Hiding In Plain Sight: Crypto Investigation Reveals How North Korean Hackers Infiltrated The Industry

Share This Post

A crypto investigation recently deep-dived into one of the industry’s largest problems, revealing its extent might be larger than suspected. The report exposed how North Korean hackers have targeted and infiltrated the sector, presenting many legal and cybersecurity risks for companies and investors.

DPRK Infiltration Targets The Whole Industry

CoinDesk recently published an investigation detailing how North Koreans have infiltrated the industry, finding that over a dozen crypto companies had fallen victim to the country’s tactics to bypass sanctions and receive money from these projects.

The report revealed that several companies, including well-established projects like Fantom, Injective, Yearn Finance, ZeroLend, and Sushi, had inadvertently hired IT workers from the Democratic People’s Republic of Korea (DPRK).

Moreover, it exposed the extent of the problem as the interviews with several founders, industry experts, and blockchain researchers showed that the infiltration is “far more prevalent” than expected.

During the investigation, most hiring management teams consulted revealed they had interviewed and hired suspected DPRK developers or knew someone who had.

Blockchain developer Zaki Manian disclosed he unknowingly hired two North Korean IT workers in 2021 to help develop the Cosmos Hub blockchain. He claimed that “everyone is struggling to filter out these people” as the probability of a job applicant being from the DPRK “is greater than 50% across the entire industry.”

On-chain investigator ZachXBT unveiled the North Korean chain of exploits in August, sharing he had discovered over 25 crypto projects with DPRK-linked developers that have been active since June 2024.

The crypto sleuth shared the names and addresses of 21 IT workers who had infiltrated the industry in just those three months. Additionally, he uncovered that North Korea was “receiving $300K – $500K / month from working at 25+ projects at once by using fake identities.”

Crypto Hacks Are Not Like Hollywood Movies

The report explained that North Korean cyberattacks “don’t tend to resemble the Hollywood version of hacking.” Instead, the hackers tend to involve some version of social engineering, earning the team’s trust to obtain access to the project’s private keys, usually through a malicious link.

Taylor Monahan, Product Manager at MetaMask, stated: “To date, we have never seen DPRK do, like, a real exploit. It’s always social engineering, and then compromise the device, and then compromise the private keys.”

The North Korean developers use fake documentation to disguise their real nationality, as hiring workers from the DPRK is prohibited in many countries due to sanctions. After being hired, the malicious actors initially do a good job to earn their employers’ trust.

However, work inconsistencies and discrepancies in their story begin to surface as time passes, making the crypto companies realize they have been targeted in a coordinated attack. Sometimes, teams discover they have been working with more than one individual who presented as one person or that several of their employees are all one person instead.

As reported by Bitcoinist, the Ethereum Layer-2 NFT gaming platform Munchables fell victim to an attack of this kind. In March, the project lost, and later recovered, over $60 million in crypto after a developer turned hacker.

The heist was revealed to be an inside job and was linked by several industry figures like Laura Shin and ZachXBT to the North Korean government. Moreover, it was suspected that four of the developers in the team were all one person.

Ultimately, the investigation showed that several crypto projects that employed DPRK IT workers later fell victim to hacks, including Sushi in 2021 and, most recently, Delta Primes in September 2024.

Crypto

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Crypto Analyst Says Solana-Based BONK Is In Prime Position For Legendary Rally

Lately, top meme based cryptocurrencies like Shiba Inu (SHIB) and Pepe (PEPE) have been witnessing a spike in their prices This bullish trend appears to have extended to Solana based meme coin Bonk

Analysis Reveals Possible 51% Attacks by Satoshi on Bitcoin in Early 2009

A social media post by an X account named “Wicked” presents claims that Satoshi Nakamoto may have conducted 51% attacks on the Bitcoin blockchain in May 2009 Wicked speculated that

Japan’s Metaplanet’s Bitcoin Holdings Rise to 530 BTC After Pulling Off Mind-Blowing Strategy

According to the latest announcement from Japanese investment firm Metaplanet Inc, its Bitcoin holdings have surged, rising to 530717 BTC as of October 3 As revealed by the Tokyo-listed company, this

Polymarket trading volume, users surge amid US election anticipation, Middle East tensions

Blockchain-based prediction platform Polymarket reached new heights in September, reporting $53351 million in trading volume as anticipation builds for the 2024 US presidential election and major

Pro-XRP Lawyer Predicts When The Ripple Vs. SEC Appeal Process Will End

On Wednesday, October 2, the United States Securities and Exchange Commission (SEC) took a formal step in extending the XRP lawsuit with Ripple by filing a Notice of Appeal of Judge Torres’s ruling

Ripple partners with Mercado Bitcoin to boost cross-border payments in Brazil

Ripple has partnered with Mercado Bitcoin, the largest crypto exchange in Latin America, to enhance cross-border payments in Brazil using its end-to-end payments solution that leverages blockchain