Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
ZachXBT Reveals North Korean Crypto Hackers’ Secret Infiltration Methods

ZachXBT Reveals North Korean Crypto Hackers’ Secret Infiltration Methods

BeInCryptoBeInCrypto2025/08/13 10:03
By:Landon Manning

ZachXBT reveals how North Korean hackers infiltrate crypto startups using fake identities and weak hiring practices, exposing security vulnerabilities in Web3 firms.

ZachXBT published a series of documents stolen from North Korean crypto hackers. These documents detail precisely how infiltrators attack crypto startups and how to fight back.

Essentially, these hackers work in small teams to jointly operate dozens of fake personas, which then apply for IT jobs. Web3 startups’ own negligence and dismissive attitudes are these criminals’ greatest asset.

North Korean Crypto Secrets Exposed

Since earlier this year, North Korean hackers have developed a fearsome reputation in the crypto industry.

A dangerous new tactic involves infiltrating Web3 startups; this sophisticated practice has led to several notorious thefts this year. However, one crypto sleuth recently published a report detailing these operations:

1/ An unnamed source recently compromised a DPRK IT worker device which provided insights into how a small team of five ITWs operated 30+ fake identities with government IDs and purchased Upwork/LinkedIn accounts to obtain developer jobs at projects.

— ZachXBT (@zachxbt) August 13, 2025

ZachXBT, a popular crypto investigator, pursues all sorts of Web3 criminals, yet North Korean hackers remain a special area of interest. He’s tracked everything from security breaches to money laundering, and has repeatedly warned of vast infiltration.

Today, however, ZachXBT is circulating valuable intel on how these groups work.

How Infiltrators Operate

Essentially, North Korean hackers split into five-man teams to impersonate crypto job seekers. These teams collectively acquire and operate upwards of 30 fake identities, purchasing government IDs, Upwork/LinkedIn accounts, VPNs, and more.

After doing this, they start applying for crypto jobs and looking for security flaws when they find employment. They vastly prefer IT roles, as this gives them ample chances to look for weaknesses and collaborate on the cover job’s workload.

ZachXBT Reveals North Korean Crypto Hackers’ Secret Infiltration Methods image 0North Korean Job Search Roster. Source:

These North Korean crypto scams are very sophisticated, but these documents show how to fight back. A few essential clues, like their choice of VPN, can expose a fake job applicant. Instead, the biggest problem is arrogance.

When cybersecurity investigators warn Web3 startups of potential infiltration, they might get a dismissive response:

“The main challenge faced in fighting [North Korean hackers] at companies includes the lack of collaboration. There’s also the negligence by the teams hiring them who become combative when alerted. [These hackers] are in no way sophisticated, but are persistent, since there’s so many flooding the job market globally for roles,” ZachXBT claimed.

These hackers never stay committed to one job, only lingering long enough to find a security exploit. Once they find one, groups like Lazarus employ a totally different unit to perpetrate the hack.

These methods encourage North Korean crypto hackers to maintain flimsy cover identities, hoping that lazy hiring practices indicate vulnerable security measures.

Web3 startups should be aware of North Korean hackers, not paralyzed by fear of them. A little diligence and caution can help keep any project safe from these infiltration attacks.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bond investors expect Powell to tee up September rate cut in Friday speech

Share link:In this post: Powell is expected to hint at a September rate cut during his Friday speech in Jackson Hole. Traders are pricing in a 70% chance of a 0.25% cut and 50bps total easing in 2025. Trump is pressuring the Fed, but Powell may avoid firm commitments before new data.

Cryptopolitan2025/08/22 08:00

UK business activity reached its fastest pace in a year

Share link:In this post: UK business activity reached its fastest pace in a year in August, led by growth in services. Government borrowing in July was £1.1bn, lower than the OBR’s £2.1bn forecast, helped by higher tax receipts. Hiring stayed weak despite stronger activity, with employment falling for the eleventh straight month.

Cryptopolitan2025/08/22 08:00

UK consumers grow more optimistic following BoE rate cut

Share link:In this post: UK consumers increase their confidence in household budgets after the Bank of England rate cuts. Consumer confidence hit its highest level in months, surprising experts. Rich families spend more, but poor families still struggle with high prices.

Cryptopolitan2025/08/22 08:00
UK consumers grow more optimistic following BoE rate cut

Crypto handheld buyers hit with sudden import charges

Share link:In this post: Crypto handheld buyers in the U.S. are being hit with unexpected import duties, sometimes as high as $348. The manufacturer has paused shipments of its $599 gaming device while it investigates varying fees and complaints from early customers. Buyers are frustrated over the lack of upfront cost clarity, with some calling the extra charges misleading and asking for refunds.

Cryptopolitan2025/08/22 08:00
Crypto handheld buyers hit with sudden import charges