Constatum
Compliance

Paying a Contractor in Crypto? Check the Wallet First

Constatum Team5 min read
A single machined metal chain link, with a thin orange line of light along its seam and a small orange checkmark at the joint

Eleven governments published the same warning on the same day. On July 31, 2026, the United States, Japan, South Korea, the United Kingdom, Australia, Canada, France, Germany, Italy, the Netherlands and New Zealand issued a joint alert about North Korean IT workers — people who apply for ordinary remote jobs under borrowed identities, actually do the work, and route the salary back to Pyongyang.

The part that got headlines was the interviews. The alert says these applicants now use real-time AI deepfake video to sit through live calls as someone else. That is a hiring problem, and recruiters are already chewing on it.

The part almost nobody covered is what happens after you hire them. They ask to be paid in crypto.

Why the payment is the legal problem

Hiring someone under a fake name is embarrassing. Paying a wallet that sits on a sanctions list is a violation.

The US Treasury made that concrete on March 12, 2026, when OFAC designated six individuals and two entities over DPRK IT worker fraud. The designation came with 21 cryptocurrency addresses attached to the SDN list, spread across Ethereum, Tron and Bitcoin. Amnokgang Technology Development Company, which manages delegations of overseas IT workers, accounted for seven of them: three Ethereum, four Tron. Yun Song Guk added two Ethereum addresses. Hoang Minh Quang, one Bitcoin address. An existing designation for Sim Hyon Sop picked up eleven more.

Then there is Nguyen Quang Viet, a Vietnamese company director who Treasury says converted roughly $2.5 million into crypto for these workers between mid-2023 and mid-2025. He was the plumbing. Salaries went in as ordinary payments, crypto came out the other end.

Treasury estimates the scheme pulled in close to $800 million in 2024 alone.

Strict liability means what it says

Here is the part that catches small companies off guard. OFAC civil enforcement runs on strict liability. Nobody has to show you knew, or that you were careless, or that you had any reason to suspect anything at all. They only have to show the transaction happened.

In 2026 the ceiling for a civil violation under IEEPA is $377,700, or twice the value of the transaction, whichever is larger. Pay a $6,000 monthly invoice to a listed address twelve times and you have twelve violations, not one.

You will not get a warning first. There is no notification when a wallet you have been paying since spring gets designated in autumn. The SDN list changes, the address saved in your accounting software does not, and nothing in that software is watching.

What the red flags actually look like

Government guidance on this has been consistent for a couple of years now, and the payment tells are unglamorous:

  • The contractor steers away from direct deposit and pushes for crypto or a money transfer service.
  • Payment is requested to an account in someone else's name, with a "friend" or "agency" taking a cut for the use of it.
  • The payout address changes often, or you are asked to split one invoice across two addresses.
  • USDT on Tron comes up constantly. It is cheap, fast and liquid.

None of these prove anything on their own. Plenty of honest freelancers in countries with broken banking prefer stablecoins, and interrogating someone about that is not a compliance program. But a remote hire you have never met in person, a rushed onboarding, and a payout address that keeps moving is a combination worth ten minutes of your attention.

Ten minutes before the first payout

Screening a payout address is the cheapest control you have, and it happens before the money leaves. Paste the address and you find out whether it appears on a sanctions list, whether it has received funds from a mixer, and what sort of counterparties it has already touched. Running the address through a check takes seconds and gives you something you can file.

Keep the result. That is not a small detail. If a bank or a regulator ever asks how you vetted a payee, "we screened the address the day we onboarded them, here is the report" is a very different conversation from "we never thought about it".

Re-run it periodically. Monthly is fine for a recurring contractor. The list moves.

What a clean result does not mean

Be honest about the limits, because most vendors in this space are not.

A brand new wallet with no history screens clean. It has to — there is nothing there to score. Someone generating a fresh address for every invoice will pass every time, and so will a great many legitimate people. Address screening catches known bad addresses and traceable exposure to them. It tells you nothing about who is holding the keys.

So it sits alongside the boring stuff: checking identity documents against a live human, confirming that the person on the video call is the person on the passport, refusing to redirect payments to third parties, and keeping records of all of it. The July 31 alert exists precisely because the identity layer is being beaten by deepfakes. The money layer is the one place where the evidence is public and permanent.

The number that should bother you

Chainalysis put North Korea-linked crypto theft at $2.02 billion in 2025, close to 60% of everything stolen in crypto that year, and roughly $6.75 billion cumulatively. The IT worker scheme is the quiet half of that. No exploit, no bridge hack, no headline. Just invoices.

The Justice Department has been pulling at the thread: a civil forfeiture complaint covering more than $7.7 million in crypto, NFTs and other digital assets tied to the laundering network behind these workers. The State Department alert is blunt about where that leaves employers — contracting with these workers and paying them for services rendered may break the domestic law of several countries, including Japan, the United States and South Korea.

If you hire remote engineers and pay any of them in crypto, you are somewhere in the supply chain those cases describe. Not as a target. As a payer.

You cannot reliably verify a face over a video call anymore. You can verify an address. Do that before the first payment goes out, save what comes back, and look again next month. It costs less than an hour of the contractor's time.

Sources

  1. 1.Treasury Sanctions Facilitators of DPRK IT Worker Fraud Targeting U.S. BusinessesU.S. Department of the Treasury
  2. 2.Specially Designated Nationals List Update — March 12, 2026OFAC
  3. 3.Alert to Countries, Companies, and Other Entities Regarding North Korean IT WorkersU.S. Department of State
  4. 4.Canada, allies express renewed concern over North Korean IT worker schemeCBC News
  5. 5.Department Files Civil Forfeiture Complaint Against Over $7.74M Laundered on Behalf of the North Korean GovernmentU.S. Department of Justice
  6. 6.2025 Crypto Theft Reaches $3.4 BillionChainalysis
  7. 7.Inflation Adjustment of Civil Monetary Penalties (IEEPA maximum: $377,700)Federal Register / U.S. Department of the Treasury
  8. 8.US: Inflation Adjustment for Federal Civil Monetary Penalties Nixed for 2026Baker McKenzie — Sanctions & Export Controls Blog

This article is general information, not legal, tax, financial, or investment advice. Crypto carries risk — do your own research and consult a qualified professional before acting. Constatum makes no warranty as to accuracy or completeness and accepts no liability for decisions made based on it.

Keep reading