Ethereum Wallet Threat Exposed in North Korean Hack Data With 1,640 Victims

ETH

ETH/USDT

$1,904.65
-0.64%
24h Volume

$7,557,415,680.03

24h H/L

$1,924.56 / $1,892.04

Change: $32.52 (1.72%)

Long/Short
59.2%
Long: 59.2%Short: 40.8%
Funding Rate

+0.0037%

Longs pay

Data provided by COINOTAG DATALive data
Ethereum
Ethereum
Daily

$1,911.06

0.11%

Volume (24h): -

Resistance Levels
Resistance 3$2,227.28
Resistance 2$2,063.38
Resistance 1$1,939.43
Price$1,911.06
Support 1$1,879.53
Support 2$1,823.98
Support 3$1,722.34
Pivot (PP):$1,897.47
Trend:Sideways
RSI (14):56.0
(06:43 PM UTC)
4 min read
AI SummaryAI
  • Vangelis Stykas identified 1,640 victim organizations across 57 countries after 22 months inside North Korean servers.
  • He collected about five terabytes of data including developer keys, source code, and Slack/Discord messages.
  • Stykas assessed that 700 to 800 organizations suffered serious breaches involving root access or wallet keys.
  • Palo Alto Networks labeled the fake-job attack pattern Contagious Interview in November 2023.

Crypto News

Ethereum (ETH) is the most directly relevant asset because the exposed operation pursued wallet keys, blockchain access, and developer credentials that can control digital funds. A Greek security researcher, Vangelis Stykas, chief technology officer at security firm Kumio, told the Black Hat conference in Las Vegas that he remained inside North Korean command-and-control servers for 22 months and identified 1,640 victim organizations across 57 countries. The tally came from the attackers' own records rather than outside estimates, giving the count unusual precision. Stykas said he collected about five terabytes of material, including developer keys, private source code, and internal messages on Slack and Discord. He assessed that 700 to 800 organizations suffered serious breaches, meaning the actors obtained root server access, AWS administrative control, or cryptocurrency wallet keys. That access places any asset tied to compromised keys at risk, from Bitcoin to a broad altcoin balance held by an exchange, fund, or developer. The disclosure also shows why large thefts can follow a single human mistake: once an attacker controls a privileged device, the blockchain layer may be secure while the custody layer fails. For Ethereum, the concern is amplified because smart-contract approvals, signing keys, and infrastructure accounts can be abused without altering the underlying protocol. The findings presented this week describe a sustained intelligence-gathering operation, not a one-time intrusion, and they suggest additional victims may still be discovered as the seized data is reviewed. The data set also included the crews' tools and communications, giving defenders a rare view of how intrusions moved from initial compromise to persistent control. Stykas warned that many organizations never responded after being notified, leaving the broader community to rely on shared threat intelligence rather than individual remediation alone. That makes the disclosure a live incident-response matter, particularly for teams holding signing keys or cloud credentials.

The second layer of the disclosure centers on the method: fake job offers rather than software bugs. Developers were approached with senior roles and attractive pay, then asked to complete take-home coding tests that secretly installed malware. Palo Alto Networks researchers labeled the pattern Contagious Interview in November 2023, and Microsoft later described malicious packages placed on GitHub, GitLab, and Bitbucket. When a developer opened one inside Visual Studio Code and accepted a trust prompt, the editor executed the attackers' code. The resulting backdoors searched for API tokens, cloud login details, signing keys, wallet files, and password-manager data. This makes the threat especially serious for Ethereum (ETH), because a compromised developer account or signing environment can authorize transactions and approvals without a visible protocol exploit. The risk extends to any custody model, whether a standard exchange account, an AI crypto wallet, or infrastructure connected to algorithmic stablecoins. One contractor's infected laptop could expose credentials for as many as 30 companies, turning a single endpoint into multiple entry points. Boston Children's Hospital was linked to a former contractor's personal device, though the hospital said credentials were revoked within hours and its systems showed no entry. In the crypto sector, Coinbase and Uniswap Labs were among organizations that responded after receiving warnings. Consensys also found a covert North Korean developer who had spent about one month working on MetaMask code. The financial scale underscores the urgency: teams linked to the DPRK allegedly took $2.02 billion in crypto assets in 2025, a 51% annual increase. The $285 million Drift Protocol loss in April was connected to physical meetings involving North Korean intermediaries, while just two incidents generated 76% of 2026 losses from only 3% of cases. The country's cumulative theft figure has exceeded $6 billion since 2017. Threat-intelligence data flagged GOLDEN CHOLLIMA for using recruitment lures to reach fintech cloud environments, showing that hiring controls are now a security boundary.

COINOTAG's analysis ties both disclosures to a single theme: the weakest layer is human custody, not the blockchain itself. On-chain theft records, including the $285 million Drift Protocol drain visible on the ledger, and the available post-incident statements point to social-engineering access, while corporate disclosures show remediation through credential revocation, insider screening, and threat-intelligence sharing via Crypto ISAC. For holders of Ethereum (ETH), Bitcoin, or any linked altcoin, the practical lesson is stricter separation of signing environments and verification of recruitment-related code. The primary evidence does not indicate a protocol failure; it indicates compromised people and devices. Even when markets are far from an all-time high, operational security remains the decisive risk control.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
James Mitchell

James Mitchell

COINOTAG author

View all posts
AI-AssistedSenior Technical Analyst·James Mitchell is a senior technical analyst with over six years of dedicated cryptocurrency market analysis experience.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments