Ripple to Collaborate with Crypto Firms on North Korean Threat Intelligence

In a move to redefine the crypto sector's response to the evolving North Korean attack methodology, Ripple has announced that it will be sharing its internal threat intelligence on North Korean hackers with the crypto industry. This decision comes after the April breach of Drift, which resulted in a loss of $285 million, and highlighted a new pattern of long-cycle social engineering replacing traditional smart contract exploits. Unlike typical hacks, the Drift breach involved North Korean operatives spending months building relationships with Drift's contributors, installing malware on their machines, and ultimately gaining access to the keys. By the time the $285 million was transferred, all systems designed to detect such breaches had nothing to flag. Ripple, in collaboration with Crypto ISAC, the crypto industry's threat-sharing group, has laid out the details of the breach and its decision to share its internal data on North Korean threat actors with the rest of the sector. The wave of DeFi hacks between 2022 and 2024 primarily focused on exploiting code vulnerabilities, with attackers finding smart contract weaknesses and draining protocols in minutes. However, as security measures improve, the modus operandi shifts from targeting technology to targeting people. Rogue operatives apply for jobs at crypto firms, pass background checks, participate in Zoom calls, and build trust over months before deploying attacks that traditional security tools are not equipped to detect. Ripple is now providing Crypto ISAC with profile data that makes this pattern recognizable across companies, including LinkedIn profiles, email addresses, locations, and contact numbers. This information enables security teams to identify potential threats, such as a candidate who has failed background checks at multiple firms. According to Ripple, "the strongest security posture in crypto is a shared one," emphasizing the importance of shared intelligence in preventing threats. The Lazarus Group's impact on the crypto sector is now visible, influencing both security and legal proceedings. Recently, an attorney representing victims of North Korean terrorism served restraining notices on Arbitrum DAO, arguing that the 30,765 ETH frozen after the Kelp bridge exploit is North Korean property under U.S. enforcement law. Lending company Aave has disputed this filing, arguing that a thief does not gain lawful ownership of stolen property simply by taking it. The Kelp breach, attributed to Lazarus Group operatives, resulted in the loss of $292 million in ether, bringing the total losses attributed to this state actor in a single month to over half a billion dollars. The effectiveness of industry-level intelligence sharing in slowing down these campaigns remains an open question, as the same operatives may already be in the process of infiltrating other firms.