cryptd.in

另类 LinkedIn 适合加密人才

North Korean Devs Used Fake Identities to Steal From Crypto Project: ZachXBT

Blockchain investigator ZachXBT has released information regarding North Korean developers who allegedly stole $1.3 million from a project’s treasury.

The theft was carried out when the devs, who had been hired using fake identities, injected malicious code into the system, which allowed the unauthorized transfer of funds.

ZachXBT Uncovers Crypto Workers Scheme

ZachXBT explained on X that the stolen funds were initially sent to a theft address and bridged from Solana to Ethereum through the deBridge platform. The funds, 50.2 ETH, were deposited into Tornado Cash, a crypto mixer that obscures transaction trails. After that, 16.5 ETH was transferred to two exchanges.

1/ Recently a team reached out to me for assistance after $1.3M was stolen from the treasury after malicious code had been pushed.

Unbeknownst to the team they had hired multiple DPRK IT workers as devs who were using fake identities.

I then uncovered 25+ crypto projects with… pic.twitter.com/W7SgY97Rd8

— ZachXBT (@zachxbt) August 15, 2024

According to ZachXBT, since June 2024, North Korean IT workers have infiltrated over 25 crypto projects using multiple payment addresses. He noted that there could be a single entity in Asia, likely based in North Korea, receiving between $300,000 to $500,000 each month while employing at least 21 workers across different crypto projects.

Further analysis noted that before this case, $5.5 million had been funneled into an exchange deposit address tied to payments made to North Korean IT workers from July 2023 to July 2024. These payments were linked to Sim Hyon Sop, an individual sanctioned by the US Office of Foreign Assets Control (OFAC).

ZachXBT’s investigation looked deeper into the several errors and unusual patterns made by the malicious actors. There were IP overlaps between developers allegedly based in the US and Malaysia and accidental leaks of alternate identities during recorded sessions.

Following the incident, ZackXBT contacted the affected projects and advised them to review their logs and do more intensive background checks. He also noted several red flags that teams can monitor, such as referrals for roles from other developers, work history inconsistency, and highly polished resumes or GitHub profiles.

North Korean Cybercrime Surge

Meanwhile, groups linked to North Korea have long been associated with cybercrime. Their tactics often include phishing schemes, exploiting software vulnerabilities, unauthorized system access, private key theft, and even infiltrating organizations in person.

One of its most infamous organizations, Lazarus Group, allegedly stole over $3 billion in crypto assets from 2017 to 2023.

In 2022, the US government warned about the surging number of North Korean workers getting into freelance tech roles, especially those in the crypto sector.

职位 North Korean Devs Used Fake Identities to Steal From Crypto Project: ZachXBT 首次出现在 加密土豆.


评论

发送留言

發佈留言必須填寫的電子郵件地址不會公開。 必填欄位標示為 *

最新信息

热门类别

搜索网站

热门故事

标签

#AlexeyPertsev (1) #BidenCryptoBan (1) #BidenElection (1) #BinanceVsCoinbase (1) #Bitcoin (377) #BitcoinETF (3) #itcoinFundamentals (1) # 比特币处理 (1) # 比特币价格 (5) # 比特币价格水平 (1) #BitcoinPump (1) #BitcoinReserve (1) #BitcoinSurge (1) #itcoinTop (1) #Bitfinex (1) #Bitwise (1) #BracebridgeCapital (1) #BRC20Tokens (1) #BTC 收购 (1) 1TP5 看涨预测 (1) #BullishSentiment (1) #C 中国矿业 (1) #CPIPreview (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #CryptoMania (1) #CryptoMarket (4) #CryptoPrediction (1) #CryptoPredictions (1) #CryptoRegulation (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoUncertainty (1) #DerivativeJump (1) #Dogecoin (65) #ogecoinGains (1) #ogecoinVolume (1) #DutchCourt (2) #ECommerce (1) #El萨尔瓦多比特币 (1) #E以太坊 (64) #EthereumPain (1) #E以太坊价格 (1) #ExpertOpinion (1) #FedRateCut (1) #FiatCurrency (1) #F 财务影响 (1) #F 财务隐私 (1) #FirmShutdown (1) #FrozenAccounts (1) #IllicitFunds (1) #InflationData (1) #Investment (1) #InvestmentLoss (1) #JapaneseFirm (1) #L LegalAction (1) #L 法律影响 (1) #Legislation (1) #LightningNetwork (1) #M 市场分析 (3) #M 市场监测 (1) #M 市场预测 (1) #M 市场预测 (1) #M 市场投影 (1) #M 市场支持 (1) #M 市场波动性 (1) #M 婚姻 (1) #MemeCoin (5) #MemeCoins (2) #Miner 盈利能力 (1) #M 洗钱 (2) #MtGox (3) #朝鲜加密货币 (1) #诺沃格拉茨预测 (1) 1TP5价格里程碑 (1) #P 价格预测 (2) 1TP5价格问题 (1) #PriceSurge (1) #PrisonSentence (1) # 量化分析 (1) #R 监管压力 (1) #SECA Anti-Crypto (1) #ShibaInu (5) #SocialBuzz (1) #T 技术分析 (1) #Toncoin (3) #T 龙卷风现金 (3) #T 龙卷风现金发展项目 (1) #T 龙卷风现金开发者 (1) #UKCrypto (1) #UpsidePotential (1) #USCongress (1) #WyomingLand (1) #XRPPrice (1) #XRPupswing (1)

实用链接

我发现了一些有用的链接,希望与大家分享。