North Korean Hackers Breach 1,640 Companies in Global Crypto-Theft Operation

1 hour ago 2 sources negative

Key takeaways:

  • State-sponsored crypto theft by North Korea adds systemic risk to centralized platforms, potentially suppressing valuations.
  • Remote developer supply-chain attacks underscore the urgent need for hardware-based security, benefiting related solutions.
  • High-profile breaches at Coinbase and Uniswap may trigger near-term volatility for COIN and UNI.

North Korean state-sponsored cyber operators have compromised at least 1,640 organizations across 57 countries through elaborate fake software developer recruitment schemes, according to a two-year investigation by cybersecurity researcher Vangelis Stykas, CTO of Kumio and founder of Atropos.ai. Stykas infiltrated the hackers' command-and-control infrastructure, gathering approximately 5 terabytes of internal data that exposed the staggering scale of the operation.

The attackers consistently targeted cryptocurrency firms, fintech companies, and blockchain infrastructure, seeking access to hot wallets, private keys, and source code repositories. The campaign, known as Contagious Interview, lured developers with fraudulent job offers and tricked them into executing malware disguised as coding assignments. Once a victim's workstation was compromised, attackers pivoted to multiple organizations using the developer's broad access credentials—in many cases achieving root-level control of production servers and cloud environments.

High-profile victims included Coinbase, Uniswap Labs, Boston Children’s Hospital, Oppo, and AEON Smart Technology, though many more remain unaware of the breaches. Stykas estimated that 700–800 organizations suffered “really damaging” intrusions with administrator-level access. The findings highlight a critical supply-chain risk posed by remote developers and contractors who often hold privileged access across several companies simultaneously.

US authorities have long linked such campaigns to North Korea’s revenue-generation strategy, with cyber theft netting the regime hundreds of millions of dollars annually. The newly disclosed data suggests operations are far broader than previously understood, and many compromised networks may still harbor persistent backdoors for future espionage or ransomware attacks. Cybersecurity experts are urging immediate adoption of hardware-backed authentication, strict privileged access management, and thorough verification of recruitment processes to counter this growing threat.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.