• bitcoinBitcoin (BTC) $ 91,224.00
  • ethereumEthereum (ETH) $ 3,110.40
  • tetherTether (USDT) $ 0.998792
  • xrpXRP (XRP) $ 2.05
  • bnbBNB (BNB) $ 903.72
  • usd-coinUSDC (USDC) $ 0.999787
  • tronTRON (TRX) $ 0.299565
  • staked-etherLido Staked Ether (STETH) $ 3,109.20
  • dogecoinDogecoin (DOGE) $ 0.136850
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.386190
  • bitcoin-cashBitcoin Cash (BCH) $ 619.11
  • wrapped-stethWrapped stETH (WSTETH) $ 3,808.47
  • moneroMonero (XMR) $ 639.50
  • whitebitWhiteBIT Coin (WBT) $ 54.89
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 91,012.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,383.58
  • wrapped-eethWrapped eETH (WEETH) $ 3,377.63
  • usdsUSDS (USDS) $ 0.999615
  • chainlinkChainlink (LINK) $ 13.10
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998899
  • leo-tokenLEO Token (LEO) $ 9.07
  • wethWETH (WETH) $ 3,108.40
  • stellarStellar (XLM) $ 0.220317
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 91,249.00
  • suiSui (SUI) $ 1.76
  • zcashZcash (ZEC) $ 399.14
  • ethena-usdeEthena USDe (USDE) $ 0.999051
  • litecoinLitecoin (LTC) $ 76.21
  • avalanche-2Avalanche (AVAX) $ 13.57
  • hyperliquidHyperliquid (HYPE) $ 24.16
  • canton-networkCanton (CC) $ 0.142694
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • hedera-hashgraphHedera (HBAR) $ 0.115148
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.169107
  • usdt0USDT0 (USDT0) $ 0.998830
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999635
  • the-open-networkToncoin (TON) $ 1.73
  • crypto-com-chainCronos (CRO) $ 0.099695
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999952
  • usd1-wlfiUSD1 (USD1) $ 0.999085
  • uniswapUniswap (UNI) $ 5.37
  • polkadotPolkadot (DOT) $ 2.06
  • mantleMantle (MNT) $ 0.948939
  • rainRain (RAIN) $ 0.008700
  • memecoreMemeCore (M) $ 1.67
  • bittensorBittensor (TAO) $ 279.24
  • aaveAave (AAVE) $ 166.90
  • bitget-tokenBitget Token (BGB) $ 3.56
  • pepePepe (PEPE) $ 0.000006
  • tether-goldTether Gold (XAUT) $ 4,590.53
  • okbOKB (OKB) $ 111.13
  • nearNEAR Protocol (NEAR) $ 1.70
  • falcon-financeFalcon USD (USDF) $ 0.996349
  • jito-staked-solJito Staked SOL (JITOSOL) $ 173.43
  • ethereum-classicEthereum Classic (ETC) $ 12.33
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,112.32
  • pax-goldPAX Gold (PAXG) $ 4,605.65
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.205998
  • internet-computerInternet Computer (ICP) $ 3.14
  • ethenaEthena (ENA) $ 0.214377
  • aster-2Aster (ASTER) $ 0.694218
  • solanaWrapped SOL (SOL) $ 138.30
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.151922
  • htx-daoHTX DAO (HTX) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.77
  • binance-staked-solBinance Staked SOL (BNSOL) $ 151.17
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999485
  • worldcoin-wldWorldcoin (WLD) $ 0.558626
  • kucoin-sharesKuCoin (KCS) $ 11.14
  • pump-funPump.fun (PUMP) $ 0.002409
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999606
  • aptosAptos (APT) $ 1.78
  • wbnbWrapped BNB (WBNB) $ 903.67
  • bfusdBFUSD (BFUSD) $ 0.998325
  • hash-2Provenance Blockchain (HASH) $ 0.024411
  • skySky (SKY) $ 0.056605
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,592.39
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999655
  • kaspaKaspa (KAS) $ 0.046887
  • cosmosCosmos Hub (ATOM) $ 2.53
  • ondo-financeOndo (ONDO) $ 0.389450
  • render-tokenRender (RENDER) $ 2.34
  • gatechain-tokenGate (GT) $ 10.29
  • arbitrumArbitrum (ARB) $ 0.202496
  • algorandAlgorand (ALGO) $ 0.130121
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,300.94
  • myx-financeMYX Finance (MYX) $ 5.91
  • midnight-3Midnight (NIGHT) $ 0.065863
  • filecoinFilecoin (FIL) $ 1.47
  • official-trumpOfficial Trump (TRUMP) $ 5.36
  • quant-networkQuant (QNT) $ 72.48
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,802.38
  • story-2Story (IP) $ 2.92
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 91,327.00
  • ignition-fbtcFunction FBTC (FBTC) $ 90,990.00
  • vechainVeChain (VET) $ 0.011318
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 91,276.00
  • nexoNEXO (NEXO) $ 0.955838
  • flare-networksFlare (FLR) $ 0.011254
  • usddUSDD (USDD) $ 0.998676
  • bonkBonk (BONK) $ 0.000010
  • xdce-crowd-saleXDC Network (XDC) $ 0.046167
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • usdtbUSDtb (USDTB) $ 0.999638
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,368.46
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,259.70
  • ousgOUSG (OUSG) $ 113.94
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999872
  • sei-networkSei (SEI) $ 0.118978
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999606
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011784
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 91,036.00
  • clbtcclBTC (CLBTC) $ 91,345.00
  • morphoMorpho (MORPHO) $ 1.29
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,325.22
  • beldexBeldex (BDX) $ 0.091329
  • blockstackStacks (STX) $ 0.378738
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 160.81
  • jupiter-exchange-solanaJupiter (JUP) $ 0.207758
  • usdaiUSDai (USDAI) $ 0.999911
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.95
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.281942
  • wrapped-flareWrapped Flare (WFLR) $ 0.011236
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,302.45
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,112.66
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999828
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.947759
  • optimismOptimism (OP) $ 0.312710
  • tezosTezos (XTZ) $ 0.562376
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • curve-dao-tokenCurve DAO (CRV) $ 0.398137
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,111.45
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.40
  • chilizChiliz (CHZ) $ 0.053500
  • usual-usdUsual USD (USD0) $ 0.987053
  • tbtctBTC (TBTC) $ 91,256.00
  • spx6900SPX6900 (SPX) $ 0.583845
  • dashDash (DASH) $ 43.55
  • lighterLighter (LIT) $ 2.09
  • lido-daoLido DAO (LDO) $ 0.613208
  • aerodrome-financeAerodrome Finance (AERO) $ 0.559778
  • injective-protocolInjective (INJ) $ 5.08
  • gtethGTETH (GTETH) $ 3,106.90
  • ghoGHO (GHO) $ 0.998938
  • true-usdTrueUSD (TUSD) $ 0.998410
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998950
  • flokiFLOKI (FLOKI) $ 0.000051
  • ether-fiEther.fi (ETHFI) $ 0.729274
  • msolMarinade Staked SOL (MSOL) $ 187.05
  • fasttokenFasttoken (FTN) $ 1.09
  • celestiaCelestia (TIA) $ 0.534050
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,358.99
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • syrupMaple Finance (SYRUP) $ 0.391668
  • stader-ethxStader ETHx (ETHX) $ 3,354.20
  • the-graphThe Graph (GRT) $ 0.040771
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,483.47
  • newton-projectAB (AB) $ 0.004455
  • jasmycoinJasmyCoin (JASMY) $ 0.008611
  • sbtc-2sBTC (SBTC) $ 91,757.00
  • starknetStarknet (STRK) $ 0.081356
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.204022
  • usdbUSDB (USDB) $ 1.01
  • bittorrentBitTorrent (BTT) $ 0.00000041
  • staked-aaveStaked Aave (STKAAVE) $ 165.99
  • doublezeroDoubleZero (2Z) $ 0.117198
  • iotaIOTA (IOTA) $ 0.095622
  • justJUST (JST) $ 0.040906
  • riverRiver (RIVER) $ 20.25
  • sun-tokenSun Token (SUN) $ 0.020687
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.14
  • conflux-tokenConflux (CFX) $ 0.074893
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.383998
  • bitcoin-svBitcoin SV (BSV) $ 19.14
  • pyth-networkPyth Network (PYTH) $ 0.064775
  • gnosisGnosis (GNO) $ 140.57
  • dogwifcoindogwifhat (WIF) $ 0.368341
  • fartcoinFartcoin (FARTCOIN) $ 0.366137
  • apenftAINFT (NFT) $ 0.00000037
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.875662
  • chain-2Onyxcoin (XCN) $ 0.008531
  • cap-usdCap USD (CUSD) $ 0.999583
  • crvusdcrvUSD (CRVUSD) $ 0.998902
  • pendlePendle (PENDLE) $ 2.13
  • euro-coinEURC (EURC) $ 1.17
  • kaiaKaia (KAIA) $ 0.060842
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,116.00
  • telcoinTelcoin (TEL) $ 0.003715
  • kinesis-goldKinesis Gold (KAU) $ 147.90
  • olympusOlympus (OHM) $ 21.47
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.136811

North Korean workers tied to $1.3M crypto theft: ZachXBT

0 94

North Korean workers tied to $1.3M crypto theft: ZachXBT

Cybersecurity expert ZachXBT’s recent tweets suggest a sophisticated scheme involving North Korean IT workers posing as crypto developers is taking place.

The operation led to the theft of $1.3 million from a project’s treasury and exposed a network of over 25 compromised crypto projects active since June 2024.

ZachXBT’s research strongly suggests that a single entity in Asia, likely operating out of North Korea, is receiving $300,000 to $500,000 per month by working simultaneously on over 25 crypto projects using fake identities.

6/ A number of experienced teams have hired these devs so it’s not fair to them single as the ones to blame.

Some indicators teams can look out for in the future includes:

1) They refer each other for roles
2) Good looking resumes / GitHub activity although sometimes lie…

— ZachXBT (@zachxbt) August 15, 2024

You might also like: Suspects in $14m Holograph hack arrested by EU authorities

The theft and laundering scheme

The incident began when a publicly anonymous team reached out to ZachXBT for help after $1.3 million was stolen from their treasury. Unbeknownst to them, they had hired multiple North Korean IT workers who used fake identities to infiltrate the team.

The stolen funds, totaling $1.3 million, were quickly laundered through a sequence of transactions, including transferring to a theft address, bridging from (SOL) to Ethereum (ETH) via deBridge, depositing 50.2 ETH to Tornado Cash, and ultimately transferring 16.5 ETH to two different exchanges.

You might also like: US govt sent $594m Silk Road Bitcoin to Coinbase

Mapping the network

Further investigation revealed that the malicious developers were part of a larger network. By tracking multiple payment addresses, the investigator mapped out a cluster of 21 developers who had received approximately $375,000 in the last month alone.

The investigation also connected these activities to previous transactions totaling $5.5 million, which flowed into an exchange deposit address from July 2023 to 2024.

These payments were linked to North Korean IT workers and Sim Hyon Sop, a figure sanctioned by the Office of Foreign Assets Control (OFAC). Throughout the investigation, several concerning activities came to light, including instances of Russian Telecom IP overlap among developers who were reportedly based in the US and Malaysia.

Additionally, one developer accidentally exposed other identities while being recorded. Further investigations revealed that payment addresses were closely linked to those of OFAC-sanctioned individuals, such as Sang Man Kim and Sim Hyon Sop.

The involvement of recruitment companies in placing some developers added complexity to the situation. Additionally, several projects employed at least three North Korean IT workers who had referred each other.

You might also like: Vitalik Buterin donated $532k in ‘animal coins’ to charity

Preventive measures

ZachXBT pointed out that many experienced teams have inadvertently hired deceptive developers, so it’s not entirely fair to blame the teams. However, there are several measures that teams can take to protect themselves in the future.

These measures include being cautious of developers who refer each other for roles, scrutinizing resumes, thoroughly verifying KYC information, asking detailed questions about developers’ claimed locations, monitoring for developers who are fired and then reappear under new accounts, watching for a decline in performance over time, regularly reviewing logs for anomalies, being cautious of developers using popular NFT profile pictures, and noting potential language accents that could indicate origins in Asia.

Source

Leave A Reply

Your email address will not be published.