Changpeng Zhao has warned that North Korean hackers use fake job postings, insider hires, and phishing tactics to infiltrate top crypto firms and steal user funds. He pointed to recent hacks tied to Lazarus Group and others, including a $400M breach allegedly linked to Coinbase’s outsourced customer support.

Changpeng Zhao has warned that North Korean hackers use fake job postings, insider hires, and phishing tactics to infiltrate top crypto firms and steal user funds. He pointed to recent hacks tied to Lazarus Group and others, including a $400M breach allegedly linked to Coinbase’s outsourced customer support.
crypto.news
Revision history

4 recorded changes

Want your article here?

Promote with Leviathan News

Changpeng Zhao warned that North Korean hackers are using increasingly sophisticated social-engineering tactics to penetrate crypto firms, including fake job applications, recruiter impersonation, phishing links sent during interviews, malicious “sample code,” and bogus customer-support requests. He said these methods are designed to gain insider access, compromise employee devices, and ultimately steal data or funds, with the threat extending beyond in-house staff to outsourced vendors and contractors. The warning comes against a backdrop of repeated campaigns attributed to North Korean-linked groups such as Lazarus Group and Famous Chollima, which have targeted the crypto sector for years. The story also connects to the alleged large-scale Coinbase customer-data breach mentioned in the reporting, where attackers reportedly bribed outsourced support staff and exposed sensitive user information; crypto.news says that incident led to more than $400 million in losses, underscoring how third-party service providers can become an entry point into major exchanges. The broader significance is that crypto companies are being pushed to treat hiring, contractor access, and support workflows as security-critical attack surfaces rather than routine operations.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Hacker

Comments