manual tracing runs out of road fast. A block explorer shows only direct, single-chain labels, so it misses multi-hop links and exposure on other networks. Rather than checking one source at a time, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six other chains in a single pass. For the wider pattern of North Korea-linked risk, the guide on checking a wallet for Lazarus Group exposure covers how stolen funds spread downstream.
Screen the payout wallet first, then pay a clean address or pause a flagged one.
What should you do if you already paid one?
Do not try to quietly move or recover the funds, because that can make the problem worse. Stop further payments to the address right away and preserve everything you have.
Save the contract, the chat logs, the invoices, and the transaction hashes in one place.
Screen the payout wallet to document the exposure and the hops involved.
Speak to counsel about a voluntary disclosure to OFAC, which can reduce penalties.
Review what systems the worker could reach, and rotate any credentials they touched.
A clear, honest timeline of how the payment happened is your strongest asset if a regulator or a bank ever asks. Screening turns a vague worry into a documented record you can act on.
FAQ
Is it illegal to hire a North Korean developer by accident?
Paying a worker tied to North Korea can be a sanctions violation even without intent, because US civil sanctions carry strict liability. You are unlikely to face the harshest penalties for an honest mistake you report, but the payment itself is still prohibited, so screening first is the safer path.
Can checking a payout wallet really tell me the worker is from the DPRK?
Not on its own. A wallet screen shows sanctions, mixer, and stolen-funds exposure, which is strong evidence of risk, but it is one signal among several. Combine it with identity checks, a live video call, and the behavioral warning signs.
Does this risk apply to small businesses and individuals?
Yes. The schemes target companies of every size, including solo founders hiring a single contractor. Sanctions law does not have a minimum payment threshold, so a one-off crypto invoice can still create exposure.
What if the worker insists on a brand-new wallet with no history?
A fresh address with no transaction history is a flag in itself, because it removes the trail you would otherwise check. Ask why, request a longer-lived address, and screen whatever wallet finally receives the funds before and after payment.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.