Ripple begins sharing DPRK threat intel with crypto firms
Ripple has begun sharing its internal threat intelligence on North Korean hacking operations with the crypto industry, expanding how firms respond to insider-driven attacks.Ripple has begun sharing internal data on North Korean threat actors with Crypto ISAC to help firms detect insider-driven attacks earlier.Security teams have identified a shift from smart contract exploits to long-term infiltration, where attackers gain trust and access before moving funds. According to Crypto ISAC, the move follows incidents where attackers bypassed code vulnerabilities and instead infiltrated teams over months, a pattern highlighted in the Drift case. Details released by Ripple and Crypto ISAC describe the Drift incident as a prolonged social engineering campaign, where North Korean-linked actors built trust with contributors before deploying malware on their systems. That access allowed attackers to compromise multisig wallets and move funds without triggering conventional alerts, as no smart contract flaw had been used. Security teams cited in the announcement said this approach differs from the 2022 to 2024 wave of DeFi breaches, which centred on exploiting code-level vulnerabilities. In the Drift case, attackers operated from within after clearing hiring processes and establishing credibility across teams. “The strongest security posture in crypto is a shared one,” Ripple said in a statement on X,