BTC $63,408.63 +0.61%
ETH $1,899.52 +1.06%
BNB $605.42 -0.01%
XRP $1.00 +0.12%
SOL $75.42 -0.04%
TRX $0.3323 +0.39%
DOGE $0.0701 +0.57%
ADA $0.1770 +0.06%
BCH $204.73 +0.85%
LINK $9.44 +0.58%
HYPE $58.77 +2.81%
AAVE $86.64 +0.52%
SUI $0.6774 +0.24%
XLM $0.1584 +1.01%
ZEC $491.99 +0.76%
BTC $63,408.63 +0.61%
ETH $1,899.52 +1.06%
BNB $605.42 -0.01%
XRP $1.00 +0.12%
SOL $75.42 -0.04%
TRX $0.3323 +0.39%
DOGE $0.0701 +0.57%
ADA $0.1770 +0.06%
BCH $204.73 +0.85%
LINK $9.44 +0.58%
HYPE $58.77 +2.81%
AAVE $86.64 +0.52%
SUI $0.6774 +0.24%
XLM $0.1584 +1.01%
ZEC $491.99 +0.76%

north

All
Article
Flash

North Korea dismantles an elite hacking group involved in infiltrating central banks and foreign trade banks to steal funds and launder money through cryptocurrency

According to South Korean media Daily NK, North Korean authorities arrested an elite hacker group on July 12, which is suspected of infiltrating the internal networks of the North Korean central bank and foreign trade bank, stealing national trade funds and laundering money through cryptocurrency. Sources say the group's leader is a veteran from the cyber warfare unit under the North Korean Reconnaissance General Bureau, who recruited talented IT graduates from Kim Chaek University of Technology and Pyongyang University of Science and Technology, using encrypted communications and wireless devices to commit crimes.They split the stolen funds into small amounts and transferred them to overseas cryptocurrency wallets, exchanged them for cash through intermediaries, and then converted them into dollars and other currencies in border areas. Pyongyang officials launched an investigation after discovering anomalies in foreign currency payment approvals and records of overseas IP access, ultimately raiding a safe house and arresting suspects who were laundering money, seizing equipment worth hundreds of thousands of dollars. This case has caused a stir among the elite and military circles in Pyongyang, with senior officials in the Reconnaissance General Bureau and the science and education sector worried about being implicated. North Korea has long been accused of stealing billions of dollars in cryptocurrency assets through hacker organizations like the Lazarus Group, but this incident rarely shows that its own financial system has also become a target of internal attacks.

Humanity releases the investigation report on the security incident: the main network bridge was not affected, and the attack tools and methods exhibit characteristics of North Korean hackers

Humanity released an independent investigation report by Quantstamp, which disclosed that in the H token security incident, the attacker used tools and methods characteristic of North Korean hackers, disguising themselves as communication from the Bithumb exchange through phishing emails, inducing project directors to click on malicious attachments, thereby deploying a remote control Trojan on their devices, ultimately gaining full desktop control and wallet private keys. Subsequently, on Ethereum and BNB Chain, they launched on-chain attacks: on the Ethereum side, by stealing keys to upgrade contracts and transferring approximately 141.18 million H tokens, and on the BSC side, by taking over the ProxyAdmin contract and minting new tokens. The stolen assets were then continuously sold on Uniswap and PancakeSwap for about 8 hours, causing significant impact on liquidity and market prices.Currently, the H token contract on the Ethereum side has been frozen, the mainnet bridge remains unaffected, but the BSC deployment has been controlled by the attacker and still has minting permissions. The team is working with exchanges and security parties to advance subsequent disposal and recovery plans, while reminding users to be wary of false "compensation/claim" links, and stated that further progress will be announced through official channels.Previously, the Humanity Protocol was attacked, resulting in the leak of a private key from a member of the Humanity Foundation, leading to over 31 million dollars in funds being stolen.

CertiK Report: North Korean hackers caused approximately 60% of digital asset thefts by 2025, with attack patterns shifting to "offline infiltration."

Web3 security company CertiK has released the "Skynet North Korea Cyber Threat Report." The data shows that since 2016, North Korean hacker groups have plundered approximately $6.75 billion in digital assets. In 2025 alone, the losses from thefts they orchestrated reached as high as $2.06 billion, accounting for nearly 60% of the total losses in the global cryptocurrency industry for the entire year (including the $1.5 billion Bybit theft case). As of early 2026, this threat trend continues, with losses accounting for about 55%.The report emphasizes that the attack patterns of North Korean hackers have undergone a fundamental shift, evolving from simple code vulnerability exploitation to a national-level attack system that combines social engineering, deep supply chain attacks, and "physical infiltration." In the recent Drift protocol incident, attackers even spent six months lurking at offline industry conferences, establishing trust through real funds and interpersonal interactions before executing their attack.CertiK security experts warn that in the face of such systemic attacks, simple technical defenses have become weak. Cryptocurrency institutions urgently need to fully implement a "zero trust" hiring model, strengthen third-party supply chains, establish fund circuit breaker mechanisms, and collaborate with professional security organizations to build a comprehensive lifecycle defense system covering code audits, round-the-clock risk monitoring, and on-chain anti-money laundering/KYT (Know Your Transaction) fund tracking.

U.S. court approves Aave to transfer $71 million worth of ETH related to North Korean hacking incident

U.S. Manhattan Federal Court Judge Margaret Garnett approved Aave's asset recovery plan following the rsETH attack incident, allowing approximately $71 million in ETH that had previously been frozen on Arbitrum to be transferred to a wallet controlled by Aave.Court documents show that this decision modifies a prior injunction against the Arbitrum DAO, allowing the community to complete the ETH transfer through on-chain governance voting, while exempting participants in the voting and execution of the transfer from related legal liabilities. This incident stems from the rsETH attack that occurred in April, which has been widely attributed to the Lazarus Group, linked to North Korea. Previously, lawyers representing the families of North Korean terrorism victims had sought to freeze the related assets and attempted to include them in the compensation for an outstanding judgment of approximately $877 million.The Arbitrum community has shown strong support in a Snapshot temperature check vote for returning the frozen ETH to Aave's recovery plan, but the actual transfer still requires formal approval through on-chain governance. Reports indicate that this case is also part of the U.S. plaintiffs' efforts to recover crypto assets associated with North Korea. In addition to Arbitrum, the plaintiffs had previously sued the privacy protocol Railgun DAO and listed Digital Currency Group (DCG) as one of the defendants, accusing it of participating in related governance and economic activities.
app_icon
ChainCatcher Building the Web3 world with innovations.