CryptoMediaClub
Monday, October 27, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

ZachXBT Exposes 5 North Korean Workers Running 30+ Fake Identities to Target Crypto Projects

13.08.2025
A A
0
119
VIEWS
ShareShare

Renowned blockchain investigator ZachXBT has exposed an elaborate scheme involving five North Korean IT workers who created more than 30 fake identities.

These operatives used government-issued ID cards and purchased professional accounts on Upwork and LinkedIn to get jobs with cryptocurrency projects as developers.

Anonymous Source Compromises North Korean IT Workers’ Devices to Reveal Operation Details

According to on-chain intelligence published on August 13, an unidentified informant successfully breached a Democratic People’s Republic of Korea (DPRK) IT worker’s device, providing insight into how this five-person team executed their employment fraud operation.

The compromised data included exports from Google Drive, Chrome browser profiles, and device screenshots.

3/ Another spreadsheet shows weekly reports for team members from 2025 which provides insight into how they operate and what they think about.
“I can't understand job requirement, and don't know what I need to do”
“Solution / fix: Put enough efforts in heart” pic.twitter.com/rYkDC3jESf

— ZachXBT (@zachxbt) August 13, 2025

All communications were conducted in English. Financial documentation obtained from the breach shows the technology job syndicate’s systematic approach to acquiring the necessary tools for their deception.

Their expense spreadsheet details purchases of Social Security numbers, professional (LinkedIn and Upwork) accounts, phone numbers, artificial-intelligence subscriptions, computer rental services, and VPN/proxy networks.

All of these were designed to meet blockchain industry employment requirements and facilitate access to internal systems and codebases.

ZachXBT’s investigation revealed documentation outlining meeting schedules for targeted cryptocurrency projects, alongside detailed scripts for maintaining the fraudulent identity “Henry Zhang.”

The operatives utilized AnyDesk software to access convenient VPN services, allowing them to appear as if they were located in regions they falsely claimed as their residence to employers.

The leaked materials included Telegram conversations where team members discussed successful job placements and payment arrangements. In these exchanges, they shared ERC-20 wallet addresses designated for salary deposits.

The investigation took a major turn when ZachXBT traced one frequently used ERC-20 wallet address (0x78e1) back to the recent $680,000 Favrr exploit that occurred in June 2025.

This incident involved the project’s chief technology officer and additional developers who were later identified as DPRK IT workers operating with fraudulent credentials.

8/ The 0x78e1 address is closely tied onchain to the recent $680K Favrr exploit from June 2025 where their CTO and other devs turned out to be DPRK ITWs with fraudulent documents.
Additional DPRK ITWs were identified at projects from the 0x78e1 address. https://t.co/BPZmFo8n5d pic.twitter.com/DcQnvNetxY

— ZachXBT (@zachxbt) August 13, 2025

This revelation prompted several cryptocurrency projects to conduct internal investigations, discovering that some of their development teams and decision-makers were North Korean operatives using false identities.

Evidence Confirms North Korean Workers’ Origin Despite Skepticism

When community members questioned the operatives’ North Korean origins, ZachXBT pointed to compelling evidence within the leaked materials.

Beyond the fraudulent documentation, browser history data showed extensive Google Translate usage with Korean language translations, all originating from Russian IP addresses.

10/ Still one of the more common questions is “how do you know they are North Korean?”
Well besides all of the fraudulent documents detailed above their search history showed frequent Google Translate usage with translations to Korean with a Russian IP. pic.twitter.com/wtTgzaiNcy

— ZachXBT (@zachxbt) August 13, 2025

The cryptocurrency community’s reaction has been mixed, with many pointing to hiring negligence among teams that become defensive when alerted to potential security threats.

Some community members emphasized the depth of the fake identity and account creation ecosystem, suggesting that numerous crypto projects may be unaware of who actually has access to their GitHub repositories and sensitive code.

“It’s an operational hazard for the industry,” explained Shaun Potts, founder of crypto-focused recruiting firm Plexus, who told Cryptonews in a related situation in July.

“It’s an ongoing challenge, similar to how hacking persists in technology. While you cannot eliminate it entirely, you can minimize associated risks.”

The crypto industry has shown varying success rates in identifying these threats.

For example, cryptocurrency exchange Kraken successfully identified a potential North Korean threat actor masquerading as a job candidate in May.

However, others have fallen victim to these sophisticated operations.

In January, these technologically adept scammers allegedly stole $2.2 million worth of cryptocurrency from New York residents through text message campaigns claiming to offer remote job assistance.

🇰🇵 DPRK-linked perpetrators landed in remote IT jobs using fake and stolen identities and exploited their company’s trust to steal and launder over $900,000 in crypto.#DPRK #NorthKoreaCrypto #CryptoScamhttps://t.co/6UvXug5OZp

— Cryptonews.com (@cryptonews) July 1, 2025

The scheme involved requesting job-seekers to deposit Tether (USDT) and USD Coin (USDC) stablecoins into designated cryptocurrency accounts.

Similarly, in June, U.S. authorities seized more than $7.7 million in cryptocurrency allegedly earned through a covert network of North Korean IT workers who posed as foreign freelancers while channeling their income back to the North Korean government.

The post ZachXBT Exposes 5 North Korean Workers Running 30+ Fake Identities to Target Crypto Projects appeared first on Cryptonews.

Share9Tweet6ShareSharePin2

Related Posts

Crypto Transfers Between Korean Exchanges and Cambodia’s Huione Jump 1,400x to $8.9M
All news

Crypto Transfers Between Korean Exchanges and Cambodia’s Huione Jump 1,400x to $8.9M

27.10.2025
0

Cryptocurrency transfers between South Korea’s largest exchanges and Cambodia’s Huione Guarantee surged nearly 1,400 times last year. Key Takeaways: Crypto...

Read moreDetails
Bitcoin Nears $116K as Stocks Rally on Signs of Thaw in US-China Trade Tensions

Bitcoin Nears $116K as Stocks Rally on Signs of Thaw in US-China Trade Tensions

27.10.2025
Sharplink Gaming Adds $80M in Ethereum to Strategic Reserve After Month-Long Lull

Sharplink Gaming Adds $80M in Ethereum to Strategic Reserve After Month-Long Lull

27.10.2025
Ledger Faces Backlash Over New Multisig App Fees Despite Technical Upgrade

Ledger Faces Backlash Over New Multisig App Fees Despite Technical Upgrade

27.10.2025
Your Crypto Isn’t Safe Outside the Blockchain, Vitalik Buterin Warns

Your Crypto Isn’t Safe Outside the Blockchain, Vitalik Buterin Warns

27.10.2025
Load More
Next Post
GENIUS Act Bombshell? Banking Groups Demand Stablecoin Interest Loophole Close Before Cash Flees

GENIUS Act Bombshell? Banking Groups Demand Stablecoin Interest Loophole Close Before Cash Flees

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

FTX’s $3.4B Liquidation Sends Shockwaves Through Crypto Market

FTX’s $3.4B Liquidation Sends Shockwaves Through Crypto Market

2 years ago
ChatGPT’s BTC Analysis Shows Key $112K Support Amid $333M ETF Outflows as Bull Run Faces Uncertainty

ChatGPT’s BTC Analysis Shows Key $112K Support Amid $333M ETF Outflows as Bull Run Faces Uncertainty

3 months ago
Laos halts electricity supply to crypto mining projects amid drought

Laos halts electricity supply to crypto mining projects amid drought

2 years ago
Argo Blockchain Appoints Ex-CBOE Digital Leader As New CEO

Argo Blockchain Appoints Ex-CBOE Digital Leader As New CEO

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Ledger Faces Backlash Over New Multisig App Fees Despite Technical Upgrade

Your Crypto Isn’t Safe Outside the Blockchain, Vitalik Buterin Warns

Kyrgyzstan Launches Stablecoin on BNB Chain, Eyes National Digital Currency and Crypto Reserve

Ethereum Price Prediction: Key Weekly Bounce Confirms Strength, Eyes Crucial Resistance Breakout

XRP Price Prediction: Outpacing Other Altcoins XRP Closes Week Up 11.4% – Momentum Building?

Coinbase CEO Wants Every Startup to Launch, Fund, and IPO Onchain

Trending

Crypto Transfers Between Korean Exchanges and Cambodia’s Huione Jump 1,400x to $8.9M
All news

Crypto Transfers Between Korean Exchanges and Cambodia’s Huione Jump 1,400x to $8.9M

27.10.2025
0

Cryptocurrency transfers between South Korea’s largest exchanges and Cambodia’s Huione Guarantee surged nearly 1,400 times last year....

Bitcoin Nears $116K as Stocks Rally on Signs of Thaw in US-China Trade Tensions

Bitcoin Nears $116K as Stocks Rally on Signs of Thaw in US-China Trade Tensions

27.10.2025
Sharplink Gaming Adds $80M in Ethereum to Strategic Reserve After Month-Long Lull

Sharplink Gaming Adds $80M in Ethereum to Strategic Reserve After Month-Long Lull

27.10.2025
Ledger Faces Backlash Over New Multisig App Fees Despite Technical Upgrade

Ledger Faces Backlash Over New Multisig App Fees Despite Technical Upgrade

27.10.2025
Your Crypto Isn’t Safe Outside the Blockchain, Vitalik Buterin Warns

Your Crypto Isn’t Safe Outside the Blockchain, Vitalik Buterin Warns

27.10.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz