North Korean IT Workers Used Fake IDs to Target Crypto Firms, Exposing $680K Favrr Hack
A compromised device from a North Korean IT worker has revealed intricate details of a cybercriminal operation targeting cryptocurrency companies. The team, consisting of six members, employed over 30 fake identities, including fabricated government-issued IDs and purchased LinkedIn and Upwork accounts, to infiltrate blockchain projects.
Evidence extracted from the device shows the operatives Leveraged Google-powered tools, AnyDesk, and VPNs to execute their schemes. On-chain investigator ZachXBT traced wallet activity to the June 2025 exploit of fan-token marketplace Favrr, linking one address (0x78e1a) directly to stolen funds.
The group falsely claimed experience at prominent blockchain firms such as Polygon Labs, OpenSea, and others to secure development roles. Their tactics highlight the growing sophistication of state-affiliated cyber threats in the crypto sector.