Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

Ripple to share North Korean threat intelligence with crypto firms

CN
coindesk
Follow
3 hours ago
AI summarizes in 5 seconds.


What to know : Ripple is sharing its internal intelligence on North Korean threat actors with the Crypto ISAC to help crypto firms spot coordinated infiltration campaigns. Recent attacks like the Drift and Kelp exploits relied on long-term social engineering and malware, not smart contract bugs, allowing North Korean operatives to steal more than $500 million in a month. The Lazarus Group’s alleged role in these thefts is now influencing legal battles, including efforts to claim frozen Arbitrum-linked funds for victims of North Korean terrorism, even as it remains unclear whether industry-wide intel sharing will curb future attacks.

Ripple is now sharing its internal threat intelligence on North Korean hackers with the crypto industry, the company said Monday, in a move that reframes how the sector is responding to a shift in DPRK attack methodology.

The Drift hack was not a hack in the way most people think of one.

Nobody found a bug or exploited a smart contract. North Korean operatives spent months befriending Drift's contributors, slipped malware onto their machines, and walked off with the keys. By the time the $285 million moved, every system that was supposed to catch a hack had nothing to flag.

That is the version of events Ripple and Crypto ISAC, the crypto industry's threat-sharing group, laid out Monday alongside news that Ripple is now sharing its internal data on North Korean threat actors with the rest of the sector.

The 2022-24 wave of more DeFi hacks was centred on exploiting code, with attackers finding smart contract vulnerabilities and draining protocols in minutes.

But as security gets tighter, the modus operandi shifts from technology to people. Rogue operatives apply for jobs at crypto firms, pass background checks, show up on Zoom calls and build trust for months. Then they deploy attacks that no traditional security tool was built to catch, because the attacker is already inside.

Ripple is now feeding Crypto ISAC the kind of profile data that makes that pattern legible across companies. LinkedIn profiles, email addresses, locations, contact numbers — or the connective tissue that lets a security team recognise the candidate they just interviewed as the same operative who failed background checks at three other firms last week.

"The strongest security posture in crypto is a shared one," Ripple posted on X. "A threat actor who fails a background check at one company will apply to three more that same week. Without shared intelligence, every company starts from zero."

Lazarus Group's reach across the crypto sector is now visible enough that it has begun reshaping legal proceedings as well as security ones.

On Monday, an attorney representing victims of North Korean terrorism served restraining notices on Arbitrum DAO, arguing that the 30,765 ETH frozen after April's Kelp bridge exploit is North Korean property under U.S. enforcement law.

Lending company Aave has since disputed that filing in support of Arbitrum, arguing that a "thief does not gain lawful ownership of stolen property simply by taking it."

The Kelp breach had drained $292 million in ether (ETH) and was also publicly attributed to Lazarus Group operatives, putting April's Drift and Kelp losses together at more than half a billion dollars tied to a single state actor in the span of a single month.

Whether industry-level intelligence sharing actually slows the campaigns is the open question. The same operatives may already be in the next round of interviews somewhere.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by coindesk

56 minutes ago
DeFi lender Aave asks court to block $71 million crypto seizure tied to North Korea claims
2 hours ago
Bitcoin used to hate inflation. Now it might be the opposite
3 hours ago
Bitcoin crosses $81,000, ETH, SOL, DOGE steady as options desks bid on further price jump
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarbitcoin.com
43 minutes ago
Hut 8 Taps Falconx for $200M Facility, Drops Rate to 7% and Boosts BTC Access
avatar
avatarcoindesk
56 minutes ago
DeFi lender Aave asks court to block $71 million crypto seizure tied to North Korea claims
avatar
avatarbitcoin.com
1 hour ago
Bitcoin Breaks $81,000 Behind ETF Inflows, Iran De-escalation and a Short Squeeze
avatar
avatarcoindesk
2 hours ago
Bitcoin used to hate inflation. Now it might be the opposite
avatar
avatarbitcoin.com
2 hours ago
From Rebels to Banks: Why the Crypto Industry Is Finally Embracing Legacy Finance
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink