
North Korea hackers scan crypto wallets through fake Zoom calls
BlueNoroff uses fake Zoom and Teams meetings to scan crypto wallets, hijack Telegram sessions, and deliver malware on Windows and macOS too.

BlueNoroff uses fake Zoom and Teams meetings to scan crypto wallets, hijack Telegram sessions, and deliver malware on Windows and macOS too.


North Korea arrested former state cyber operators for hacking two state banks and laundering funds through crypto wallets, exposing internal

Daily NK reported that North Korea arrested former state cyber operators accused of hacking two state banks and laundering funds through crypto.

Welcome to The Adversarial. Every other week, we’ll provide you with expert analysis on America’s greatest challengers: China, Russia, Iran, North Korea, and jihadists. Read more below.***IranThe U.S.-Iranian ceasefire agreed in April began deteriorating — and the Memorandum of Understanding signed on June 17 — ramping up to a near-constant exchange of hostilities in early July. On July 10, Trump declared that the ceasefire was over. The United States resumed its naval blockade and has been striking Iranian soil on a daily basis. Iran has targeted vessels transiting the Strait of Hormuz while launching drones and missiles at Arab Gulf states

A contractor brought in through a third-party provider worked on MetaMask code from March until Consensys cut off access in April and paused product releases. The company says it found no stolen assets, exposed data or malicious code.
Ethereum software firm Consensys is pushing back against rumors following a recent security incident involving a North Korea-linked IT worker.

Consensys found no compromised assets or data, no malicious code deployment and no user impact, but contractor access controls face scrutiny.

Consensys has temporarily halted product releases after a North Korea-linked consultant gained access to its systems for about one month. Drop Site News reported that the developer joined the Ethereum software company under the alias “Tyler Knapp” and used the…

Through an introduction with a “reputable third-party service provider,“ the company took on a developer who, as part of an investigation, was revealed to be tied to North Korea.

Taiwan's blacklist of shadow fleet ships highlights the geopolitical tensions and potential disruptions in regional maritime trade.

North Korea's crypto thefts highlight urgent global security risks, necessitating stronger international cooperation to counter cyber threats.

The hack underscores the urgent need for enhanced cybersecurity measures in the crypto industry, potentially influencing future regulations.

North Korea's crypto-funded nuclear ambitions highlight the urgent need for tighter global cybersecurity and regulatory measures in the crypto space.

G7 leaders elevated North Korea’s crypto thefts as a global security concern, linking digital asset crime to international security and Indo-Pacific stability. The statement included one direct reference to cryptocurrency thefts, alongside warnings about nuclear and missile programs. G7 Flags North Korea Crypto Theft in Security Statement The leaders of Canada, France, Germany, Italy, Japan, […]

G7 leaders urged joint action on North Korea crypto theft as reports tie DPRK hackers to $2.02B stolen in 2025 and missile funding.

The G7 Evian summit formally linked North Korea crypto theft to weapons funding, citing $6.75B stolen since 2017 and calling for coordinated enforcement.

G7's unified stance against North Korea's crypto thefts highlights the urgent need for global cooperation to curb state-sponsored cyber threats.

Humanity Protocol has attributed a roughly $36 million token theft to hackers linked to North Korea after an investigation found that attackers gained access to critical private keys through a compromised developer device. According to Humanity Protocol’s June 13 disclosure…

Developers behind Solana-based derivatives exchange Drift proposed on Tuesday a recovery plan that would funnel protocol revenue to users who lost money in a devastating April hack. The developers also proposed relaunching the protocol before July “a leaner, perps-native exchange with an emphasis on security.” “The Drift team is taking considered measures to ensure that users are made whole, and that Drift restores itself as the leading perpetuals DEX on Solana,” they said in an update posted on the exchange’s website. “The team has made internal hard decisions to restructure and operate as lean as possible, focusing entirely on recovery and relaunch.” But various elements of the recovery plan will have to be approved by Drift tokenholders — and, if all goes according to plan, victims could wait years to break even. On April 1, hackers were able to trick Drift administrators into approving bogus transactions. The hackers made off with crypto worth $295 million, forcing Drift to suspend trading and other activity. Blockchain analysts have since said North Korea was likely behind the hack. Should it pass, Drift’s proposal would lead to a lengthy recovery process for users who want to be fully compensated for their losses. Users would be issued a “recovery token” representing a claim on a "recovery pool” that would be gradually filled by Drift revenue, as well as crypto committed by Tether and other organizations that offered help after the hack. The claim would be proportional to the amount that each user lost, according to an update on the Drift website. Drift earned $19 million in revenue in 2025. At that rate, it could take nearly eight years for the recovery pool to reach $295 million, assuming Tether and other partners honour their promise to commit a combined $147 million to Drift recovery efforts. Users who don’t want to wait would be able to redeem their recovery tokens under par as soon as the recovery pool tops $5 million in assets. Drift proposed seeding the pool with just under $4 million in stablecoins. The recovery tokens would be transferrable, letting people bet on the success of Drift’s business model, which is changing dramatically in the wake of the hack. According to the proposal, the new Drift would drop “earn” products that resemble high-risk, high-yield savings accounts, and focus on a perpetual futures exchange running on slimmed-down code — a change that would limit hackers’ opportunities to find exploitable bugs. The protocol would accept fewer collateral assets and offer only the most popular and liquid assets for trading. Drift would also delay work on a mobile application and a new liquidity model it had unveiled just three months earlier. Its rebrand as a “security-first” exchange, administrators would be required to follow a formal security protocol that includes dedicated devices and quarterly security training sessions. The proposal had little affect on the Drift token, which was trading just under $0.04 before and after Tuesday’s announcement. “This will take time but the structure is in place, ecosystem partners are committed and the work is underway,” the proposal concluded. Aleks Gilbert is DL News’ New York-based DeFi correspondent. You can reach him at aleks@dlnews.com .