The post ZachXBT Uncovers $3.5M Operation by North Korean Fake Devs Inside Crypto Firms appeared on BitcoinEthereumNews.com. Home » Crypto News A hacked deviceThe post ZachXBT Uncovers $3.5M Operation by North Korean Fake Devs Inside Crypto Firms appeared on BitcoinEthereumNews.com. Home » Crypto News A hacked device

ZachXBT Uncovers $3.5M Operation by North Korean Fake Devs Inside Crypto Firms

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Home » Crypto News


A hacked device uncovered how North Korean developers secretly earned millions in crypto while working across different projects.

‘;
}
function loadTrinityPlayer(targetWrapper, theme,extras=””) {
cleanupPlayer(targetWrapper); // Always clean first ✅
targetWrapper.classList.add(‘played’);
// Create script
const scriptEl = document.createElement(“script”);
scriptEl.setAttribute(“fetchpriority”, “high”);
scriptEl.setAttribute(“charset”, “UTF-8”);
const scriptURL = new URL(`https://trinitymedia.ai/player/trinity/2900019254/?themeAppearance=${theme}${extras}`);
scriptURL.searchParams.set(“pageURL”, window.location.href);
scriptEl.src = scriptURL.toString();
// Insert player
const placeholder = targetWrapper.querySelector(“.add-before-this”);
placeholder.parentNode.insertBefore(scriptEl, placeholder.nextSibling);
}
function getTheme() {
return document.body.classList.contains(“dark”) ? “dark” : “light”;
}
// Initial Load for Desktop
if (window.innerWidth > 768) {
const desktopBtn = document.getElementById(“desktopPlayBtn”);
if (desktopBtn) {
desktopBtn.addEventListener(“click”, function () {
const desktopWrapper = document.querySelector(“.desktop-player-wrapper.trinity-player-iframe-wrapper”);
if (desktopWrapper) loadTrinityPlayer(desktopWrapper, getTheme(),’&autoplay=1′);
});
}
}
// Mobile Button Click
const mobileBtn = document.getElementById(“mobilePlayBtn”);
if (mobileBtn) {
mobileBtn.addEventListener(“click”, function () {
const mobileWrapper = document.querySelector(“.mobile-player-wrapper.trinity-player-iframe-wrapper”);
if (mobileWrapper) loadTrinityPlayer(mobileWrapper, getTheme(),’&autoplay=1′);
});
}
function reInitButton(container,html){
container.innerHTML = ” + html;
}
// Theme switcher
const destroyButton = document.getElementById(“checkbox”);
if (destroyButton) {
destroyButton.addEventListener(“click”, () => {
setTimeout(() => {
const theme = getTheme();
if (window.innerWidth > 768) {
const desktopWrapper = document.querySelector(“.desktop-player-wrapper.trinity-player-iframe-wrapper”);
if(desktopWrapper.classList.contains(‘played’)){
loadTrinityPlayer(desktopWrapper, theme,’&autoplay=1′);
}else{
reInitButton(desktopWrapper,’Listen‘)
const desktopBtn = document.getElementById(“desktopPlayBtn”);
if (desktopBtn) {
desktopBtn.addEventListener(“click”, function () {
const desktopWrapper = document.querySelector(“.desktop-player-wrapper.trinity-player-iframe-wrapper”);
if (desktopWrapper) loadTrinityPlayer(desktopWrapper,theme,’&autoplay=1’);
});
}
}
} else {
const mobileWrapper = document.querySelector(“.mobile-player-wrapper.trinity-player-iframe-wrapper”);
if(mobileWrapper.classList.contains(‘played’)){
loadTrinityPlayer(mobileWrapper, theme,’&autoplay=1′);
}else{
const mobileBtn = document.getElementById(“mobilePlayBtn”);
if (mobileBtn) {
mobileBtn.addEventListener(“click”, function () {
const mobileWrapper = document.querySelector(“.mobile-player-wrapper.trinity-player-iframe-wrapper”);
if (mobileWrapper) loadTrinityPlayer(mobileWrapper,theme,’&autoplay=1′);
});
}
}
}
}, 100);
});
}
})();


Summarize with AI


Summarize with AI

A large batch of leaked internal data has revealed that North Korean IT workers generated over $3.5 million in cryptocurrency in recent months through a coordinated operation involving fake developer identities and structured payment systems, according to blockchain investigator ZachXBT.

The information surfaced after an unnamed hacker compromised one of the workers’ devices, exposing records from an internal payment server tied to nearly 390 accounts, along with chat logs, browser data, and falsified identity documents used to secure jobs.

North Korean Crypto Operation

The dataset shows the operation brought in roughly $1 million per month, and individuals used forged credentials to obtain roles across projects while routing their earnings through an internal platform. ZachXBT revealed that communication and payment tracking were handled through a platform known as “luckyguys.site,” which functioned as an internal hub where workers logged transactions and reported income to administrators.

The platform appeared to have minimal security safeguards, and multiple users relied on a default password. User listings included roles, locations, and group identifiers similar to known North Korean IT worker structures, including links to entities sanctioned by the US Treasury’s Office of Foreign Assets Control, such as Sobaeksu, Saenal, and Songkwang.

Meanwhile, chat records indicate that a central administrator account was responsible for confirming incoming transfers and distributing account credentials for various financial services. Payments typically followed a consistent pattern, where funds received in cryptocurrency from exchanges or clients were converted into fiat and transferred through Chinese bank accounts using payment platforms like Payoneer. Blockchain tracing of these flows revealed connections to previously identified North Korean-linked wallets, including addresses later frozen by Tether in late 2025.

Data extracted from the compromised device, associated with a user operating under the name “Jerry,” revealed extensive use of VPN services and multiple fabricated personas for job applications. Internal conversations referenced deepfake-related hiring concerns and restrictions on sharing external information within the network. Additional logs suggested that dozens of workers operated simultaneously within the same communication system.

Beyond income generation, the records also captured discussions related to the potential exploitation of crypto projects. In one instance, “Jerry” discussed targeting a project with another worker using a proxy setup, although there is no confirmation that the attempt was carried out.

You may also like:

Separately, administrators distributed training materials covering reverse engineering and debugging tools such as IDA Pro.

DPRK Developers in DeFi

Just this week, cybersecurity researcher Taylor Monahan said North Korea-linked IT workers have been operating in the crypto sector for years, and even contributed to major DeFi protocols. Monahan explained that many of their resumes reflected real development experience rather than fabricated backgrounds.

Projects such as SushiSwap, Yearn, and THORChain were among those cited. The security expert also added that these actors later played an important role in enabling large-scale exploits.

Additionally, North Korean-affiliated hacking group Lazarus Group has been linked to some of the industry’s highest-profile hacks, such as the $625 million Ronin Bridge exploit in 2022, the $235 million WazirX hack in 2024, and the more recent $1.4 billion Bybit heist in 2025.

SPECIAL OFFER (Exclusive)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source: https://cryptopotato.com/zachxbt-uncovers-3-5m-operation-by-north-korean-fake-devs-inside-crypto-firms/

Market Opportunity
Helium Mobile Logo
Helium Mobile Price(MOBILE)
$0.0001348
$0.0001348$0.0001348
-1.10%
USD
Helium Mobile (MOBILE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!