Ripple Just Made It Harder for North Korea to Hide Inside Crypto Firms
Ripple is now contributing exclusive threat intelligence on DPRK (Democratic Peoples Republic of Korea) cyber actors to Crypto ISAC, a nonprofit organization that helps crypto companies share security information and defend against cyber threats targeting digital assets. The intelligence covers domains, wallets, and indicators of compromise from active DPRK hack campaigns. It also includes enriched profiles of suspected North Korean IT workers trying to embed themselves inside crypto firms. Drift Hack Triggered Industry Reckoning The Drift hack served as a wake-up call for the sector. Attackers spent months building trust with Drift contributors. They later deployed malicious software that compromised devices and bypassed traditional indicators of compromise. The intruders manipulated individuals to seize control of multisig wallets and steal funds. The same pattern has appeared at crypto and traditional financial firms. North Korean threat actors are operating from inside organizations rather than relying on smart contract exploits. Crypto ISAC characterized the campaign as social engineering at a new level. The piece raised the central question of how to detect someone who appears to be a trusted partner. The strongest security posture in crypto is a shared one. A threat actor who fails a background check at one company will apply to three more that same week. Without shared