Cointime

Download App
iOS & Android

Someone counter-hacked a North Korean IT worker: Here’s what they found

A small team of North Korean IT workers — linked to a $680,000 crypto hack in June — have been using Google products and even renting computers to infiltrate crypto projects, according to newly leaked screenshots coming from one of the workers’ devices. 

In an X post from ZachXBT on Wednesday, the crypto sleuth shared a rare inside look into the workings of a North Korean (DPRK) hacker. The information came from “an unnamed source” who was able to compromise one of their devices. 

North Korean-linked workers were responsible for $1.4 billion exploit of crypto exchange Bitbit in February and have siphoned millions from crypto protocols over the years.

The data shows that the small team of six North Korean IT workers shares at least 31 fake identities, obtaining everything from government IDs and phone numbers to purchasing LinkedIn and UpWork accounts to mask their true identities and land crypto jobs. 

One of the workers supposedly interviewed for a full-stack engineer position at Polygon Labs, while other evidence showed scripted interview responses in which they claimed to have experience at NFT marketplace OpenSea and blockchain oracle provider Chainlink.

  Fake list of identities involved in the North Korean IT scam operation. Source: ZachXBT


Google, remote working software

The leaked documents show the North Korean IT workers secured “blockchain developer” and “smart contract engineer” roles on freelance platforms like Upwork, then use remote access software like AnyDesk to carry out the work for unsuspecting employers. They also use VPNs to hide their true location.

Google Drive exports and Chrome profiles show they used Google tools to manage schedules, tasks and budgets, communicating mainly in English while using Google’s Korean-to-English translation tool.One spreadsheet shows IT workers spent a combined $1,489.8 on expenses in May to carry out their operations.

  Interview notes/preparation, likely intended to be referenced during an interview. Source: ZachXBT

North Korean IT workers tied to recent $680,000 crypto hack 

The North Koreans often use Payoneer to convert fiat into crypto for their work, and one of those wallet addresses —“0x78e1a” — is “closely tied” to the $680,000 exploit on fan-token marketplace Favrr in June 2025, ZachXBT said.

At the time, ZachXBT alleged the project’s chief technology officer, known as “Alex Hong,” along with other developers, were actually DPRK workers in disguise. 

  Source: ZachXBT

The evidence also provides insight into their areas of curiosity. One search asked whether ERC-20 tokens can be deployed on Solana, while another sought information on the top AI development companies in Europe.

Crypto firms need to do more due diligence

ZachXBT called on crypto and tech firms to do more homework on potential hirees — noting that many of these operations aren’t highly sophisticated, but the volume of applications often leads to hiring teams becoming negligent.

He added that a lack of collaboration between tech firms and freelance platforms further contributes to the problem.

Last month, the US Treasury took matters into its own hands, sanctioning two people and four entities involved in a North Korea-run IT worker ring infiltrating crypto firms.

Comments

All Comments

Recommended for you

  • BTC Surpasses $82,000

    Market data shows that BTC has surpassed $82,000, currently priced at $82,009.39, with a 24-hour increase of 3.54%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $81,000

    Market data shows that BTC has surpassed $81,000, currently priced at $81,005.66, with a 24-hour increase of 1.57%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Senator Warren Calls for SEC Investigation into Trump Family's Cryptocurrency Company

    On May 14, U.S. Senator Warren requested the Securities and Exchange Commission (SEC) to investigate the cryptocurrency company owned by the family of President Trump.

  • BTC Surpasses $80,000

    Market data shows that BTC has surpassed $80,000, currently priced at $80,011.1, with a 24-hour decline of 0.31%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Central Bank: M2 Money Supply Reaches 353.04 Trillion Yuan at End of April, Up 8.6% Year-on-Year

    On May 14, data from the central bank showed that at the end of April, the broad money supply (M2) reached 353.04 trillion yuan, an increase of 8.6% year-on-year. The narrow money supply (M1) amounted to 114.58 trillion yuan, up 5% year-on-year. The amount of currency in circulation (M0) was 14.75 trillion yuan, marking a year-on-year increase of 12.2%. In the first four months, a net cash injection of 653 billion yuan was made.

  • Nvidia Soars in After-Hours Trading

    On May 14, Nvidia experienced a rapid increase in after-hours trading on the US stock market, rising nearly 2% to $230. (Dongxin News Agency)

  • China and US Agree to Build Constructive Strategic Stability Relationship

    Beijing, May 14th – On the morning of May 14th, Chinese President Xi Jinping held talks with US President Donald Trump, who is on a state visit to China, at the Great Hall of the People in Beijing. President Xi Jinping stated: "President Trump and I agree to establish a 'constructive strategic stability relationship' as the new positioning for China-US relations." (CCTV News)

  • Key Updates for May 14 Afternoon

    7:00-12:00 Keywords: Aave, Metaplanet, DeFi Development, Cerebras Systems 1. Aave: Cross-chain between the rsETH mainnet and L2 has reopened; 2. Metaplanet has postponed its preferred stock listing plan due to structural issues in the Japanese market; 3. The U.S. government seeks to confiscate $1.07 million in assets before sentencing of former Celsius executives; 4. Aave proposes to integrate the Babylon protocol in version V4, launching a native BTC lending module; 5. Solana Treasury's DeFi Development report states that the value of each SOL share has increased by 108% year-on-year; 6. Bipartisan negotiations on the Clarity Act failed to reach an agreement overnight, with Democrats divided over ethical and BRCA provisions; 7. AI chip manufacturer Cerebras Systems has raised $5.55 billion in its IPO, making it the largest fundraising of the year to date.

  • Trump: US-China Relations Will Be the Best in History

    On May 14, according to China News Service, US President Trump stated that the relationship between the United States and China will be the best in history.