A cybersecurity researcher spent nearly two years secretly monitoring servers controlled by a North Korean hacking group, uncovering a massive campaign that compromised 1,640 companies across 57 nations. The findings, first reported by cybersecurity firm Kumio and later detailed by the researcher, show that the attackers specifically targeted cryptocurrency platforms like Coinbase and Uniswap Labs, prioritizing financial gain over other sensitive data.
The infiltrator, a Greek security expert, maintained access to the hackers’ command-and-control infrastructure for 22 months. During this time, they observed that 700 to 800 organizations suffered serious intrusions, with attackers gaining root privileges on servers, control over AWS root accounts, and—most critically—access to cryptocurrency wallet keys. Despite having access to medical records and criminal databases, the hackers almost entirely focused on stealing digital assets, highlighting a clear and strategic financial motive.
The revelation sent immediate ripples through the crypto market. While no immediate price swings occurred, the breach underscores deep vulnerabilities within the industry’s security posture. The attackers used sophisticated social engineering, such as fake job interviews, to penetrate systems, taking advantage of lax access controls among external contractors. Both Coinbase and Uniswap Labs were alerted and responded, though details remain undisclosed. The incident is a stark reminder that state-sponsored hacking groups continue to see crypto platforms as high-value targets, potentially funding broader national agendas through stolen funds.