
Researcher Vangelis Stykas identified 700–800 damaging intrusions targeting crypto wallets and blockchain infrastructure, with contractors linking to 30 companies each.
North Korean hackers compromised systems linked to 1,640 companies across 57 countries, with cryptocurrency wallets and blockchain infrastructure among their primary targets, according to research presented at the Black Hat security conference and reported by Wired.
Cybersecurity researcher Vangelis Stykas of Kumio said between 700 and 800 of the affected organizations suffered damaging intrusions. Attackers gained access to corporate servers, cloud infrastructure, developer credentials, and digital assets.
Stykas spent 22 months inside command and control systems used by the hackers. He reviewed about five terabytes of data from compromised infrastructure and communications platforms. By examining developer credentials, source code, and other stored information, he identified potential victims.
He said he contacted affected organizations and publicly identified around a dozen companies during his Black Hat presentation. Those named included crypto companies Coinbase and Uniswap Labs, Boston Children’s Hospital, Japanese technology firm AEON Smart Technology, smartphone manufacturer Oppo, Italy’s Supreme Judicial Council, and a technology agency linked to the Flemish government.
Coinbase told Wired it had investigated a contractor before Stykas’ warning and found no evidence the individual was based in North Korea or affiliated with its government. The exchange said its security systems flagged risks suggesting the contractor may have outsourced work to another person. Coinbase terminated the contractor within 30 days of onboarding and said no sensitive information or customer data was exposed.
Boston Children’s Hospital said the incident involved the personal device of a former independent contractor, not its internal systems. It disabled the remaining credentials and found no evidence its systems were accessed without authorization.
The Flemish government said authorities isolated an affected workstation after receiving Stykas’ disclosure in March. Credentials were revoked and replaced, and the organization said the incident was contained.
The hackers approached software developers with fake employment offers featuring high salaries. Targets were told to download software or complete coding tests that installed malware on their devices. The tactic is known as the Contagious Interview campaign, which uses fake recruiters, technical interviews, and malicious code repositories. Microsoft has documented North Korean groups using similar methods to steal credentials and access company systems.
External contractors amplified the attack’s reach. Some compromised contractors held credentials for as many as 30 organizations, Stykas said.
Although several affected organizations held sensitive corporate, government, or health information, Stykas said the hackers focused largely on obtaining cryptocurrency wallet credentials and blockchain access.
The findings come as US authorities continue warning companies about North Korean remote technology workers who use false identities to secure employment and gain access to corporate networks. The FBI said North Korean workers impersonate people from other countries to obtain remote positions and generate revenue for the government. US authorities have linked these employment schemes to cryptocurrency theft and efforts to fund North Korea’s weapons programs.
For broader context on crypto market exposure, see crypto market analysis.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.