BTCC / BTCC Square / Global Cryptocurrency /
North Korean Developer Compromises Waves Protocol Wallet in Credential-Stealing Attack

North Korean Developer Compromises Waves Protocol Wallet in Credential-Stealing Attack

Published:
2025-06-19 00:11:02
5
1

A North Korean operative infiltrated the codebase of Waves Protocol's Keeper-Wallet, inserting malicious code to harvest sensitive user data. The attacker, operating under the GitHub alias "AhegaoXXX," gained elevated privileges to modify dependencies and redirect package namespaces—a clear sign of insider-level access.

Repository analytics show the wallet's repositories had lain dormant since August 2023 before suspicious activity resumed in May 2025. The compromised account could publish updates to NPM, create releases, and alter critical infrastructure. Forensic evidence ties the actor to DPRK IT contracting rings known for infiltrating software projects through freelance channels.

The most damning modification surfaces in the Keeper-Wallet-Extension commit logs: a function designed to exfiltrate wallet logs, runtime errors, and—most critically—mnemonic phrases and private keys to an external server. This breach underscores the growing sophistication of state-sponsored crypto attacks.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users