ZachXBT uncovers $16.58M in direct payments to North Korean IT workers

来源 Cryptopolitan

On-chain investigator ZachXBT intercepted payments made directly to North Korean IT workers. The payroll suggests more crypto projects are exposed to potential hacks from their own teams, or bugs and backdoors introduced to smart contracts.

A new investigation by ZachXBT showed significant payrolls still coming to IT workers uncovered as DPRK agents. The project teams have hired international IT workers, often under cover with fake profiles. Currently, a series of profiles are getting exposed for infiltrating blockchain, Web3 and DeFi projects. 

ZachXBT discovered $16.58M in payments since January 2025, pointing to hundreds of jobs in crypto projects. 

The intercepted addresses and payrolls suggest some of the IT workers have used disguised identities and fake locations. The recent unveiling of additional wallets and identities arrived after the US Department of Justice cracked down on a recent IT scheme targeting US companies.

The risks involve the theft of crypto, attacks against tokens, draining liquidity, in addition to exposing and stealing sensitive information. 

ZachXBT’s discoveries also follow recent doxxing of DPRK IT workers, who turned out to be highly active meme token creators or joined existing meme token teams. Other investigations involve attempts to present as civil engineers or even seek out roles as interior designers. The fake teams often use AI as a research tool and to disguise their identity.

North Korean IT teams were outed in voluntary investigations

For some, North Korean hackers in crypto teams are still a conspiracy theory. Most of the recent discoveries are linked to OSINT efforts and real-life tracking and doxxing. 

ZachXBT also adds wallet monitoring, often linking known IT workers with prominent social media profiles based on their wallet connections to known DPRK hacker wallet clusters. ZachXBT warned that North Korean IT workers are infiltrating traditional tech companies as well, but crypto projects often allow for easier tracking, especially if their payrolls are on-chain. 

For now, ZachXBT has not announced the names of crypto projects that were most affected by hackers. Previously, even established protocols like Waves have reported compromised smart contracts due to hiring unvetted IT workers. 

North Korean IT workers also  pose as crypto influencers

Earlier in June, investigators also pointed out several high-profile crypto influencers linked to older meme and NFT projects were also connected to suspicious wallet clusters. Some of the addresses observed by ZachXBT were also flagged as being connected to the Favvr NFT project.

DPRK hackers often do not stay long with projects, but their involvement is risky even with a short stint. DPRK hackers can have multiple roles in projects, including access to multi-sig wallets or other key responsibilities. Since crypto projects only perform audits months or years apart, some DeFi platforms, meme tokens, and other apps may hold hidden risks for exploits.

ZachXBT also notes that the hackers are mostly drawn to MEXC, as well as US-based exchanges including Robinhood and Coinbase. Binance, one of the widely used markets, is now unsuitable, as it has a track record of freezing funds and assisting authorities in intercepting suspicious accounts. The North Korean IT workers often resort to USDC, though trying to conceal the transactions as the stablecoin can be frozen.

Your crypto news deserves attention - KEY Difference Wire puts you on 250+ top sites

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
2025年美元年中收官:贬值10%创1970年代以来最差H1,下半年继续跌?TradingKey - 随着特朗普高关税政策的影响从提高通胀演变为美国例外论消退和美国资产大撤离,叠加美联储独立性受到质疑和降息预期升温,2025年上半年美元指数意外暴跌超10%,与华尔街2024年底的美元走势预期相去甚远。美元指数(DXY)今年已连续6个月单月下跌,从年初的110左右一度跌破97。截至6月30日,美元指数报97.09,处于近三年低位,上半年以来下跌约11%。【2025年美元指数
作者  TradingKey
6 月 30 日 周一
TradingKey - 随着特朗普高关税政策的影响从提高通胀演变为美国例外论消退和美国资产大撤离,叠加美联储独立性受到质疑和降息预期升温,2025年上半年美元指数意外暴跌超10%,与华尔街2024年底的美元走势预期相去甚远。美元指数(DXY)今年已连续6个月单月下跌,从年初的110左右一度跌破97。截至6月30日,美元指数报97.09,处于近三年低位,上半年以来下跌约11%。【2025年美元指数
placeholder
逢七必涨!美股会打破“7月上涨魔咒”吗? 7月是美股表现最强的月份之一,标普500平均回报率为3.35%。
作者  Alison Ho
7 月 01 日 周二
7月是美股表现最强的月份之一,标普500平均回报率为3.35%。
placeholder
特朗普“大而美”法案助力黄金上涨!汇丰:2025年下半年金价或承压市场对美国财政状况感到担忧,进而推动黄金价格上涨。7月1日金价一度涨至3358美元/盎司,截至7月2日发稿有所回落,报3334美元/盎司。
作者  Alison Ho
21 小时前
市场对美国财政状况感到担忧,进而推动黄金价格上涨。7月1日金价一度涨至3358美元/盎司,截至7月2日发稿有所回落,报3334美元/盎司。
placeholder
美国6月非农前瞻:失业率4.3%为7月降息铺路,美股美债继续涨?TradingKey - 2025年7月3日周四,美国劳工统计局将发布6月非农就业报告,这份就业报告因美国独立纪念日假期提前一日发布。分析认为,特朗普关税的负面影响将在6月劳动力市场数据体现,美联储7月降息概率有望增加,利好美股美债等资产表现。据Factset数据,经济学家预计美国6月非农就业新增人数将从5月的13.9万人降至11.5万;失业率将反弹至4.3%,此前已连续三个月稳定在4.2%的水平
作者  TradingKey
16 小时前
TradingKey - 2025年7月3日周四,美国劳工统计局将发布6月非农就业报告,这份就业报告因美国独立纪念日假期提前一日发布。分析认为,特朗普关税的负面影响将在6月劳动力市场数据体现,美联储7月降息概率有望增加,利好美股美债等资产表现。据Factset数据,经济学家预计美国6月非农就业新增人数将从5月的13.9万人降至11.5万;失业率将反弹至4.3%,此前已连续三个月稳定在4.2%的水平
placeholder
美股行业视角下的参议院版减税法案:晶片股利好,光伏股缓忧TradingKey - 美国参议院于7月1日以一票之差通过了特朗普的减税与支出法案,该版本法案拟对晶片制造商增加税收抵免额度且没有囊括此前市场担忧的对风能和太阳能项目的进口组件关税,晶片股和清洁能源股迎来利好。在参议院版本的「大美丽法案」中,若晶片制造商在现有《晶片与科学法案》剔除的2026年截止日期前在美国兴建新工厂,它们将有资格享受35%的投资税抵免,税收抵免比例高于目前的25%和预期的30
作者  TradingKey
15 小时前
TradingKey - 美国参议院于7月1日以一票之差通过了特朗普的减税与支出法案,该版本法案拟对晶片制造商增加税收抵免额度且没有囊括此前市场担忧的对风能和太阳能项目的进口组件关税,晶片股和清洁能源股迎来利好。在参议院版本的「大美丽法案」中,若晶片制造商在现有《晶片与科学法案》剔除的2026年截止日期前在美国兴建新工厂,它们将有资格享受35%的投资税抵免,税收抵免比例高于目前的25%和预期的30
goTop
quote