North Korean Hackers Target Crypto Projects Using Fake Profiles

North Korean hackers stole $680,000 by infiltrating crypto projects using fake identities and Google tools, with connections to previous major heists revealed through blockchain analysis.

north-korean-hackers-crypto-fake-profiles
Facebook X LinkedIn Bluesky WhatsApp
de flag en flag es flag fr flag nl flag pt flag

North Korean Hackers Infiltrate Crypto Projects via Fake Identities

A team of North Korean IT operatives has been exposed for infiltrating cryptocurrency projects using sophisticated deception tactics. Blockchain investigator ZachXBT revealed the group used fake profiles, Google tools, and rented computers to steal $680,000 in June 2025.

Elaborate Identity Fraud

The six-member hacking team maintained 31 false identities using stolen government IDs, phone numbers, and purchased LinkedIn/Upwork accounts. One member even applied to Polygon Labs posing as a former Chainlink and OpenSea employee, with scripted interview responses.

Freelance Platforms as Attack Vectors

Posing as blockchain developers, the hackers secured positions through Upwork using remote access tools like AnyDesk and VPNs to conceal their location. Google Drive and Chrome were utilized for task management, scheduling, and communication via translation tools.

Connections to Major Heists

Evidence links their cryptocurrency wallet to the $680,000 Favrr marketplace hack. Their search history revealed technical interests including ERC-20 token functionality on Solana and European AI companies.

Security Warnings and Sanctions

ZachXBT warns inadequate vetting enables such breaches. The U.S. Treasury recently sanctioned two individuals and four companies tied to North Korean IT infiltration networks targeting crypto businesses.

Related

north-korean-hackers-axios-breach-2026
Crypto

North Korean Hackers Attack Axios: Supply Chain Breach Explained | Cybersecurity

North Korean hackers compromised the Axios npm package on March 31, 2026, affecting thousands of developers...

crypto-sanctions-nations-digital-assets
Crypto

Crypto Sanctions: How Nations Bypass or Enforce Digital Asset Rules

Nations like Russia, Iran, and North Korea are increasingly using cryptocurrency to bypass international sanctions,...

crypto-scams-ai-fraud-tactics-surge
Crypto

Crypto Scams Evolve: AI Fraud & Sophisticated Tactics Surge

Cryptocurrency scams are using AI deepfakes, voice cloning, and sophisticated social engineering to steal over $500M...

crypto-heists-wallet-security-2025
Crypto

Crypto Heists and Wallet Security in 2025: How to Protect Your Digital Assets

The article discusses the increasing threat of crypto heists in 2025, focusing on the ByBit attack, and provides...

digital-yuan-cbdc-overhaul-2026
Crypto

China's Digital Yuan Overhaul: CBDC 2.0 Reshapes Global Finance

China's upgraded digital yuan framework took effect Jan 1, 2026, reclassifying e-CNY as deposit money with interest....