市值: $2.194T -0.11%
成交额(24h): $64.9084B 1.19%
  • 市值: $2.194T -0.11%
  • 成交额(24h): $64.9084B 1.19%
  • 恐惧与贪婪指数:
  • 市值: $2.194T -0.11%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

朝鲜渗透针对整个加密货币行业

2024/10/03 23:00

CoinDesk 最近发布了一项调查,详细介绍了朝鲜人如何渗透该行业,发现十几家加密货币公司

朝鲜渗透针对整个加密货币行业

An extensive crypto investigation has uncovered a widespread infiltration by North Korean hackers, posing significant legal and cybersecurity risks for companies and investors in the industry.

一项广泛的加密货币调查发现朝鲜黑客的广泛渗透,给该行业的公司和投资者带来了重大的法律和网络安全风险。

According to the report, over a dozen crypto companies have fallen victim to tactics employed by the Democratic People's Republic of Korea (DPRK) to circumvent sanctions and obtain funds from these projects.

该报告称,十几家加密货币公司已成为朝鲜民主主义人民共和国(DPRK)为规避制裁并从这些项目中获取资金而采取的策略的受害者。

The investigation revealed that several companies, including prominent projects like Fantom, Injective, Yearn Finance, ZeroLend, and Sushi, had unknowingly hired IT workers from the DPRK.

调查显示,包括 Fantom、Injective、Yearn Finance、ZeroLend 和 Sushi 等知名项目在内的多家公司在不知情的情况下雇佣了来自朝鲜的 IT 员工。

Interviews with founders, industry experts, and blockchain researchers during the investigation indicated that the infiltration was "far more prevalent" than initially suspected.

调查期间对创始人、行业专家和区块链研究人员的采访表明,渗透比最初怀疑的“普遍得多”。

Most hiring management teams consulted during the investigation reported having interviewed and hired suspected DPRK developers or knew someone who had.

调查期间接受咨询的大多数招聘管理团队都表示曾采访并雇用了可疑的朝鲜开发商或认识有此类嫌疑的人。

Blockchain developer Zaki Manian disclosed that he had unknowingly hired two North Korean IT workers in 2021 to help develop the Cosmos Hub blockchain.

区块链开发者 Zaki Manian 透露,他在 2021 年不知不觉中雇佣了两名朝鲜 IT 工人来帮助开发 Cosmos Hub 区块链。

"Everyone is struggling to filter out these people," said Manian, adding that the probability of a job applicant being from the DPRK "is greater than 50% across the entire industry."

马尼安说:“每个人都在努力过滤掉这些人。”他补充说,求职者来自朝鲜的概率“在整个行业中超过 50%”。

On-chain investigator ZachXBT had initially highlighted the North Korean chain of exploits in August, revealing that he had discovered over 25 crypto projects with DPRK-linked developers that had been active since June 2024.

链上调查员 ZachXBT 最初在 8 月份强调了朝鲜的一系列漏洞,并透露他发现了超过 25 个与朝鲜有联系的开发商的加密项目,这些项目自 2024 年 6 月以来一直活跃。

The crypto sleuth went on to reveal the names and addresses of 21 IT workers who had infiltrated the industry in just those three months.

这位加密货币侦探随后透露了在短短三个月内渗透到该行业的 21 名 IT 员工的姓名和地址。

"North Korea is receiving $300K – $500K / month from working at 25+ projects at once by using fake identities," ZachXBT stated.

ZachXBT 表示:“朝鲜通过使用虚假身份同时参与 25 个以上项目,每月获得 30 万至 50 万美元的收入。”

The report noted that North Korean cyberattacks "don't tend to resemble the Hollywood version of hacking." Instead, the hackers typically use some form of social engineering to gain the team's trust and ultimately obtain access to the project's private keys, often through a malicious link.

报告指出,朝鲜的网络攻击“并不像好莱坞版的黑客攻击”。相反,黑客通常使用某种形式的社会工程来获得团队的信任,并最终通常通过恶意链接来访问项目的私钥。

"To date, we have never seen DPRK do, like, a real exploit. It's always social engineering, and then compromise the device, and then compromise the private keys," said Taylor Monian, Product Manager at MetaMask.

MetaMask 产品经理泰勒·莫尼安 (Taylor Monian) 表示:“迄今为止,我们从未见过朝鲜进行真正的利用。它总是社会工程,然后危害设备,然后危害私钥。”

The North Korean developers often use fake documentation to disguise their nationality, as many countries prohibit hiring workers from the DPRK due to sanctions.

朝鲜开发商经常使用虚假文件来掩饰其国籍,因为许多国家因制裁而禁止雇用朝鲜工人。

After being hired, the malicious actors initially perform well to gain their employers' trust. However, over time, inconsistencies in their work and story begin to emerge, leading the crypto companies to realize they have been targeted in a coordinated attack.

恶意行为者在被雇用后,最初表现良好,以赢得雇主的信任。然而,随着时间的推移,他们的工作和故事开始出现不一致,导致加密货币公司意识到他们已成为协调攻击的目标。

In some cases, teams have discovered that they were working with multiple individuals who presented as one person or that several of their employees were all the same person.

在某些情况下,团队发现他们正在与多个以同一个人身份出现的人一起工作,或者他们的几名员工都是同一个人。

As reported by Bitcoinist, the Ethereum Layer-2 NFT gaming platform Munchables fell victim to an attack of this nature.

据 Bitcoinist 报道,以太坊 Layer-2 NFT 游戏平台 Munchables 成为此类攻击的受害者。

In March, the project lost, and later recovered, over $60 million in crypto after a developer turned hacker.

今年 3 月,一名开发人员成为黑客后,该项目损失了超过 6000 万美元的加密货币,后来又恢复了。

The heist was later revealed to be an inside job and was linked by several industry figures like Laura Shin and ZachXBT to the North Korean government.

后来,这起抢劫案被揭露为内部人员所为,劳拉·辛 (Laura Shin) 和 ZachXBT 等几位业内人士将其与朝鲜政府联系起来。

Additionally, it was suspected that four of the developers in the team were all one person.

另外,团队中的四名开发人员疑似都是一个人。

The investigation ultimately showed that several crypto projects that employed DPRK IT workers later fell victim to hacks, including Sushi in 2021 and, most recently, Delta Primes in September 2024.

调查最终显示,几个雇用朝鲜 IT 员工的加密项目后来成为黑客攻击的受害者,包括 2021 年的 Sushi 和最近的 2024 年 9 月的 Delta Primes。

原文来源:bitcoinist

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月31日 发表的其他文章