BTCC / BTCC Square / Global Cryptocurrency /
North Korean IT Workers Unmasked in $680K Crypto Scam Through ZachXBT Investigation

North Korean IT Workers Unmasked in $680K Crypto Scam Through ZachXBT Investigation

Published:
2025-08-14 09:45:02
25
1
BTCCSquare news:

Five North Korean IT operatives orchestrated a sophisticated crypto scam by fabricating over 30 false identities, complete with forged government documents and professional profiles on LinkedIn and Upwork. The scheme unraveled when an anonymous source breached one worker's device on August 13, exposing detailed operational records including expense spreadsheets and falsified credentials.

The group invested $1,489.8 in May alone to maintain their cover, purchasing fake IDs, VIRTUAL phone numbers, VPN services, and AI tool subscriptions. A critical breakthrough came when blockchain sleuth ZachXBT linked their 0x78e1 wallet address to the $680,000 Favrr marketplace exploit in June 2025, revealing the team's direct involvement in the heist.

Operational tactics included consistent English communications, Google Translate for localization, AnyDesk for remote access, and VPNs to mask their geographic origins. The compromised data provided unprecedented insight into North Korea's crypto infiltration methods, showing deliberate targeting of development roles within blockchain projects.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users