ZachXBT uncovers $16.58M in direct payments to North Korean IT workers

來源 Cryptopolitan

On-chain investigator ZachXBT intercepted payments made directly to North Korean IT workers. The payroll suggests more crypto projects are exposed to potential hacks from their own teams, or bugs and backdoors introduced to smart contracts.

A new investigation by ZachXBT showed significant payrolls still coming to IT workers uncovered as DPRK agents. The project teams have hired international IT workers, often under cover with fake profiles. Currently, a series of profiles are getting exposed for infiltrating blockchain, Web3 and DeFi projects. 

ZachXBT discovered $16.58M in payments since January 2025, pointing to hundreds of jobs in crypto projects. 

The intercepted addresses and payrolls suggest some of the IT workers have used disguised identities and fake locations. The recent unveiling of additional wallets and identities arrived after the US Department of Justice cracked down on a recent IT scheme targeting US companies.

The risks involve the theft of crypto, attacks against tokens, draining liquidity, in addition to exposing and stealing sensitive information. 

ZachXBT’s discoveries also follow recent doxxing of DPRK IT workers, who turned out to be highly active meme token creators or joined existing meme token teams. Other investigations involve attempts to present as civil engineers or even seek out roles as interior designers. The fake teams often use AI as a research tool and to disguise their identity.

North Korean IT teams were outed in voluntary investigations

For some, North Korean hackers in crypto teams are still a conspiracy theory. Most of the recent discoveries are linked to OSINT efforts and real-life tracking and doxxing. 

ZachXBT also adds wallet monitoring, often linking known IT workers with prominent social media profiles based on their wallet connections to known DPRK hacker wallet clusters. ZachXBT warned that North Korean IT workers are infiltrating traditional tech companies as well, but crypto projects often allow for easier tracking, especially if their payrolls are on-chain. 

For now, ZachXBT has not announced the names of crypto projects that were most affected by hackers. Previously, even established protocols like Waves have reported compromised smart contracts due to hiring unvetted IT workers. 

North Korean IT workers also  pose as crypto influencers

Earlier in June, investigators also pointed out several high-profile crypto influencers linked to older meme and NFT projects were also connected to suspicious wallet clusters. Some of the addresses observed by ZachXBT were also flagged as being connected to the Favvr NFT project.

DPRK hackers often do not stay long with projects, but their involvement is risky even with a short stint. DPRK hackers can have multiple roles in projects, including access to multi-sig wallets or other key responsibilities. Since crypto projects only perform audits months or years apart, some DeFi platforms, meme tokens, and other apps may hold hidden risks for exploits.

ZachXBT also notes that the hackers are mostly drawn to MEXC, as well as US-based exchanges including Robinhood and Coinbase. Binance, one of the widely used markets, is now unsuitable, as it has a track record of freezing funds and assisting authorities in intercepting suspicious accounts. The North Korean IT workers often resort to USDC, though trying to conceal the transactions as the stablecoin can be frozen.

Your crypto news deserves attention - KEY Difference Wire puts you on 250+ top sites

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
AI再掀高潮!Meta股價狂飆,緊隨輝達創下歷史新高TradingKey - Meta宣佈重組AI部門,提振其股價盤中跳漲,創下新的記錄。當地時間週一(6月30日),Meta (META)股價盤中跳漲至747.9美元,創下歷史新高。截止收盤,該股收漲0.61%,報738.09美元。(哪些機構持有Meta股票,可查看「明星投資者」)【Meta股價走勢圖,來源:TradingView】Meta股價上漲主要是受該公司的人工智慧業務推動。Meta Plat
作者  TradingKey
7 月 01 日 週二
TradingKey - Meta宣佈重組AI部門,提振其股價盤中跳漲,創下新的記錄。當地時間週一(6月30日),Meta (META)股價盤中跳漲至747.9美元,創下歷史新高。截止收盤,該股收漲0.61%,報738.09美元。(哪些機構持有Meta股票,可查看「明星投資者」)【Meta股價走勢圖,來源:TradingView】Meta股價上漲主要是受該公司的人工智慧業務推動。Meta Plat
placeholder
日幣2025年上半年漲9%!7月繼續升值?分析師這樣說2025年上半年,美元/日圓(USD/JPY)累計下跌9%,創下近年來最佳表現。
作者  Alison Ho
7 月 01 日 週二
2025年上半年,美元/日圓(USD/JPY)累計下跌9%,創下近年來最佳表現。
placeholder
川普「大而美」法案助力黃金上漲!匯豐:2025年下半年金價或承壓市場對美國財政狀況感到擔憂,進而推動黃金價格上漲。7月1日金價一度漲至3358美元/盎司,截至7月2日發稿回落,報3334美元/盎司。
作者  Alison Ho
21 小時前
市場對美國財政狀況感到擔憂,進而推動黃金價格上漲。7月1日金價一度漲至3358美元/盎司,截至7月2日發稿回落,報3334美元/盎司。
placeholder
特斯拉股價再度跳水!川馬關係緊張,交付前景黯淡,抄底機會來了?隨著馬斯克和川普互懟升級,一些投資人擔心,其不斷升級的言論可能會進一步連累特斯拉。
作者  Alison Ho
17 小時前
隨著馬斯克和川普互懟升級,一些投資人擔心,其不斷升級的言論可能會進一步連累特斯拉。
placeholder
英特爾「豪賭」!跳過18A直攻14A,是彎道超車還是自陷巨坑?TradingKey-業界傳出消息,英特爾(INTC)正醞釀對其晶圓廠代工業務進行重大戰略調整,計劃跳過原定的Intel 18A(1.8奈米)工藝,直接推進更先進的14A(1.4奈米)工藝,旨在提升市場競爭力。原本18A對標台積電/三星的2奈米技術,是英特爾重奪製程領先的關鍵節點。但目前看來,該工藝對蘋果、英偉達等大客戶吸引力不足。而14A作為全球最先進的工藝,在能源效率和晶片密度上較18A提升1
作者  TradingKey
15 小時前
TradingKey-業界傳出消息,英特爾(INTC)正醞釀對其晶圓廠代工業務進行重大戰略調整,計劃跳過原定的Intel 18A(1.8奈米)工藝,直接推進更先進的14A(1.4奈米)工藝,旨在提升市場競爭力。原本18A對標台積電/三星的2奈米技術,是英特爾重奪製程領先的關鍵節點。但目前看來,該工藝對蘋果、英偉達等大客戶吸引力不足。而14A作為全球最先進的工藝,在能源效率和晶片密度上較18A提升1
goTop
quote