|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CoinDesk 最近發布了一項調查,詳細介紹了北韓人如何滲透該行業,發現十幾家加密貨幣公司

An extensive crypto investigation has uncovered a widespread infiltration by North Korean hackers, posing significant legal and cybersecurity risks for companies and investors in the industry.
一項廣泛的加密貨幣調查發現北韓駭客的廣泛滲透,給該行業的公司和投資者帶來了重大的法律和網路安全風險。
According to the report, over a dozen crypto companies have fallen victim to tactics employed by the Democratic People's Republic of Korea (DPRK) to circumvent sanctions and obtain funds from these projects.
該報告稱,十幾家加密貨幣公司已成為朝鮮民主主義人民共和國(DPRK)為規避制裁並從這些項目中獲取資金而採取的策略的受害者。
The investigation revealed that several companies, including prominent projects like Fantom, Injective, Yearn Finance, ZeroLend, and Sushi, had unknowingly hired IT workers from the DPRK.
調查顯示,包括 Fantom、Injective、Yearn Finance、ZeroLend 和 Sushi 等知名專案在內的多家公司在不知情的情況下僱用了來自北韓的 IT 員工。
Interviews with founders, industry experts, and blockchain researchers during the investigation indicated that the infiltration was "far more prevalent" than initially suspected.
調查期間對創始人、行業專家和區塊鏈研究人員的採訪表明,滲透比最初懷疑的「普遍得多」。
Most hiring management teams consulted during the investigation reported having interviewed and hired suspected DPRK developers or knew someone who had.
調查期間接受諮詢的大多數招募管理團隊都表示曾採訪並僱用了可疑的北韓開發商或認識有此類嫌疑的人。
Blockchain developer Zaki Manian disclosed that he had unknowingly hired two North Korean IT workers in 2021 to help develop the Cosmos Hub blockchain.
區塊鏈開發者 Zaki Manian 透露,他在 2021 年不知不覺中僱用了兩名北韓 IT 工人來幫助開發 Cosmos Hub 區塊鏈。
"Everyone is struggling to filter out these people," said Manian, adding that the probability of a job applicant being from the DPRK "is greater than 50% across the entire industry."
馬尼安說:「每個人都在努力過濾掉這些人。」他補充說,求職者來自北韓的機率「在整個行業中超過 50%」。
On-chain investigator ZachXBT had initially highlighted the North Korean chain of exploits in August, revealing that he had discovered over 25 crypto projects with DPRK-linked developers that had been active since June 2024.
鏈上調查員 ZachXBT 最初在 8 月強調了北韓的一系列漏洞,並透露他發現了超過 25 個與北韓有聯繫的開發人員的加密項目,這些項目自 2024 年 6 月以來一直活躍。
The crypto sleuth went on to reveal the names and addresses of 21 IT workers who had infiltrated the industry in just those three months.
這位加密貨幣偵探隨後透露了在短短三個月內滲透到該行業的 21 名 IT 員工的姓名和地址。
"North Korea is receiving $300K – $500K / month from working at 25+ projects at once by using fake identities," ZachXBT stated.
ZachXBT 表示:“北韓透過使用虛假身份同時參與 25 個以上項目,每月獲得 30 萬至 50 萬美元的收入。”
The report noted that North Korean cyberattacks "don't tend to resemble the Hollywood version of hacking." Instead, the hackers typically use some form of social engineering to gain the team's trust and ultimately obtain access to the project's private keys, often through a malicious link.
報告指出,北韓的網路攻擊「並不像好萊塢版的駭客攻擊」。相反,駭客通常使用某種形式的社會工程來獲得團隊的信任,並最終通常透過惡意連結來存取專案的私鑰。
"To date, we have never seen DPRK do, like, a real exploit. It's always social engineering, and then compromise the device, and then compromise the private keys," said Taylor Monian, Product Manager at MetaMask.
MetaMask 產品經理 Taylor Monian 表示:“迄今為止,我們從未見過朝鮮進行真正的利用。它總是社會工程,然後危害設備,然後危害私鑰。”
The North Korean developers often use fake documentation to disguise their nationality, as many countries prohibit hiring workers from the DPRK due to sanctions.
北韓開發商經常使用虛假文件來掩飾其國籍,因為許多國家因制裁而禁止僱用北韓工人。
After being hired, the malicious actors initially perform well to gain their employers' trust. However, over time, inconsistencies in their work and story begin to emerge, leading the crypto companies to realize they have been targeted in a coordinated attack.
惡意行為者在被雇用後,最初表現良好,以贏得雇主的信任。然而,隨著時間的推移,他們的工作和故事開始出現不一致,導致加密貨幣公司意識到他們已成為協調攻擊的目標。
In some cases, teams have discovered that they were working with multiple individuals who presented as one person or that several of their employees were all the same person.
在某些情況下,團隊發現他們正在與多個以同一個人身份出現的人一起工作,或者他們的幾名員工都是同一個人。
As reported by Bitcoinist, the Ethereum Layer-2 NFT gaming platform Munchables fell victim to an attack of this nature.
根據 Bitcoinist 報導,以太坊 Layer-2 NFT 遊戲平台 Munchables 成為此類攻擊的受害者。
In March, the project lost, and later recovered, over $60 million in crypto after a developer turned hacker.
今年 3 月,一名開發人員成為駭客後,該專案損失了超過 6,000 萬美元的加密貨幣,後來又恢復了。
The heist was later revealed to be an inside job and was linked by several industry figures like Laura Shin and ZachXBT to the North Korean government.
後來,這起搶劫案被揭露為內部人員所為,勞拉·辛 (Laura Shin) 和 ZachXBT 等幾位業內人士將其與北韓政府聯繫起來。
Additionally, it was suspected that four of the developers in the team were all one person.
另外,團隊中的四名開發人員疑似都是一人。
The investigation ultimately showed that several crypto projects that employed DPRK IT workers later fell victim to hacks, including Sushi in 2021 and, most recently, Delta Primes in September 2024.
調查最終顯示,幾個僱用北韓 IT 員工的加密項目後來成為駭客攻擊的受害者,包括 2021 年的 Sushi 和最近的 2024 年 9 月的 Delta Primes。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































