{"id":634,"date":"2024-10-03T15:01:37","date_gmt":"2024-10-03T15:01:37","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=634"},"modified":"2024-10-03T15:01:37","modified_gmt":"2024-10-03T15:01:37","slug":"hiding-in-plain-sight-crypto-investigation-reveals-how-north-korean-hackers-infiltrated-the-industry","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=634","title":{"rendered":"Hiding In Plain Sight: Crypto Investigation Reveals How North Korean Hackers Infiltrated The Industry"},"content":{"rendered":"<div>\n<p style=\"font-weight: 400;\">A crypto investigation recently deep-dived into one of the industry\u2019s largest problems, revealing its extent might be larger than suspected. The report exposed how North Korean hackers have targeted and infiltrated the sector, presenting many legal and cybersecurity risks for companies and investors.<\/p>\n<h2 style=\"font-weight: 400;\">DPRK Infiltration Targets The Whole Industry<\/h2>\n<p style=\"font-weight: 400;\">CoinDesk <a href=\"https:\/\/www.coindesk.com\/tech\/2024\/10\/02\/how-north-korea-infiltrated-the-crypto-industry\/\" target=\"_blank\" rel=\"noopener nofollow\">recently<\/a> published an investigation detailing how North Koreans have infiltrated the industry, finding that over a dozen crypto companies had fallen victim to the country\u2019s tactics to bypass sanctions and receive money from these projects.<\/p>\n<p style=\"font-weight: 400;\">The report revealed that several companies, including well-established projects like Fantom, Injective, Yearn Finance, ZeroLend, and Sushi, had inadvertently hired IT workers from the Democratic People\u2019s Republic of Korea (DPRK).<\/p>\n<p style=\"font-weight: 400;\">Moreover, it exposed the extent of the problem as the interviews with several founders, industry experts, and blockchain researchers showed that the <a href=\"https:\/\/bitcoinist.com\/crypto-etf-sector-under-siege-fbi-raises-alarm\/\" target=\"_blank\" rel=\"noopener\">infiltration<\/a> is \u201cfar more prevalent\u201d than expected.<\/p>\n<p style=\"font-weight: 400;\">During the investigation, most hiring management teams consulted revealed they had interviewed and hired suspected DPRK developers or knew someone who had.<\/p>\n<p style=\"font-weight: 400;\">Blockchain developer Zaki Manian disclosed he unknowingly hired two North Korean IT workers in 2021 to help develop the Cosmos Hub blockchain. He claimed that \u201ceveryone is struggling to filter out these people\u201d as the probability of a job applicant being from the DPRK \u201cis greater than 50% across the entire industry.\u201d<\/p>\n<p style=\"font-weight: 400;\">On-chain investigator ZachXBT <a href=\"https:\/\/x.com\/zachxbt\/status\/1824047425822310580\" target=\"_blank\" rel=\"noopener nofollow\">unveiled<\/a> the North Korean chain of exploits in August, sharing he had discovered over 25 crypto projects with DPRK-linked developers that have been active since June 2024.<\/p>\n<p style=\"font-weight: 400;\">The crypto sleuth shared the names and addresses of 21 IT workers who had infiltrated the industry in just those three months. Additionally, he uncovered that North Korea was \u201creceiving $300K \u2013 $500K \/ month from working at 25+ projects at once by using fake identities.\u201d<\/p>\n<h2 style=\"font-weight: 400;\">Crypto Hacks Are Not Like Hollywood Movies<\/h2>\n<p style=\"font-weight: 400;\">The report explained that North Korean cyberattacks \u201cdon\u2019t tend to resemble the Hollywood version of hacking.\u201d Instead, the <a href=\"https:\/\/bitcoinist.com\/chain-of-exploits-investigator-unveils-connection-between-multiple-crypto-hacks\/\" target=\"_blank\" rel=\"noopener\">hackers<\/a> tend to involve some version of social engineering, earning the team\u2019s trust to obtain access to the project\u2019s private keys, usually through a malicious link.<\/p>\n<p style=\"font-weight: 400;\">Taylor Monahan, Product Manager at MetaMask, stated: \u201cTo date, we have never seen DPRK do, like, a real exploit. It\u2019s always social engineering, and then compromise the device, and then compromise the private keys.\u201d<\/p>\n<p style=\"font-weight: 400;\">The North Korean developers use fake documentation to disguise their real nationality, as hiring workers from the DPRK is prohibited in many countries due to sanctions. After being hired, the malicious actors initially do a good job to earn their employers\u2019 trust.<\/p>\n<p style=\"font-weight: 400;\">However, work inconsistencies and discrepancies in their story begin to surface as time passes, making the crypto companies realize they have been targeted in a coordinated attack. Sometimes, teams discover they have been working with more than one individual who presented as one person or that several of their employees are all one person instead.<\/p>\n<p style=\"font-weight: 400;\">As <a href=\"https:\/\/bitcoinist.com\/gaming-platform-security-62m-in-crypto-returned\/\" target=\"_blank\" rel=\"noopener\">reported<\/a> by Bitcoinist, the Ethereum Layer-2 NFT gaming platform Munchables fell victim to an attack of this kind. In March, the project lost, and later recovered, over $60 million in crypto after a developer turned hacker.<\/p>\n<p style=\"font-weight: 400;\">The heist was revealed to be an inside job and was linked by several industry figures like Laura Shin and ZachXBT to the North Korean government. Moreover, it was suspected that four of the developers in the team were all one person.<\/p>\n<p style=\"font-weight: 400;\">Ultimately, the investigation showed that several crypto projects that employed DPRK IT workers later fell victim to hacks, including Sushi in 2021 and, most recently, Delta Primes in September 2024.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"size-large wp-image-327801 aligncenter\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/TOTAL_2024-10-02_14-10-09.png?w=980&amp;resize=980%2C524\" alt=\"Crypto\" width=\"980\" height=\"524\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/TOTAL_2024-10-02_14-10-09.png?w=1102 1102w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/TOTAL_2024-10-02_14-10-09.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/TOTAL_2024-10-02_14-10-09.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/TOTAL_2024-10-02_14-10-09.png?w=980 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/TOTAL_2024-10-02_14-10-09.png?w=750 750w\" sizes=\"(max-width: 980px) 100vw, 980px\"><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A crypto investigation recently deep-dived into one of the industry\u2019s largest problems, revealing its extent might be larger than suspected. The report exposed how North Korean hackers have targeted and infiltrated the sector, presenting many legal and cybersecurity risks for companies and investors. DPRK Infiltration Targets The Whole Industry CoinDesk recently published an investigation detailing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-634","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=634"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/634\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}