Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Someone counter-hacked a North Korean IT worker: Here’s what they found

Someone counter-hacked a North Korean IT worker: Here’s what they found

CointimeCointime2025/08/14 07:05
By:Cointime

A small team of North Korean IT workers — linked to a $680,000 crypto hack in June — have been using Google products and even renting computers to infiltrate crypto projects, according to newly leaked screenshots coming from one of the workers’ devices. 

In an X  post  from ZachXBT on Wednesday, the crypto sleuth shared a rare inside look into the workings of a North Korean (DPRK) hacker. The information came from “an unnamed source” who was able to compromise one of their devices. 

North Korean-linked workers were responsible for  $1.4 billion exploit  of crypto exchange Bitbit in February and have siphoned millions from crypto protocols over the years.

The data shows that the small team of six North Korean IT workers shares at least 31 fake identities, obtaining everything from government IDs and phone numbers to purchasing LinkedIn and UpWork accounts to mask their true identities and land crypto jobs. 

One of the workers supposedly interviewed for a full-stack engineer position at Polygon Labs, while other evidence showed scripted interview responses in which they claimed to have experience at NFT marketplace OpenSea and blockchain oracle provider Chainlink.

Someone counter-hacked a North Korean IT worker: Here’s what they found image 0   Fake list of identities involved in the North Korean IT scam operation. Source: ZachXBT


Google, remote working software

The leaked documents show the North Korean IT workers secured “blockchain developer” and “smart contract engineer” roles on  freelance platforms  like Upwork, then use remote access software like AnyDesk to  carry out the work  for unsuspecting employers. They also use VPNs to hide their true location.

Google Drive exports and Chrome profiles show they used Google tools to manage schedules, tasks and budgets, communicating mainly in English while using Google’s Korean-to-English translation tool.One spreadsheet shows IT workers spent a combined $1,489.8 on expenses in May to carry out their operations.

Someone counter-hacked a North Korean IT worker: Here’s what they found image 1   Interview notes/preparation, likely intended to be referenced during an interview. Source: ZachXBT

North Korean IT workers tied to recent $680,000 crypto hack 

The North Koreans often use Payoneer to convert fiat into crypto for their work, and one of those wallet addresses —“0x78e1a” — is “closely tied” to  the $680,000 exploit  on fan-token marketplace Favrr in June 2025, ZachXBT said.

At the time, ZachXBT alleged the project’s chief technology officer, known as “Alex Hong,” along with other developers, were actually DPRK workers in disguise. 

Someone counter-hacked a North Korean IT worker: Here’s what they found image 2   Source: ZachXBT

The evidence also provides insight into their areas of curiosity. One search asked whether ERC-20 tokens can be deployed on Solana, while another sought information on the top AI development companies in Europe.

Crypto firms need to do more due diligence

ZachXBT called on crypto and tech firms to do more homework on potential hirees — noting that many of these operations aren’t highly sophisticated, but the volume of applications often leads to hiring teams becoming negligent.

He added that a lack of collaboration between tech firms and freelance platforms further contributes to the problem.

Last month, the US Treasury took matters into its own hands, sanctioning  two people and four entities  involved in a North Korea-run IT worker ring infiltrating crypto firms.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Norway hands Musk Tesla boost as SpaceX BTC holdings expand past $1B

Share link:In this post: Tesla’s sales in Norway have surged despite growing discontent among Norwegians regarding Elon Musk’s political stance. SpaceX’s BTC holdings have crossed the $1 billion mark again. Tesla’s deep ties in Norway influence its consistent sales numbers, but it is slowly losing its dominance as more rivals make headway.

Cryptopolitan2025/08/14 14:35
Norway hands Musk Tesla boost as SpaceX BTC holdings expand past $1B

Musk tips Google to dominate AI as it commits extra $9B to Oklahoma AI, cloud infrastructure

Share link:In this post: Elon Musk says Google currently has the highest probability of leading AI due to its compute and data advantage. Google will invest $9 billion in Oklahoma to expand AI and cloud infrastructure over the next two years. The plan includes a new Stillwater data center campus and expansion of its Pryor facility.

Cryptopolitan2025/08/14 14:35

Nvidia partner Foxconn reports strong surge in AI server sales

Share link:In this post: Hon Hai Precision Industry (Foxconn) reported a 27% increase in Q2 profits, driven by sales in its AI server business. The company reported a net income of NT$44.36 billion for the period, surpassing an average analyst projection of NT$36.14 billion. It also expects significant growth in Q3 and the rest of the year.

Cryptopolitan2025/08/14 14:35

US PPI beats estimates with 3.3% annual gain in July

Share link:In this post: US PPI jumped 3.3% in July, the highest annual gain since February. Monthly PPI rose 0.9%, blowing past the 0.2% forecast. Service costs surged, led by machinery wholesaling and portfolio fees.

Cryptopolitan2025/08/14 14:35
US PPI beats estimates with 3.3% annual gain in July