Kraken says North Korea-backed hacker posed as job applicant to infiltrate company

Source Cryptopolitan

A North Korea-backed hacker tried to get a job at Kraken to access the company’s systems, the exchange revealed Thursday.

The applicant posed as an engineer and was caught mid-interview after Kraken’s security teams ran a full investigation into the person’s identity and digital trail. The company said the hiring process became an intelligence operation the moment red flags started to show.

According to Kraken, the job application attempt came during a routine recruitment process. However, the situation turned serious when the candidate gave a name different from the one on their resume during the first call and then quickly corrected it. The person’s voice also shifted multiple times during the interview, leading recruiters to believe someone else might’ve been coaching them live.

Kraken uses breach data and email tracing to expose the operation

The applicant had submitted an email that matched one previously flagged by crypto industry contacts who had warned that North Korea’s hacker units were actively applying to companies in the sector. After confirming the match, Kraken’s internal Red Team launched a deeper investigation using OSINT techniques to analyze breach records and data tied to the email account.

That search uncovered a broader network of fake identities. The individual behind the application had created multiple aliases, some of which had already been hired at other companies. The team found work emails tied to these fake names.

One of them belonged to someone on an international sanctions list as a known foreign agent. The fake resume was connected to a GitHub account with a breached email, and the submitted ID appeared altered. The candidate used remote colocated Mac desktops and routed all traffic through a VPN — a setup designed to hide their real location.

Kraken said the ID likely came from a two-year-old identity theft case. At that point, the security team had enough evidence to consider the applicant part of a state-level infiltration campaign — not a solo scammer.

Kraken runs a full sting operation through interview process

Instead of cutting off communication, Kraken’s recruitment and security teams pushed forward with the process. The applicant was moved through various rounds, including infosec skill assessments and identity verifications.

The final interview involved Kraken’s Chief Security Officer Nick Percoco, who met the candidate with a group of other staff members for what the company labeled a “chemistry interview.”

During that call, Nick and his team inserted verification prompts into the conversation. They asked the applicant to confirm their location, show a government ID, and name local restaurants in the city they claimed to live in. The applicant couldn’t keep up.

They hesitated, gave unclear answers, and failed basic questions about their own alleged hometown. The performance collapsed under pressure, revealing that the applicant had no real knowledge of the location they claimed or the identity they were using.

At the end of the interview, Kraken said it was clear this wasn’t a real applicant. It was a foreign-backed imposter using a fake identity to try to gain insider access to the crypto company.

Nick confirmed the incident in a public statement, saying: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto or U.S. corporate issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.”

Kraken said they were releasing the full details of the case to warn other crypto firms that traditional hiring pipelines are now being used as infiltration tools by foreign governments. The exchange also noted that North Korea-linked hackers had stolen over $650 million from crypto firms in 2024, with job application schemes becoming a new trend.

Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin ETF Investors Face 8% Losses as $3 Billion Exits Market in Two WeeksUS spot Bitcoin ETF buyers are essentially the very investors expected to provide a stable, long-term bid for the pioneer crypto. However, data shows that these players are now sitting on mounting unr
Author  Beincrypto
Feb 03, Tue
US spot Bitcoin ETF buyers are essentially the very investors expected to provide a stable, long-term bid for the pioneer crypto. However, data shows that these players are now sitting on mounting unr
placeholder
MicroStrategy Faces Catastrophic Risk as Bitcoin Falls to $60,000MicroStrategy is under renewed market pressure after Bitcoin slid to $60,000, pushing the company’s vast crypto treasury deeper below its average acquisition cost and reigniting concerns about balance
Author  Beincrypto
Feb 06, Fri
MicroStrategy is under renewed market pressure after Bitcoin slid to $60,000, pushing the company’s vast crypto treasury deeper below its average acquisition cost and reigniting concerns about balance
placeholder
Bitcoin Slips Below $70,000 Support, Risk of 37% Drop EmergesBitcoin has entered a critical phase after its recent correction dragged the price toward the $70,000 level. Viewed through a macro lens, this move has exposed BTC to elevated downside risk. Several o
Author  Beincrypto
Feb 06, Fri
Bitcoin has entered a critical phase after its recent correction dragged the price toward the $70,000 level. Viewed through a macro lens, this move has exposed BTC to elevated downside risk. Several o
placeholder
Risks Rise for Bitcoin, Gold, and Silver as Goldman Sachs Warns $80 Billion in Stock SellingGlobal markets may be entering a new phase of volatility after Goldman Sachs warned that systematic funds could offload tens of billions of dollars in equities in the coming weeks.This wave of selling
Author  Beincrypto
11 hours ago
Global markets may be entering a new phase of volatility after Goldman Sachs warned that systematic funds could offload tens of billions of dollars in equities in the coming weeks.This wave of selling
placeholder
Fed to enter gradual money-printing phase, says Lyn AldenLyn Alden says the Federal Reserve is likely entering a gradual phase of money printing rather than aggressive stimulus.
Author  Cryptopolitan
11 hours ago
Lyn Alden says the Federal Reserve is likely entering a gradual phase of money printing rather than aggressive stimulus.
goTop
quote