Crypto Exchange Kraken Uncovers North Korean Espionage Plot
By: bitcoin ethereum news|2025/05/03 12:45:01
0
Share
Crypto exchange Kraken’s latest security disclosure reads less like a corporate blog post than a field report from the front lines of modern cyber-warfare. Published on 1 May 2025 under the blunt title “How we identified a North Korean hacker who tried to get a job at Kraken,” the account describes in granular detail how a seemingly routine hiring process morphed into what the exchange openly calls “an intelligence gathering operation.” From the first contact, something felt wrong. Recruiters noticed that the applicant “joined under a different name from the one on their resume, and quickly changed it,” a detail the security team later described as the opening note in a symphony of red flags. Moments later, the interview took on an uncanny timbre: “the candidate occasionally switched between voices, indicating that they were being coached through the interview in real time.” Kraken Tricks North Korean Crypto Hacker Kraken’s staff did not rely on intuition alone. The post explains that industry partners had already circulated “a list of email addresses linked to the hacker group,” and one of those addresses matched the résumé in question. Armed with that match, Kraken’s Red Team launched an OSINT dive that exposed what it calls “a larger network of fake identities and aliases” spreading across the crypto employment market. According to the blog, multiple companies had unwittingly hired personas from the same lattice of fabricated résumés, and “one identity in this network was also a known foreign agent on the sanctions list.” Technical inconsistencies began piling up. The exchange recounts how the applicant relied on “remote colocated Mac desktops but interacted with other components through a VPN,” a configuration favoured by operators who need to launder location data. Investigators tied the résumé to a GitHub profile containing an email address that “had been exposed in a past data breach,” and finally concluded that the primary government ID “appeared to be altered, likely using details stolen in an identity theft case two years prior.” With the evidence mounting, Kraken opted for misdirection rather than immediate rejection. The company advanced the applicant through successive stages—in effect baiting the hook. “Instead of tipping off the applicant, our security and recruitment teams strategically advanced them through our rigorous recruitment process – not to hire, but to study their approach,” the blog states. The denouement came in what should have been an informal “chemistry interview” with Chief Security Officer Nick Percoco. The applicant did not realise that every pleasantry was laced with a test. Percoco and his colleagues asked for live two-factor confirmations: show your government ID on camera, report your physical location, name a few local restaurants. “At this point,” the post recounts, “the candidate unraveled. Flustered and caught off guard, they struggled with the basic verification tests, and couldn’t convincingly answer real-time questions about their city of residence or country of citizenship.” Percoco subsequently distilled the lesson from the disclosure: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto, or US corporate, issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.” The blog underscores that the crypto sector’s attack surface is no longer confined to code repositories or hot-wallet infrastructure; it extends to the HR inbox. “Not all attackers break in, some try to walk through the front door,” Kraken writes, adding that “Generative AI is making deception easier, but isn’t foolproof... genuine candidates will usually pass real-time, unprompted verification tests.” In a concluding reflection on organisational culture, the post argues that “a culture of productive paranoia is key. Security isn’t just an IT responsibility. In the modern era, it’s an organizational mindset.” Kraken closes its narrative with a reminder that the candidate was part of the North Korean campaign which, by third-party estimates cited in the post, siphoned more than $650 million from crypto firms in 2024. The message is sober and unsentimental: “Sometimes, the biggest threats come disguised as opportunities.” At press time, BTC traded at $96,825. Featured image created with DALL.E, chart from TradingView.com Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers. Source: https://bitcoinist.com/crypto-exchange-kraken-north-korean-espionage-plot/
You may also like

What do projects born in the crypto bear market do?
From January to April, RootData has recorded over 1,070 new projects, a decrease of about 32% compared to the same period last year.

a16z founder's Stanford lecture: Whenever Wall Street and Silicon Valley have different ideas, it's Wall Street that ends up being wrong
Ben Horowitz, co-founder of a16z, delivered a powerful talk: The two traditional moats of software in the AI era have been erased, and entrepreneurs must seek "new barriers" beyond code and UI.

Michael Saylor: After three consecutive quarters of losses, Strategy will sell Bitcoin to pay dividends
After MSTR's financial report showed continued net losses, Saylor changed his stance: Bitcoin is no longer "never to be sold" and can be used as a payment tool.

The toll station at Hormuz and the RMB that cannot be bought
The disorder of the US dollar is giving rise to a new situation in global settlement: gold is being redefined as a "bridge," the CIPS system is expanding rapidly, and global funds are quietly opening up a new channel for the renminbi, which is "hard to obtain."

Interview with Coinbase Institutional's Strategic Head: The Institutionalization of Crypto Reaches a Critical Point
Coinbase executives provide an in-depth analysis: Unfazed by short-term market panic, institutions are accelerating their entry, and tokenization along with the "exchange of everything" is about to completely reconstruct the global financial infrastructure.

Dialogue with Agora CEO Nick: The battle for stablecoin licenses has just begun
Agora strikes: officially applies for a federal trust bank license in the United States, elevating from a stablecoin issuer to "underlying financial infrastructure," targeting the trillion-dollar enterprise payment and B2B settlement market.

Morning Report | a16z Crypto completes $2.2 billion fundraising for its fifth fund; Bullish invests $4.2 billion to acquire share transfer agency Equiniti; PayPal's Q1 performance exceeds expectations
Overview of Important Market Events on May 5th

a16z Crypto: What We See Behind the $2.2 Billion New Fund
After the noise subsides, what remains is often more useful than it appeared at its peak and more enduring than it seemed at its lowest point.

Web3 is dead, Web2+3 should rise
We are not aiming to hold a self-indulgent party for Web3 practitioners, but rather to build a bridge for rational connection between Web2 and Web3.

Stablecoins and Latin American Remittances: The Misunderstood $174 Billion Market
In the Latin American remittance market, the real protagonists have never been the young people speculating on cryptocurrencies, but rather the 50-year-old workers who send money to their mothers every month. They don't care about blockchain; they only care about whether the money has arrived.

The arrival of the Web 3.0 era: A review of Hong Kong court rulings on digital assets
Hong Kong judiciary landmark: The court officially recognizes cryptocurrency as legal property and introduces the "tokenized injunction" to track and freeze involved funds, comprehensively upgrading the protection of digital asset investors.

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android
To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance
Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.

A Brief Analysis of Stablecoin Licenses and On-Chain Funding
Hong Kong accelerates the layout of digital finance, providing a panoramic analysis of the evolution of three major on-chain financial forms: central bank digital currency, deposit tokens, and stablecoins, along with future opportunities.

BVNK Founder: Three Stages of Stablecoin Development
Once payments become faster, cheaper, and globally interconnected, stablecoins will not just open up a new market, but a new realm with boundaries that are not yet visible today.

The truth about Trump's son's Bitcoin game: he made a staggering $100 million while retail investors lost $500 million
The Trump family has a family skill: to exaggerate and make something sound bigger than it actually is.

What Is Futures Trading? Hours, Platforms, and How to Start Trade Futures(2026 Guide)
Learn how to start futures trading, understand trading hours, and choose the best futures trading platform. Includes real data, strategies, and ways to maximize returns with rebates.

The Rise of Composable RWA
27 billion RWA funds are undergoing a major reshuffle: U.S. Treasury bonds are "cooling off," while high-yield credit assets are quietly dominating the DeFi lending market with permissionless designs. This article reveals the explosive logic behind composable RWA.
What do projects born in the crypto bear market do?
From January to April, RootData has recorded over 1,070 new projects, a decrease of about 32% compared to the same period last year.
a16z founder's Stanford lecture: Whenever Wall Street and Silicon Valley have different ideas, it's Wall Street that ends up being wrong
Ben Horowitz, co-founder of a16z, delivered a powerful talk: The two traditional moats of software in the AI era have been erased, and entrepreneurs must seek "new barriers" beyond code and UI.
Michael Saylor: After three consecutive quarters of losses, Strategy will sell Bitcoin to pay dividends
After MSTR's financial report showed continued net losses, Saylor changed his stance: Bitcoin is no longer "never to be sold" and can be used as a payment tool.
The toll station at Hormuz and the RMB that cannot be bought
The disorder of the US dollar is giving rise to a new situation in global settlement: gold is being redefined as a "bridge," the CIPS system is expanding rapidly, and global funds are quietly opening up a new channel for the renminbi, which is "hard to obtain."
Interview with Coinbase Institutional's Strategic Head: The Institutionalization of Crypto Reaches a Critical Point
Coinbase executives provide an in-depth analysis: Unfazed by short-term market panic, institutions are accelerating their entry, and tokenization along with the "exchange of everything" is about to completely reconstruct the global financial infrastructure.
Dialogue with Agora CEO Nick: The battle for stablecoin licenses has just begun
Agora strikes: officially applies for a federal trust bank license in the United States, elevating from a stablecoin issuer to "underlying financial infrastructure," targeting the trillion-dollar enterprise payment and B2B settlement market.
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com
