Close Menu
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Facebook X (Twitter) Instagram
    Bytecore News
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Bytecore News
    Home»Uncategorized»ZachXBT Uncovers $3.5M Operation by North Korean Fake Devs Inside Crypto Firms
    Uncategorized

    ZachXBT Uncovers $3.5M Operation by North Korean Fake Devs Inside Crypto Firms

    April 10, 20263 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email




    A hacked device uncovered how North Korean developers secretly earned millions in crypto while working across different projects.

    A large batch of leaked internal data has revealed that North Korean IT workers generated over $3.5 million in cryptocurrency in recent months through a coordinated operation involving fake developer identities and structured payment systems, according to blockchain investigator ZachXBT.

    The information surfaced after an unnamed hacker compromised one of the workers’ devices, exposing records from an internal payment server tied to nearly 390 accounts, along with chat logs, browser data, and falsified identity documents used to secure jobs.

    North Korean Crypto Operation

    The dataset shows the operation brought in roughly $1 million per month, and individuals used forged credentials to obtain roles across projects while routing their earnings through an internal platform. ZachXBT revealed that communication and payment tracking were handled through a platform known as “luckyguys.site,” which functioned as an internal hub where workers logged transactions and reported income to administrators.

    The platform appeared to have minimal security safeguards, and multiple users relied on a default password. User listings included roles, locations, and group identifiers similar to known North Korean IT worker structures, including links to entities sanctioned by the US Treasury’s Office of Foreign Assets Control, such as Sobaeksu, Saenal, and Songkwang.

    Meanwhile, chat records indicate that a central administrator account was responsible for confirming incoming transfers and distributing account credentials for various financial services. Payments typically followed a consistent pattern, where funds received in cryptocurrency from exchanges or clients were converted into fiat and transferred through Chinese bank accounts using payment platforms like Payoneer. Blockchain tracing of these flows revealed connections to previously identified North Korean-linked wallets, including addresses later frozen by Tether in late 2025.

    Data extracted from the compromised device, associated with a user operating under the name “Jerry,” revealed extensive use of VPN services and multiple fabricated personas for job applications. Internal conversations referenced deepfake-related hiring concerns and restrictions on sharing external information within the network. Additional logs suggested that dozens of workers operated simultaneously within the same communication system.

    Beyond income generation, the records also captured discussions related to the potential exploitation of crypto projects. In one instance, “Jerry” discussed targeting a project with another worker using a proxy setup, although there is no confirmation that the attempt was carried out.

    You may also like:

    Separately, administrators distributed training materials covering reverse engineering and debugging tools such as IDA Pro.

    DPRK Developers in DeFi

    Just this week, cybersecurity researcher Taylor Monahan said North Korea-linked IT workers have been operating in the crypto sector for years, and even contributed to major DeFi protocols. Monahan explained that many of their resumes reflected real development experience rather than fabricated backgrounds.

    Projects such as SushiSwap, Yearn, and THORChain were among those cited. The security expert also added that these actors later played an important role in enabling large-scale exploits.

    Additionally, North Korean-affiliated hacking group Lazarus Group has been linked to some of the industry’s highest-profile hacks, such as the $625 million Ronin Bridge exploit in 2022, the $235 million WazirX hack in 2024, and the more recent $1.4 billion Bybit heist in 2025.

    SPECIAL OFFER (Exclusive)

    Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

    LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    CryptoExpert
    • Website

    Related Posts

    Solana Price At Risk As ‘Consolidation Trap’ Emerges – $52 Next?

    April 10, 2026

    SEC Chair Presses Congress On Crypto Market Structure, Wants Bill To Reach President’s Desk

    April 10, 2026

    Musk’s xAI Sues Colorado over AI Law

    April 10, 2026

    AAVE price risks $77 as $100 flips to resistance

    April 10, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    notion
    Latest Posts

    XRP Supply Is Thinning and Leverage Is Absent. Learn What Happens When One Of Those Changes

    April 10, 2026

    Bitcoin Just Hit A Generational Buy Zone. Discover The One Condition Still Missing

    April 10, 2026

    Ex-SEC, Coinbase Staffer Becomes Securitize President

    April 10, 2026

    March CPI could be worst since 2024

    April 10, 2026

    Bitcoin Profit Supply Drops to 59%, Closing In on Bear Market Levels

    April 9, 2026
    10web
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    Solana Price At Risk As ‘Consolidation Trap’ Emerges – $52 Next?

    April 10, 2026

    SEC Chair Presses Congress On Crypto Market Structure, Wants Bill To Reach President’s Desk

    April 10, 2026
    binance
    Facebook X (Twitter) Instagram Pinterest
    © 2026 BytecoreNews.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.