BPOI Banner
North Korean Devs Used Fake Identities to Steal From Crypto Project: ZachXBT North Korean Devs Used Fake Identities to Steal From Crypto Project: ZachXBT

North Korean Devs Used Fake Identities to Steal From Crypto Project: ZachXBT

Blockchain investigator ZachXBT has released information regarding North Korean developers who allegedly stole $1.3 million from a project’s treasury.

The theft was carried out when the devs, who had been hired using fake identities, injected malicious code into the system, which allowed the unauthorized transfer of funds.

ZachXBT Uncovers Crypto Workers Scheme

ZachXBT explained on X that the stolen funds were initially sent to a theft address and bridged from Solana to Ethereum through the deBridge platform. The funds, 50.2 ETH, were deposited into Tornado Cash, a crypto mixer that obscures transaction trails. After that, 16.5 ETH was transferred to two exchanges.

According to ZachXBT, since June 2024, North Korean IT workers have infiltrated over 25 crypto projects using multiple payment addresses. He noted that there could be a single entity in Asia, likely based in North Korea, receiving between $300,000 to $500,000 each month while employing at least 21 workers across different crypto projects.

Further analysis noted that before this case, $5.5 million had been funneled into an exchange deposit address tied to payments made to North Korean IT workers from July 2023 to July 2024. These payments were linked to Sim Hyon Sop, an individual sanctioned by the US Office of Foreign Assets Control (OFAC).

ZachXBT’s investigation looked deeper into the several errors and unusual patterns made by the malicious actors. There were IP overlaps between developers allegedly based in the US and Malaysia and accidental leaks of alternate identities during recorded sessions.

Following the incident, ZackXBT contacted the affected projects and advised them to review their logs and do more intensive background checks. He also noted several red flags that teams can monitor, such as referrals for roles from other developers, work history inconsistency, and highly polished resumes or GitHub profiles.

North Korean Cybercrime Surge

Meanwhile, groups linked to North Korea have long been associated with cybercrime. Their tactics often include phishing schemes, exploiting software vulnerabilities, unauthorized system access, private key theft, and even infiltrating organizations in person.

One of its most infamous organizations, Lazarus Group, allegedly stole over $3 billion in crypto assets from 2017 to 2023.

In 2022, the US government warned about the surging number of North Korean workers getting into freelance tech roles, especially those in the crypto sector.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER 2024 at BYDFi Exchange: Up to $2,888 welcome reward, use this link to register and open a 100 USDT-M position for free!



Source link

Wayne Jones

https://cryptopotato.com/north-korean-devs-used-fake-identities-to-steal-from-crypto-project-zachxbt/

2024-08-16 23:45:13

bitcoin
Bitcoin (BTC) $ 91,061.40 2.40%
ethereum
Ethereum (ETH) $ 3,174.19 3.59%
tether
Tether (USDT) $ 1.00 0.34%
solana
Solana (SOL) $ 218.34 3.03%
bnb
BNB (BNB) $ 629.11 2.70%
xrp
XRP (XRP) $ 1.14 30.28%
dogecoin
Dogecoin (DOGE) $ 0.370404 1.37%
usd-coin
USDC (USDC) $ 1.00 0.32%
staked-ether
Lido Staked Ether (STETH) $ 3,171.53 3.98%
cardano
Cardano (ADA) $ 0.763381 16.07%
tron
TRON (TRX) $ 0.202082 8.13%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 4.33%
the-open-network
Toncoin (TON) $ 5.71 7.19%
avalanche-2
Avalanche (AVAX) $ 35.41 9.98%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,764.63 3.27%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 90,660.29 1.58%
sui
Sui (SUI) $ 3.74 10.58%
weth
WETH (WETH) $ 3,172.85 3.47%
pepe
Pepe (PEPE) $ 0.000022 3.58%
chainlink
Chainlink (LINK) $ 14.36 6.52%
bitcoin-cash
Bitcoin Cash (BCH) $ 450.35 4.83%
polkadot
Polkadot (DOT) $ 5.44 9.15%
near
NEAR Protocol (NEAR) $ 6.00 10.43%
leo-token
LEO Token (LEO) $ 7.63 0.91%
litecoin
Litecoin (LTC) $ 90.30 6.89%
aptos
Aptos (APT) $ 12.24 2.54%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,349.09 3.97%
uniswap
Uniswap (UNI) $ 9.02 10.54%
stellar
Stellar (XLM) $ 0.177087 27.30%
usds
USDS (USDS) $ 0.994427 0.66%
internet-computer
Internet Computer (ICP) $ 9.34 14.81%
crypto-com-chain
Cronos (CRO) $ 0.163283 0.14%
bittensor
Bittensor (TAO) $ 530.43 5.04%
ethereum-classic
Ethereum Classic (ETC) $ 25.88 13.89%
dogwifcoin
dogwifhat (WIF) $ 3.71 3.12%
kaspa
Kaspa (KAS) $ 0.144662 10.24%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.30 5.45%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.420069 13.79%
dai
Dai (DAI) $ 1.00 0.39%
hedera-hashgraph
Hedera (HBAR) $ 0.088079 26.91%
whitebit
WhiteBIT Coin (WBT) $ 22.16 0.21%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.39%
blockstack
Stacks (STX) $ 1.96 6.80%
bonk
Bonk (BONK) $ 0.000041 9.46%
render-token
Render (RENDER) $ 7.02 5.96%
monero
Monero (XMR) $ 147.70 0.87%
filecoin
Filecoin (FIL) $ 4.45 10.28%
okb
OKB (OKB) $ 44.37 1.89%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.64%
arbitrum
Arbitrum (ARB) $ 0.655179 11.82%