最新报道:According to Bijie.com, an investigation by renowned blockchain sleuth ZachXBT has revealed extensive North Korean infiltration of the global cryptocurrency development recruitment market. An unnamed source recently hacked into the device of a North Korean IT worker and provided unprecedented insight into how a small team of five IT workers operated over 30 fake identities. North Korean operatives are flooding the cryptocurrency recruitment market. According to ZachXBT's tweet, North Korean teams used government-issued IDs to register accounts on Upwork and LinkedIn to secure developer positions on various projects. Investigators discovered an export of the worker's Google Drive, Chrome profile, and screenshots, revealing that Google products were central to the organization's schedules, tasks, and budgets, with communications primarily conducted in English. Among these files was a spreadsheet from 2025 containing weekly reports from team members, revealing their inner workings and mindsets. Typical entries included statements such as "I don't understand the job requirements and don't know what I need to do" and self-directed notes such as "Solution/Fix: Dedicate sufficient effort." Another spreadsheet tracked expenses, showing charges for purchasing Social Security numbers, Upwork and LinkedIn accounts, phone numbers, AI subscriptions, computer rentals, and VPN or proxy services. Meeting schedules and scripts for fake identities were also recovered, including one named "Henry Zhang." The group's operating methods included purchasing or leasing computers, performing work remotely using AnyDesk, and converting earned fiat currency into cryptocurrency through Payoneer. A wallet address associated with the group, 0x78e1, was linked on-chain to a $680,000 exploit involving Favrr in June 2025. The project's CTO and other developers were later identified as North Korean IT workers using fraudulent documents. Other North Korean-linked workers were linked to the project through the 0x78e1 address. Signs of their North Korean origin included frequent use of Google Translate and Korean searches conducted from Russian IP addresses. ZachXBT stated that these IT workers were not particularly sophisticated, but their persistence was aided by the large number of positions they targeted globally. Challenges in responding to these actions include poor cooperation between private companies and services, as well as resistance from teams when reporting fraudulent activity. The ongoing threat from North Korea: North Korean hackers, particularly the Lazarus Group, continue to pose a significant threat to the industry. In February 2025, the group orchestrated the largest cryptocurrency exchange hack in history, stealing approximately $1.5 billion in Ethereum from Dubai-based Bybit. The attack exploited vulnerabilities in the third-party wallet provider Safe{Wallet}, allowing hackers to bypass multi-signature security measures and transfer funds to multiple wallets. The FBI attributed the breach to North Korean operatives, labeled "TraderTraitor." Subsequently, in July 2025, the Indian cryptocurrency exchange CoinDCX fell victim to a $44 million theft also linked to the Lazarus Group. The attackers infiltrated CoinDCX's liquidity infrastructure and exploited exposed internal credentials to carry out the theft.