Ripple has started sharing detailed threat intelligence on North Korea‑linked crypto hacking campaigns with the wider industry, aiming to help exchanges and protocols defend against a clear shift from technical exploits toward long-horizon social engineering attacks. The data is being distributed through the nonprofit Crypto ISAC’s new API, providing members with enriched indicators such as fraud-associated domains, wallet addresses, and profiles of suspected DPRK IT operatives, including their LinkedIn identities and communication details. According to Crypto ISAC and coverage of the move, this initiative responds directly to recent high‑impact incidents like the roughly $280–285 million Drift Protocol attack, where a DPRK‑linked group spent around six months building trust with project contributors before draining user funds, despite no smart contract vulnerability being involved. Ripple’s contribution is positioned as part of a broader collective‑defense model in which founding members such as Ripple and Coinbase integrate shared intelligence into their security operations so that firms can detect and block DPRK‑associated infrastructure and personas in near real time, rather than only reacting after breaches. The shift is occurring against a backdrop of rapidly growing North Korean involvement in crypto theft: TRM Labs data cited by Crypto ISAC indicates that DPRK‑linked operations rose from under 10% of global crypto hack losses in 2020–2021 to roughly 64% of global losses in 2025, underscoring the systemic risk to Web3 projects and service providers.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on North Korea

Comments