Kraken Thwarts North Korean Hacker Posing as Job Applicant

By: financefeeds|2025/05/02 16:30:02
Share
copy
U.S.-based crypto exchange Kraken revealed that it uncovered and blocked a North Korean hacking attempt disguised as a job application for an engineering role. The scheme was detailed in a blog post on Wednesday and shows the increasing use of social engineering and insider threats by state-backed cybercriminals targeting the crypto industry. According to Kraken, the red flags emerged early in the interview process when the candidate used a different name than the one on their application and intermittently switched voices during the call—suggesting someone was coaching them live. Rather than cutting the process short, Kraken advanced the applicant through additional stages to collect intelligence on the hacker’s methods. The exchange later confirmed the applicant’s email matched a known address linked to North Korea’s cyber units , which had been flagged by industry partners sharing intelligence on ongoing threats. The investigation revealed a broader network of fake identities used by the hacker to apply to several firms, including signs of manipulated ID documents, a resume tied to a GitHub profile linked to an exposed email, and suspicious login behavior involving VPNs and remote Mac desktops. In the final round of interviews, Kraken’s chief security officer, Nick Percoco, ran a series of identity verification traps that the applicant failed, confirming the person behind the screen was not who they claimed to be. The individual’s ID appeared to contain details lifted from a previous identity theft case. “This wasn’t just a fake candidate—it was a coordinated attempt to get inside a crypto company,” said Percoco. “In today’s environment, the old rules don’t apply. Trust has to be earned—and verified.” The attempted breach follows warnings from U.S., Japanese, and South Korean authorities that North Korea has been actively embedding IT workers in blockchain and crypto firms to exfiltrate funds or intelligence. Lazarus Group , a notorious North Korean hacking collective, was blamed for February’s record-breaking $1.4 billion Bybit hack and several others totaling over $650 million in 2024 alone.

You may also like

Key Market Intelligence on December 30th, how much did you miss out on?

1. On-chain Volume: $31.6M inflow to Base this week; $57.8M outflow from Arbitrum 2. Biggest Gainers and Losers: $BETA, $LGCT 3. Top News: LIT rebounds 18% in the past hour, with Polymarket predicting a 52% probability of its "first-day market cap exceeding $30 billion"

Matrixdock 2025: The Practical Path to Sovereign-Grade RWA of Gold Tokenization

Gold Tokenization is becoming one of the first asset types to undergo a reality check in this transformation.

$50 to $1 Million: How to Survive in the Meme Battlefield with 'Wallet Tracking'

My reliance is not on the luck of a single transaction skyrocketing, but on consistently capturing replicable market patterns.

Paradigm's Tempo Project Launches Testnet, Is It Worth Checking Out?

The current testnet already supports basic EVM functionality and has launched features such as payment channels, stablecoin gas mechanism, and decentralized exchange components.

When Everyone Uses AI Trading, Where Does Cryptocurrency Alpha Go in 2026?

In 2025, AI trading has become the default, but Alpha hasn’t disappeared — it’s been eroded by crowding, as similar data, models, and strategies cause traders to act in sync and lose their edge.
Real Alpha has shifted to harder-to-copy layers like behavioral and on-chain data, execution quality, risk management, and human judgment in extreme markets, where acting differently — or not acting at all—matters more than better predictions.

Without Narrative Power, Web3 Will Not Tap into the Vastness

In the Web3 space, the importance of storytelling far surpasses any other industry.

Popular coins

Latest Crypto News

Read more