Tag: Cryptocurrency theft

  • Prosecutors Allege Cybercriminal Directed $2.6M Crypto Heist From Prison

    Prosecutors Allege Cybercriminal Directed $2.6M Crypto Heist From Prison

    Key Highlights

    • Incarcerated cybercriminal Robert Barr directed a crypto-theft syndicate from HMP Edinburgh between January and April 2024, targeting a local entrepreneur’s holdings valued at over $2.6 million.
    • Two home-invasion attempts failed: the first in January netted a hardware wallet but no PIN or recovery phrase; the second in April was foiled when the homeowner spotted intruders via a video doorbell camera.
    • Barr and accomplice Sean Favier have pleaded guilty to serious organized crime and attempted robbery charges; sentencing by Judge Lord Cubie is deferred pending background reports.

    Prison-Run Crypto Syndicate Targets Scottish Entrepreneur

    Prosecutors at the High Court in Edinburgh revealed on September 23 that Robert Barr, already serving sentences for fraud and illicit mobile-phone possession at HMP Edinburgh, orchestrated a sophisticated cryptocurrency theft operation from inside his cell. Between January and April 2024, Barr acted as the leader of an organized crime gang that twice attempted to raid the Midlothian home of an unnamed local entrepreneur who co-founded a startup and has been investing in digital assets since 2014.

    High-Value Target and Failed January Raid

    According to prosecution advocate David Dickson, Barr believed the victim’s cryptocurrency portfolio exceeded $2.6 million (£2 million), including $1.32 million in a self-created digital coin. During the initial break-in in January 2024, intruders stole a physical hardware wallet but were unable to access the funds because they lacked the device’s PIN and recovery seed phrase. Dickson told the court the assets remained secure despite the theft of the hardware itself.

    Technical Escalation: Remote Access and AnyDesk Deployment

    Undeterred, Barr organized a second attempt in April, this time instructing associates to gain remote control of the victim’s computers using remote-desktop software. Court documents read by prosecutors showed Barr messaging an accomplice: “When they’re in his house gonna need [to] get him on his PC fast [and] download AnyDesk rapid.” Barr also offered to join the raid via Telegram to guide the team through transferring the cryptocurrency once remote access was established.

    Video Doorbell Foils Second Attempt

    The April 17, 2024, operation collapsed when the homeowner spotted two men approaching and alerted his wife not to open the door. When she spoke through the video doorbell application, the suspects noticed the camera, attempted to conceal their faces, and fled the scene. The footage and subsequent investigation led authorities to seize an illicit mobile phone from Barr’s cell on June 25, 2024. Forensic analysis of that device uncovered extensive evidence of Barr organizing and providing technical support for crypto-theft schemes.

    Why This Matters

    The case highlights a growing intersection between traditional organized crime and cyber-enabled asset theft, demonstrating that incarceration does not necessarily neutralize sophisticated digital offenders. Barr’s ability to coordinate physical break-ins, direct remote-access tooling, and manage encrypted communications from a Scottish prison cell underscores the challenges correctional facilities face in contraband device detection and network monitoring. For the cryptocurrency sector, the episode reinforces the critical importance of multi-factor hardware wallet security—specifically, the protection of PINs and seed phrases—which rendered the stolen device useless to the thieves. Law-enforcement agencies across the UK are likely to cite this prosecution as a precedent for pursuing offenders who blend physical violence with advanced cyber tactics, and for seeking enhanced digital-forensics capabilities within prison environments.

    Frequently Asked Questions

    Who is Robert Barr and what has he pleaded guilty to?

    Robert Barr is a convicted fraudster who was serving time at HMP Edinburgh. He pleaded guilty at the High Court in Edinburgh to involvement in serious organized crime between January and April 2024, specifically directing a gang that attempted to steal cryptocurrency from a local entrepreneur.

    How much cryptocurrency was the target holding, and why was the first theft unsuccessful?

    Prosecutors estimated the victim’s holdings at over $2.6 million (£2 million), including $1.32 million in a self-created coin. The January break-in yielded a hardware wallet, but the thieves could not access the funds because they did not possess the device’s PIN or recovery seed phrase.

    What happened to the accomplices and when will sentencing occur?

    Accomplice Sean Favier pleaded guilty to attending the Midlothian property in an attempt to commit robbery and steal cryptocurrency assets. Judge Lord Cubie deferred sentencing for both Barr and Favier pending background reports; both men remain remanded in custody.

  • £10,000 Reward Offered for Information on Birmingham Crypto Robbery

    £10,000 Reward Offered for Information on Birmingham Crypto Robbery

    Key Highlights

    • A £10,000 Crimestoppers reward has been announced for information leading to the arrest and conviction of those responsible for a targeted cryptocurrency home robbery in Smith’s Wood, Birmingham.
    • The December 13, 2025 attack involved three masked men who forced entry, assaulted the husband, threatened the pregnant wife with a knife, and demanded a substantial cryptocurrency transfer while a fourth suspect coordinated via video call.
    • West Midlands Police and Crimestoppers renewed their appeal on September 24, releasing CCTV footage and describing one suspect as a Black man in his twenties with a diagonal scar beneath his left eyebrow; the getaway vehicle is believed to be a black BMW X3.

    Targeted Cryptocurrency Robbery Shakes Smith’s Wood Community

    A violent, meticulously planned home invasion in the Smith’s Wood area of Birmingham has prompted a £10,000 reward offer from Crimestoppers as investigators continue hunting for four suspects involved in a cryptocurrency-focused robbery that left a young couple traumatized. The charity announced the reward on September 24, nearly nine months after the December 13, 2025 incident, underscoring the complexity of the investigation and the determination of authorities to bring the perpetrators to justice.

    Coordinated Attack Involving Remote Direction via Video Call

    According to Crimestoppers and West Midlands Police, the robbery unfolded at approximately 5:20 p.m. when the couple returned to their residence. Three men exited a nearby vehicle and forced their way through the front door behind the victims. Once inside, the attackers demanded a substantial transfer of cryptocurrency, a detail that has led investigators to classify the crime as a targeted operation rather than an opportunistic burglary.

    Adding a layer of sophistication, a fourth individual—believed to be the orchestrator—relayed real-time instructions to the three intruders through a video call during the robbery. This remote coordination suggests pre-meditation and technical awareness, distinguishing the case from typical home invasions. The husband sustained serious injuries in the assault, while his wife, who was pregnant with their third child at the time, was threatened at knifepoint. The assailants fled with the cryptocurrency and several high-value watches, escaping in what witnesses and CCTV indicate was a black BMW X3.

    Suspect Descriptions and Investigative Appeals

    West Midlands Police have confirmed that all three men who entered the property are believed to be in their twenties and wore face coverings and hoods, significantly limiting visual identification. However, one suspect has been described as a Black man with a distinctive small diagonal scar beneath his left eyebrow—a feature investigators hope will trigger public recognition. Crimestoppers has released CCTV footage capturing the forced entry, appealing for anyone who may recognize the suspects, the vehicle, or the sequence of events to come forward.

    Authorities have not disclosed the specific cryptocurrency involved, the monetary value of the transfer, or any blockchain addresses associated with the stolen funds. This operational secrecy is standard in ongoing investigations involving digital assets, where blockchain analysis may play a pivotal role in tracing the proceeds.

    Why This Matters: The Rising Threat of Crypto-Targeted Home Invasions

    This case highlights a disturbing trend in the United Kingdom: the convergence of physical violence and cryptocurrency crime. As digital asset adoption grows, criminals are increasingly targeting known holders through home invasions, kidnappings, and coercive transfers—exploiting the irreversible and pseudonymous nature of blockchain transactions. The use of a video call to direct the robbery in real time signals a level of operational security and technical sophistication that challenges traditional investigative methods. For law enforcement, such cases demand coordination between cybercrime units, forensic blockchain analysts, and frontline officers. For the public, especially cryptocurrency holders, the incident underscores the importance of operational security, including avoiding public disclosure of holdings, using multi-signature wallets, and implementing physical security measures at home. The September 24 appeal renewal suggests the investigation remains active but has hit hurdles in suspect identification, making public assistance critical.

    Frequently Asked Questions

    How can I claim the £10,000 Crimestoppers reward?

    To qualify for the reward, you must submit information directly to Crimestoppers—either through their website or by calling 0800 555 111—and request a reward code during your initial contact. Online submissions must also use the charity’s “keeping in contact” facility. Information given directly to the police does not qualify. The reward is paid only if the information leads to the arrest and conviction of those responsible.

    Is my identity protected if I contact Crimestoppers?

    Yes. Crimestoppers guarantees anonymity: callers do not need to provide personal information, calls are not recorded, and computer IP addresses are not traced. The charity operates independently of the police to ensure informants’ safety and confidentiality.

    What details are investigators still seeking?

    Authorities are looking for anyone who may recognize the suspect with the diagonal scar beneath his left eyebrow, the black BMW X3 used as the getaway vehicle, or the three masked men seen on the released CCTV footage. Any information about the planning, the video call coordinator, or the disposal of the stolen watches and cryptocurrency could prove vital.

  • North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    Key Highlights

    • North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters from legitimate crypto and AI companies to target software developers and IT professionals worldwide.
    • The campaign infected over 30,000 devices across more than 100 countries and extracted funds or credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
    • A joint advisory from Japan, Germany, Australia, and the United States links WaterPlum to North Korea’s Munitions Industry Department and its broader strategy of placing undercover IT workers inside foreign organizations.

    Global Advisory Exposes Sophisticated Recruitment Fraud

    A joint cybersecurity advisory issued by authorities in Japan, Germany, Australia, and the United States has detailed a sprawling operation by the North Korean hacking group WaterPlum, also tracked as Contagious Interview. The group masqueraded as recruiters for legitimate artificial intelligence, cryptocurrency, and non-fungible token (NFT) companies, leveraging social media platforms, online job boards, gig work sites, and freelance marketplaces to lure victims. According to the advisory, the primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The operation has resulted in the theft of at least $10.7 million, marking a significant escalation in North Korea’s use of social engineering to fund its weapons programs.

    Malware Deployment via Fake Coding Assignments

    The attack chain relied on tricking job seekers into downloading and executing malicious files disguised as coding assignments or fixes for video-conferencing errors. Once executed, the malware provided the threat actors with backdoor access to the victim’s computer. WaterPlum operators then deployed remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. The advisory notes that successful infections create downstream risks, enabling WaterPlum actors to infiltrate the organizations that employ the compromised developers, thereby extending the blast radius beyond individual freelancers to corporate networks.

    Connection to North Korean IT Worker Infiltration

    The advisory explicitly links WaterPlum’s activities to North Korea’s broader campaign of placing IT workers inside foreign companies under false pretenses. Japanese and U.S. authorities assess that WaterPlum actors and certain North Korean IT workers operate under the direction of the country’s Munitions Industry Department. This dual-track approach—stealing cryptocurrency directly while simultaneously building a workforce of impersonators—amplifies the regime’s revenue generation. Stolen identity documents allow North Korean operatives to impersonate legitimate developers, securing employment and income, while sensitive personal data harvested during intrusions creates opportunities for extortion.

    Recent Incidents Highlight Ongoing Threat

    The advisory cites concrete examples of the infiltration tactic. In one case, a suspected North Korean IT worker applied for an engineering role at a Japanese cryptocurrency exchange using a forged resume; the applicant was rejected after failing to demonstrate the claimed skills during the interview. More recently, in July, Cointelegraph reported that blockchain software company Consensys had unknowingly engaged a North Korea-linked developer as a consultant. Consensys confirmed it terminated the contractor’s access upon discovering the threat, stating an investigation found no theft of assets or data, no malicious code deployment, and no impact on user safety. These incidents underscore the persistent difficulty organizations face in vetting remote technical talent.

    Why This Matters

    The WaterPlum campaign represents the latest evolution in North Korea’s long-standing reliance on cryptocurrency theft to circumvent international sanctions and fund its nuclear and ballistic missile programs. The Federal Bureau of Investigation (FBI) previously attributed the $1.5 billion theft from the Bybit exchange in February 2025 to North Korean actors. U.S. authorities have issued warnings about the regime’s undercover IT worker scheme since at least 2018. The convergence of direct financial theft, supply chain compromise via compromised developers, and strategic workforce infiltration signals a mature, well-resourced threat ecosystem. For the cybersecurity industry and any organization hiring remote technical talent, the advisory serves as a critical reminder that identity verification and device trust cannot be assumed based solely on a resume or interview performance.

    Frequently Asked Questions

    What is WaterPlum and how does it operate?

    WaterPlum, also known as Contagious Interview, is a North Korean state-sponsored hacking group. It operates by posing as recruiters from legitimate AI, crypto, and NFT companies on job platforms. The group tricks software developers and IT professionals into downloading malware disguised as coding tests or software fixes, gaining backdoor access to steal cryptocurrency, credentials, and sensitive data.

    How can job seekers protect themselves from such recruitment scams?

    Job seekers should verify the legitimacy of recruiters and companies through independent channels before downloading any files. Be wary of unsolicited offers, requests to execute code as part of an interview process, or pressure to install specific video-conferencing software or “fixes.” Use endpoint detection and response (EDR) solutions and maintain strict separation between personal and work devices.

    What are the implications for companies hiring remote developers?

    Companies face the risk of inadvertently hiring North Korean operatives using stolen identities, which can lead to intellectual property theft, infrastructure compromise, and regulatory violations. The Consensys incident demonstrates that even sophisticated firms can be deceived. Organizations must implement rigorous identity verification, background checks, technical assessments that cannot be easily faked, and continuous monitoring of contractor activity.

  • Cryptocurrency App Secretly Steals Assets — Delete Immediately

    Cryptocurrency App Secretly Steals Assets — Delete Immediately

    Key Highlights

    • Blockchain security firm SlowMist, in collaboration with the OKX security team, discovered malicious code in FomoPeek versions 1.1 and 1.2 designed to steal private keys, seed phrases, and Keychain data from iOS devices.
    • The malware includes an exploit framework targeting iOS kernel vulnerabilities across versions 12.0 through 18.7 and 26.0–26.1, capable of bypassing sandbox protections and automatically selecting from eight attack methods based on device model.
    • SlowMist urges all affected users to immediately migrate assets to a new wallet generated on a clean device, update iOS to the latest version, and permanently cease using FomoPeek.

    SlowMist Uncovers Supply-Chain Attack in FomoPeek iOS App

    Blockchain security company SlowMist has issued a critical alert revealing that versions 1.1 and 1.2 of the FomoPeek application contain malicious code engineered to exfiltrate users’ private keys, seed phrases, login credentials, and other sensitive data stored in the iOS Keychain. The discovery followed reports from multiple FomoPeek users who experienced unexplained asset theft, prompting a joint forensic investigation by SlowMist and the OKX security team.

    Exploit Framework Targets Broad iOS Version Range

    According to SlowMist’s technical analysis, the compromised application bundles an exploit framework wholly unrelated to FomoPeek’s stated functionality. This framework specifically targets kernel vulnerabilities in Apple’s iOS operating system, supporting eight distinct attack vectors. The malware automatically fingerprints the victim’s device model and iOS version to select the appropriate exploit, enabling it to bypass the iOS sandbox and decrypt Keychain contents.

    The affected iOS versions span a remarkably wide range: iOS 12.0 through 18.7, as well as the newly released iOS 26.0 and 26.1. This coverage suggests the attackers maintained and updated their exploit chain over an extended period, potentially impacting millions of devices that have not applied the very latest security patches.

    Active Command-and-Control Infrastructure

    SlowMist researchers further determined that FomoPeek communicates with hidden command-and-control (C2) servers not associated with any legitimate public service. Analysis of intercepted unencrypted network traffic indicates the attack functions remain active and execute automatically at regular intervals, meaning the threat is ongoing and not merely a dormant payload.

    Why This Matters

    This incident represents a sophisticated supply-chain compromise targeting cryptocurrency users through a seemingly legitimate application. The breadth of iOS versions exploited underscores the persistent value of kernel-level vulnerabilities to threat actors and the difficulty of defending against zero-day or n-day exploits once they are weaponized in widely distributed software. For the crypto ecosystem, the case highlights the critical importance of verifying application integrity, using hardware wallets for significant holdings, and maintaining rigorous device hygiene. The collaboration between SlowMist and OKX also demonstrates the growing role of exchange security teams in threat intelligence sharing and incident response.

    Frequently Asked Questions

    Which FomoPeek versions are confirmed compromised?

    Only versions 1.1 and 1.2 have been identified as containing the malicious exploit framework and data-exfiltration code.

    What should I do if I installed FomoPeek 1.1 or 1.2?

    Immediately check your wallet for unauthorized transactions. Using a trusted device on which FomoPeek was never installed, generate a new private key and mnemonic phrase, then transfer all assets to the new wallet. Update your iPhone or iPad to the latest iOS version, delete FomoPeek, and do not reinstall it.

    Does updating iOS alone fix the problem?

    Updating iOS patches the kernel vulnerabilities used by the exploit, preventing future Keychain decryption. However, if your private keys or seed phrases were already stolen, the attacker retains control of the associated wallets. You must rotate credentials on a clean device as described above.

  • Japan’s National Police Agency Exposes North Korean Hackers in Joint Operation with US, Australia, Germany

    Japan’s National Police Agency Exposes North Korean Hackers in Joint Operation with US, Australia, Germany

    Key Highlights

    • A seven-nation intelligence coalition publicly attributed a global cryptocurrency theft campaign to the North Korean group WaterPlum (alias “Contagious Interview”), linking the operation to the 313 General Bureau of the Munitions Industry Department under the Central Committee of the Workers’ Party of Korea.
    • Fake job recruitment schemes targeting software developers compromised over 30,000 devices across 100+ countries and breached approximately 7,000 cryptocurrency accounts, diverting an estimated 1.7 billion yen ($10.71 million) to North Korea between December 2025 and July 2026.
    • Japanese authorities dismantled a domestic “laptop farm” used to conceal the physical location of North Korean IT workers, marking the first such intervention in Japan and exposing a broader labor fraud network routing hundreds of millions of yen annually to Pyongyang.

    Seven-Agency Coalition Unmasks WaterPlum Operation

    In a coordinated announcement on Friday, September 18, 2026, seven national security agencies jointly exposed a North Korean cyber operation that has been masquerading as technology recruiters to steal cryptocurrency from information technology professionals worldwide. The advisory bears the seals of Japan’s National Police Agency (NPA) and National Cybersecurity Office, the United States Federal Bureau of Investigation (FBI) and Department of Defense Cyber Crime Center (DC3), Australia’s ASD Cyber Security Centre, and Germany’s Bundesnachrichtendienst (BND) and Bundesamt für Verfassungsschutz (BfV).

    The disclosure was made under a “public attribution” framework—a deliberate diplomatic and legal strategy designed to deter future attacks by formally naming the state sponsor and operational units behind malicious cyber activity. According to the joint assessment of the NPA and FBI, the hackers operating under the WaterPlum banner, alongside a contingent of North Korean IT workers, operate under the direct command of the 313 General Bureau of the Munitions Industry Department, a subunit of the Central Committee of the Workers’ Party of Korea. This chain of command confirms the operation as a state-directed revenue generation program for Pyongyang’s weapons development, a charge U.S. intelligence agencies have leveled repeatedly in previous North Korean cryptocurrency theft campaigns—allegations the North Korean regime has consistently denied.

    Fake Recruitment Lure: How the Malware Campaign Worked

    The threat actors posed as hiring managers at artificial intelligence firms, cryptocurrency ventures, and non-fungible token startups, extending attractive job offers to software developers. Candidates were guided through technical interviews or coding assignments, then instructed to download and execute files framed as assessment tasks. Those files were weaponized: they carried malware embedded in Node Package Manager (npm) packages, deploying a suite of custom payloads identified as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

    Once installed, the malware established persistent backdoors via remote-access trojans, enabling operators to harvest browser-stored passwords, keystroke logs, screenshots, and—critically—the private keys and seed phrases that control cryptocurrency wallets. Between December 2025 and July 2026, the campaign infected more than 30,000 devices in over 100 countries and compromised sensitive credentials for roughly 7,000 cryptocurrency accounts, yielding the 1.7 billion yen ($10.71 million) in diverted assets.

    Malware Arsenal and Technical Infrastructure

    The five identified malware families represent a modular toolkit designed for credential theft, system surveillance, and long-term access maintenance. Researchers note the use of legitimate software supply chains—specifically the npm registry—as a delivery vector, allowing the malicious packages to blend with routine development workflows. The stolen private keys and seed phrases provided direct, irreversible control over victims’ on-chain assets, facilitating rapid liquidation and laundering through North Korea’s established cryptocurrency mixing and exchange networks.

    Japan’s First Laptop Farm Takedown

    The advisory reveals a second, parallel operation: North Korean IT workers residing in North Korea, China, and Russia fraudulently secured remote programming and web-development contracts, funneling hundreds of millions of yen in wages back to the regime over several years. To obscure the true geographic origin of this labor, the network enlisted local facilitators to operate “laptop farms”—physical locations housing devices that made the remote workers appear to be logging in from within the hiring country.

    Japanese investigators identified, raided, and shut down one such laptop farm operated by a domestic enabler, marking the first known disruption of this infrastructure type in Japan. The takedown illustrates how North Korea’s revenue generation blends cyber intrusion with labor fraud, exploiting the global shift toward remote work to bypass sanctions and financial controls.

    Why This Matters

    The WaterPlum attribution arrives amid a sharp escalation in state-sponsored cryptocurrency theft. The advisory cites a 420% surge in malware targeting public blockchains, with North Korea and Iran identified as primary originators. In June 2026, G7 leaders formally classified North Korean cryptocurrency theft as a significant security threat, citing an estimated $6.75 billion stolen since 2016 by Pyongyang-linked actors. Independent research presented at Black Hat by Vangelis Stykas corroborates the scale: his analysis traced North Korean infiltration into 1,640 companies across 57 countries, frequently initiated through the same fake job offers that deliver malware, as reported by Cryptopolitan. The seven-agency public attribution signals a strategic shift toward collective deterrence, exposing not only the hackers but the institutional command structure that directs them.

    Frequently Asked Questions

    What is WaterPlum and who controls it?

    WaterPlum (also known by the alias “Contagious Interview”) is a North Korean cyber operation attributed by seven national intelligence agencies to the 313 General Bureau of the Munitions Industry Department, a unit under the Central Committee of the Workers’ Party of Korea. The group conducts cryptocurrency theft and labor fraud to fund North Korea’s weapons programs.

    How did the fake job scheme steal cryptocurrency?

    Attackers posed as recruiters at AI, crypto, and NFT companies. After interviews, victims were sent malware-laced npm packages (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle) disguised as coding tests. The malware installed remote-access trojans, stealing browser passwords, keystrokes, screenshots, and—most critically—private keys and seed phrases for cryptocurrency wallets, enabling direct asset theft.

    What is a “laptop farm” and why is Japan’s takedown significant?

    A “laptop farm” is a physical facility where local enablers host devices that make North Korean remote workers appear to be logging in from within the hiring country (e.g., Japan). Japan’s disruption of such a farm is the first known case of its kind in the country, exposing a key infrastructure layer that allows North Korea to evade sanctions and labor laws while routing wages back to the regime.

  • North Korea Recruits Foreign Talent to Infiltrate US Companies, Report Finds

    North Korea Recruits Foreign Talent to Infiltrate US Companies, Report Finds

    North Korea is increasingly recruiting IT workers from third countries—including Iran and Lebanon—to help infiltrate U.S. companies and funnel salaries back to state agencies funding weapons programs, NBC News reported Friday.

    U.S. Alert Details North Korean IT Worker Scheme

    A joint advisory issued in July by the U.S. government and several foreign agencies warned that North Korean IT workers “seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information.”

    Tactics Shift to Third-Country Intermediaries

    As the United States and partner governments have tightened screening to counter North Korea’s remote-work infiltration, the DPRK has adapted by using foreign nationals to pass initial job interviews. According to the NBC report, once contracts are secured, North Korean operatives typically take over the positions.

    Foreign IT workers have been recruited on LinkedIn, with some offered $500 per month in cryptocurrency to work part-time as “interview associates,” the report said.

    Cyber Operations Yield Billions in Crypto Theft

    The regime’s evolving tactics appear to be paying off. Cointelegraph reported in May, citing cybersecurity firm CrowdStrike, that North Korean state-affiliated hackers and threat actors were responsible for more than $2 billion in cryptocurrency losses in 2025—a 51% year-over-year increase.

    Economy Grows Despite Sanctions

    The Bank of Korea estimates North Korea’s gross domestic product grew 3.5% in 2025, even as international sanctions remain in place.

  • Predictable Wallet Seed Phrases Tied to $5.69M Theft, Security Firm Reports

    Predictable Wallet Seed Phrases Tied to $5.69M Theft, Security Firm Reports

    Critical CryptoJS Vulnerability Exposes Wallet Seed Phrases, $5.69M Stolen

    Blockchain security firm Coinspect has uncovered a critical vulnerability in the random number generator of the widely used CryptoJS library, making recovery phrases in at least five cryptocurrency wallet applications predictable. The flaw has been actively exploited since May, resulting in an estimated minimum of $5.69 million in stolen funds, according to a report by CryptoSlate.

    How the Vulnerability Was Exploited

    Coinspect’s analysis revealed that the flawed random number generator allowed attackers to predict seed phrases—the sequences of words used to back up and restore wallets. The firm documented three separate attack waves:

    • May 27: Approximately $3.14 million drained
    • May 30 – July 13: Additional $2.55 million traced
    • July 20 – 21: Third attack causing roughly $40,000 in losses

    Researchers noted that more than 2,000 seed phrases across five blockchain networks appear to have been affected. However, the specific list of impacted wallet applications and the full scale of damage remain unclear, as some victims may not have publicly reported losses.

    Implications for Wallet Security

    This incident highlights a persistent challenge in cryptocurrency security: even well-intentioned code can introduce systemic risks. CryptoJS is a popular JavaScript library used for cryptographic functions, and its random number generation was found to be insufficient for generating secure keys. While the library is widely used, not all applications may be affected—only those that relied on the vulnerable implementation for seed generation.

    For users, the incident underscores the importance of using wallets with audited, battle-tested code and hardware wallets for significant holdings. It also raises questions about the responsibility of open-source maintainers to ensure cryptographic primitives meet current security standards.

    What Users Should Do

    Wallet users who suspect they may be affected should immediately transfer funds to a newly generated wallet with a hardware device or a reputable software wallet that uses audited random number generation. They should also monitor blockchain addresses associated with their seed phrases for unauthorized transactions.

    For developers, this serves as a reminder to use established libraries for random number generation, such as those based on Web Crypto API, and to conduct thorough security reviews.

    Conclusion

    The discovery by Coinspect reveals a serious flaw in a widely used library, leading to significant financial losses. While the full impact is still being assessed, the incident emphasizes the need for rigorous security practices in cryptocurrency wallet development and user vigilance. As the investigation continues, affected users are advised to act promptly to secure their assets.

    FAQs

    What is a wallet seed phrase?

    A wallet seed phrase is a set of words that acts as a backup for a cryptocurrency wallet. It allows users to recover their funds if the wallet is lost or damaged.

    How can I tell if my wallet is affected by this vulnerability?

    If you used a wallet app that relied on the CryptoJS library for seed generation, you may be at risk. Check the wallet’s documentation or contact the provider. If you suspect exposure, move funds to a new wallet immediately.

    What should developers do to avoid such vulnerabilities?

    Developers should use cryptographically secure random number generators, such as those provided by the Web Crypto API, and avoid relying on general-purpose libraries for security-critical functions. Regular security audits are also essential.