North Korean Hackers Target Crypto Projects Using Fake Profiles

North Korean hackers stole $680,000 by infiltrating crypto projects using fake identities and Google tools, with connections to previous major heists revealed through blockchain analysis.

North Korean Hackers Target Crypto Projects Using Fake Profiles
Facebook X LinkedIn Bluesky WhatsApp
de flag en flag es flag fr flag nl flag pt flag

North Korean Hackers Infiltrate Crypto Projects via Fake Identities

A team of North Korean IT operatives has been exposed for infiltrating cryptocurrency projects using sophisticated deception tactics. Blockchain investigator ZachXBT revealed the group used fake profiles, Google tools, and rented computers to steal $680,000 in June 2025.

Elaborate Identity Fraud

The six-member hacking team maintained 31 false identities using stolen government IDs, phone numbers, and purchased LinkedIn/Upwork accounts. One member even applied to Polygon Labs posing as a former Chainlink and OpenSea employee, with scripted interview responses.

Freelance Platforms as Attack Vectors

Posing as blockchain developers, the hackers secured positions through Upwork using remote access tools like AnyDesk and VPNs to conceal their location. Google Drive and Chrome were utilized for task management, scheduling, and communication via translation tools.

Connections to Major Heists

Evidence links their cryptocurrency wallet to the $680,000 Favrr marketplace hack. Their search history revealed technical interests including ERC-20 token functionality on Solana and European AI companies.

Security Warnings and Sanctions

ZachXBT warns inadequate vetting enables such breaches. The U.S. Treasury recently sanctioned two individuals and four companies tied to North Korean IT infiltration networks targeting crypto businesses.

Related

Crypto Heists and Wallet Security in 2025: How to Protect Your Digital Assets
Crypto
AI relevance 94.4%

Crypto Heists and Wallet Security in 2025: How to Protect Your Digital Assets

The article discusses the increasing threat of crypto heists in 2025, focusing on the ByBit attack, and provides...

Crypto Sanctions: How Nations Bypass or Enforce Digital Asset Rules
Crypto
AI relevance 88.9%

Crypto Sanctions: How Nations Bypass or Enforce Digital Asset Rules

Nations like Russia, Iran, and North Korea are increasingly using cryptocurrency to bypass international sanctions,...

Crypto Scams Evolve: AI Fraud & Sophisticated Tactics Surge
Crypto
AI relevance 83.3%

Crypto Scams Evolve: AI Fraud & Sophisticated Tactics Surge

Cryptocurrency scams are using AI deepfakes, voice cloning, and sophisticated social engineering to steal over $500M...

South America Emerges as Global Crypto Powerhouse
Crypto
AI relevance 77.8%

South America Emerges as Global Crypto Powerhouse

South American nations lead global crypto adoption with favorable regulations, renewable mining energy, and...

SEC Approves Grayscale's First Multi-Crypto ETF with 5 Assets
Crypto
AI relevance 72.2%

SEC Approves Grayscale's First Multi-Crypto ETF with 5 Assets

SEC approves Grayscale's first multi-crypto ETF with Bitcoin, Ethereum, XRP, Solana, and Cardano, marking historic...

Crypto Lenders Face Liquidity Squeeze Amid Defaults
Crypto
AI relevance 66.7%

Crypto Lenders Face Liquidity Squeeze Amid Defaults

Crypto lending platforms face severe liquidity strains due to borrower defaults, prompting new regulations from FDIC...