North Korean Hackers Expand Crypto Theft and IT Infiltration Campaign

1 hour ago 3 sources negative

Key takeaways:

  • North Korea's crypto-funded IT infiltration signals rising insider risk for exchanges and wallet providers.
  • Bybit's $1.5B ETH theft underscores custody concentration risks beyond North Korea's state hacking.
  • Traders should watch exchange security disclosures, as state-linked theft now weighs on crypto sentiment.

US officials and cybersecurity researchers say North Korea has expanded a covert campaign to place IT workers inside American firms by recruiting people in third countries such as Iran, Lebanon, Syria, South Africa and Saudi Arabia. These recruits appear on camera for interviews and sometimes make in-person contact before a North Korean operative takes over the job. Threat intelligence firm Flare found that North Korean teams approached at least 14 Iranian engineers since 2024, and two received formal offer letters after completing interviews for hidden applicants. Recruiters use LinkedIn and offer about $500 a month in cryptocurrency for part-time “interview associate” work.

The IT-worker scheme generates an estimated $600 million to $800 million annually, with salaries remitted to Pyongyang to fund sanctioned weapons programs. A July 2026 joint warning by the State Department, Justice Department and partner governments called the tactics increasingly sophisticated. The same state apparatus operates Lazarus Group, responsible for major crypto thefts, including the 2022 Ronin Network theft of more than $600 million, the $100 million Harmony Horizon bridge attack, and the February 2025 theft of roughly $1.5 billion in Ethereum from Bybit, the largest single crypto theft on record.

North Korean-linked actors stole more than $2 billion in digital assets in 2025, a 51% increase from the previous year, with cumulative thefts above $6 billion. Additional 2026 breaches of Drift Protocol and KelpDAO added hundreds of millions more. In some cases the employment fraud and hacking overlap, as fraudulent remote workers use insider access to steal crypto or sensitive data.

Japan’s National Police Agency and the FBI separately reported that a North Korean-linked group known as WaterPlum infected more than 30,000 devices and stole data from 7,000 crypto wallets, with compromised wallets receiving at least $10.71 million in assets. The attackers impersonated tech-firm recruiters to deploy malware, underscoring the growing convergence of state-sponsored espionage and cryptocurrency theft.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.