"The digital space has become the new battlefield. You don't need tanks here, just skill and patience." — Bruce Schneier, cybersecurity expert
In 2025, a new cyberattack scenario emerged involving a state-sponsored hacker group from North Korea. Four agents, operating on behalf of the Lazarus Group, carried out a series of attacks against startups in the cryptocurrency and Web3 space. One of their targets was a small American crypto project that lost approximately $900,000 in the fraud.
This story is not just another case of stolen crypto assets. It illustrates how professional hackers leverage social engineering, fake profiles, and bogus job offers to gain access to crypto wallets and siphon off funds without a trace.
According to Chainalysis and investigative reports, the Lazarus Group employs a consistent scheme:
In this case, four individuals using fabricated identities were hired by a small DeFi-focused crypto platform. Posing as developers, they gained wallet access and, after several months, transferred the funds to external addresses.
The investigation revealed a methodical approach by the attackers:
Alarmingly, one of the employees in the security team was part of this group, allowing them to bypass internal controls and gain direct access to transactions.
The hackers actively leveraged:
This multi-chain strategy allowed them to evade most monitoring systems and move assets out of reach. Arkham data shows the funds passed through at least six intermediary addresses before reaching the final recipients.
The Lazarus Group, linked to Kim Jong Un’s regime, has long used cybercrime to fund its operations. Chainalysis reports that they are responsible for stealing over $3 billion in cryptoassets in the past five years.
In 2025, their tactics became even more sophisticated:
These attacks demonstrate that North Korean cyber threats are not abating but growing in complexity and scale.
Defending against this type of attack is challenging but possible. Consider these precautions when hiring and working with remote developers:
Additionally, maintain ongoing employee verification—check not just technical skills but work history, community involvement, and online presence.
Chainalysis reports that in 2025, the Lazarus Group:
The U.S., South Korea, and Japan have set up special units to counter these threats. Yet, as this incident shows, even well-protected firms can fall victim.
Alexander Vlasov, a crypto cybersecurity expert, notes:
"The key to defense lies not just in code but in people. If you don't vet your staff, you're already vulnerable."
Steps you can take:
This incident sent a clear message to the crypto business: internal threats can be as dangerous as external ones. As a result, there is growing interest in:
There’s also increased attention on decentralized identity and zero-knowledge proofs to reduce risk when onboarding remote staff.
The $900,000 heist is just one of many. In 2025, crypto protocols and startups must prepare for:
For startups and small teams, it’s a wake-up call to reassess hiring policies—especially regarding access to wallets, smart contracts, and internal tools. For investors, it’s a reminder to exercise caution when funding high‑risk projects.
