How Four North Korean Hackers Stole $900,000 from an American Crypto Startup

"The digital space has become the new battlefield. You don't need tanks here, just skill and patience." — Bruce Schneier, cybersecurity expert

In 2025, a new cyberattack scenario emerged involving a state-sponsored hacker group from North Korea. Four agents, operating on behalf of the Lazarus Group, carried out a series of attacks against startups in the cryptocurrency and Web3 space. One of their targets was a small American crypto project that lost approximately $900,000 in the fraud.

This story is not just another case of stolen crypto assets. It illustrates how professional hackers leverage social engineering, fake profiles, and bogus job offers to gain access to crypto wallets and siphon off funds without a trace.

🧩 How Did North Korean Hackers Infiltrate the Crypto Startup?

According to Chainalysis and investigative reports, the Lazarus Group employs a consistent scheme:

  • Creating fake profiles on LinkedIn, X, and GitHub;
  • Submitting resumes to blockchain-related startups;
  • Obtaining remote access to internal systems;
  • Deploying malware and laundering assets via cross-chain transactions.

In this case, four individuals using fabricated identities were hired by a small DeFi-focused crypto platform. Posing as developers, they gained wallet access and, after several months, transferred the funds to external addresses.

🔐 How the Attack Was Carried Out: Technical Details

The investigation revealed a methodical approach by the attackers:

  1. Creating fake profiles claiming experience at major companies;
  2. Infiltrating the company through remote work arrangements;
  3. Deploying malware to extract private keys;
  4. Transferring funds to cross-chain pools (Arbitrum, Optimism, Binance Chain);
  5. Laundering via OTC exchanges and privacy coins (Monero, Zcash).

Alarmingly, one of the employees in the security team was part of this group, allowing them to bypass internal controls and gain direct access to transactions.

⛓️ Which Blockchains Were Used in the Attack?

The hackers actively leveraged:

  • Ethereum — for initial access to the DeFi protocol;
  • Arbitrum — to lower gas fees and obscure activity;
  • Binance Chain — to convert into BNB and BUSD;
  • Monero (XMR) — to fully conceal the trail of transfers.

This multi-chain strategy allowed them to evade most monitoring systems and move assets out of reach. Arkham data shows the funds passed through at least six intermediary addresses before reaching the final recipients.

🧠 How Does the Lazarus Group Orchestrate Attacks on Crypto Projects?

The Lazarus Group, linked to Kim Jong Un’s regime, has long used cybercrime to fund its operations. Chainalysis reports that they are responsible for stealing over $3 billion in cryptoassets in the past five years.

In 2025, their tactics became even more sophisticated:

  • Fake recruitment agencies;
  • Using AI to generate fraudulent portfolios;
  • Embedding within development teams;
  • Setting up sham companies to launder funds;
  • Integrating with NFT marketplaces to mask activity.

These attacks demonstrate that North Korean cyber threats are not abating but growing in complexity and scale.

🛡️ How to Protect Your Startup from Such Threats?

Defending against this type of attack is challenging but possible. Consider these precautions when hiring and working with remote developers:

  • Verify identities via KYC platforms and biometric checks;
  • Analyze resumes and portfolios using specialized vetting services;
  • Monitor on-chain activity with DeFi explorers;
  • Use multi-sig wallets instead of single-signature;
  • Encrypt sensitive data and restrict access rights;
  • Audit contracts regularly via CertiK or OpenZeppelin;
  • Train security teams to spot phishing attempts;
  • Implement data loss prevention (DLP) systems.

Additionally, maintain ongoing employee verification—check not just technical skills but work history, community involvement, and online presence.

📊 2025 Threat Landscape: Statistics and Scale

Chainalysis reports that in 2025, the Lazarus Group:

  • Conducted over 12 major attacks on crypto projects;
  • Stole more than $180 million in cryptocurrency;
  • Used over 80 fake profiles to infiltrate companies;
  • Communicated heavily via Telegram and Discord;
  • Employed AI generators to craft false portfolios.

The U.S., South Korea, and Japan have set up special units to counter these threats. Yet, as this incident shows, even well-protected firms can fall victim.

🧠 Expert Insight: How to Detect and Prevent Such an Attack?

Alexander Vlasov, a crypto cybersecurity expert, notes:

"The key to defense lies not just in code but in people. If you don't vet your staff, you're already vulnerable."

Steps you can take:

  • Check geolocation data on connections;
  • Analyze user behavior within systems;
  • Use biometric access for critical systems;
  • Monitor suspicious transactions via Nansen, Arkham, and Dune;
  • Train staff on wallet security best practices;
  • Implement zero-trust architecture for internal systems;
  • Establish internal controls for crypto assets;
  • Conduct regular pentests and bug bounty programs.

📈 Impact on the Market and Crypto Startup Industry

This incident sent a clear message to the crypto business: internal threats can be as dangerous as external ones. As a result, there is growing interest in:

  • Employee verification services;
  • Cybersecurity platforms;
  • Internal monitoring and control solutions;
  • Multi-sig and cold storage adoption;
  • Developing robust internal security frameworks.

There’s also increased attention on decentralized identity and zero-knowledge proofs to reduce risk when onboarding remote staff.

📊 Conclusion: North Korean Cyber Threats in 2025

The $900,000 heist is just one of many. In 2025, crypto protocols and startups must prepare for:

  • State-sponsored hackers intensifying social engineering;
  • Phishing and fake job offers becoming part of cyber warfare;
  • Rising laundering via NFTs, privacy coins, and cross-chain transactions;
  • Crypto projects needing to boost internal security measures.

For startups and small teams, it’s a wake-up call to reassess hiring policies—especially regarding access to wallets, smart contracts, and internal tools. For investors, it’s a reminder to exercise caution when funding high‑risk projects.

16.07.2025, 03:03