<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>North Korean - Coinfea</title>
	<atom:link href="https://coinfea.com/tag/north-korean/feed/" rel="self" type="application/rss+xml" />
	<link>https://coinfea.com</link>
	<description>Crypto and Blockchain News</description>
	<lastBuildDate>Sat, 18 Jul 2026 19:33:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://coinfea.com/wp-content/uploads/2022/04/cropped-Cfeawhite-1-32x32.png</url>
	<title>North Korean - Coinfea</title>
	<link>https://coinfea.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>North Korean operative busted after accessing MetaMask code</title>
		<link>https://coinfea.com/north-korean-operative-busted-after-accessing-metamask-code/</link>
		
		<dc:creator><![CDATA[Owotunse Adebayo]]></dc:creator>
		<pubDate>Sat, 18 Jul 2026 20:32:00 +0000</pubDate>
				<category><![CDATA[Cryptocurrency News]]></category>
		<category><![CDATA[ConsenSys]]></category>
		<category><![CDATA[Metamask]]></category>
		<category><![CDATA[North Korean]]></category>
		<guid isPermaLink="false">https://coinfea.com/?p=22845</guid>

					<description><![CDATA[<p>Consensys, the blockchain firm behind the MetaMask crypto wallet, has confirmed it accidentally brought a software developer with links to North Korea onto its team. The firm confirmed that they gave the North Korean operative access to the core wallet code before the company caught on and shut him down after a month. Internal Slack [&#8230;]</p>
<p>The post <a href="https://coinfea.com/north-korean-operative-busted-after-accessing-metamask-code/">North Korean operative busted after accessing MetaMask code</a> first appeared on <a href="https://coinfea.com">Coinfea</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph"><strong>Consensys, the blockchain firm behind the MetaMask crypto wallet, has confirmed it accidentally brought a software developer with links to North Korea onto its team. The firm confirmed that they gave the North Korean operative access to the core wallet code before the company caught on and shut him down after a month.</strong></p>



<p class="wp-block-paragraph">Internal Slack messages <a href="http://www.cryptopolitan.com/north-korean-dev-metamask-code-being-caught/" title="revealed">revealed</a> that the North Korean operative worked on core MetaMask code for approximately one month before being terminated. Although Consensys confirmed that the infiltrator was stopped before any damage was done, the market remains skeptical of MetaMask’s ability to guarantee the safety of its users’ funds. According to the report, the North Korean software engineer worked under the alias “Tyler Knapp” and used the GitHub handle “imyugioh.” He was hired as a consultant through a third-party service provider with a long-standing relationship with Consensys.</p>



<h2 class="wp-block-heading">Consensys says North Korean operative was terminated after one month</h2>



<p class="wp-block-paragraph">Consensys confirmed that the North Korean software engineer was not hired directly through its internal hiring pipeline, insisting that the third-party hiring agency may have been responsible for the breakdown in proper screening. Internal Slack messages reviewed show that Tyler Knapp worked on the core <a href="https://coinfea.com/portfolio-dapp-from-metamask-a-self-custodial-wallet/" title="Portfolio Dapp from MetaMask, a self-custodial wallet">MetaMask</a> platform code. He had access to the core MetaMask codebase that converts crypto to fiat currency via third-party payment providers and vice versa.</p>



<p class="wp-block-paragraph">The North Korean also contributed to MetaMask’s mobile wallet codebase on GitHub. Those contributions began on March 9 and abruptly stopped in April, the same month Consensys cut off his access, meaning the operative had roughly a month of activity within the company’s systems. Consensys general counsel Matt Corva revealed that the company discovered the threat quickly after Tyler was hired. The company followed its security protocols and terminated access immediately upon identifying the threat.</p>



<p class="wp-block-paragraph">Corva also said a subsequent investigation found no misappropriation of assets or data, no malicious code pushed into production, and no impact on user safety. In April, Corva sent a company-wide alert ordering all product releases suspended pending investigation and instructing staff not to interact with the individual. He also asked employees to keep the matter internal while the probe continued, a request that suggests Consensys was trying to control the narrative well before the story became public this week.</p>



<p class="wp-block-paragraph">North Korean operatives posing as remote software engineers have repeatedly landed real jobs at American companies. These companies achieve this with the help of US-based facilitators running laptop farms that make it appear the worker is logging in from within the country. One Arizona woman was sentenced last year for running such an operation, which prosecutors say generated more than $17 million for North Korea-linked entities, according to reporting from The Guardian.</p>



<p class="wp-block-paragraph">Earlier this year, two more American nationals were sentenced for facilitating similar schemes that the Department of Justice says touched close to 70 US companies. Crypto firms are an especially attractive target because a developer’s ordinary access can extend well beyond source code into transaction signing infrastructure, the layer where stolen funds actually move. Blockchain analytics firm TRM Labs has estimated that North Korea-linked actors were behind roughly two-thirds of all crypto stolen in hacks last year, a figure that includes the $1.5 billion Bybit theft widely attributed to Pyongyang.</p><p>The post <a href="https://coinfea.com/north-korean-operative-busted-after-accessing-metamask-code/">North Korean operative busted after accessing MetaMask code</a> first appeared on <a href="https://coinfea.com">Coinfea</a>.</p>]]></content:encoded>
					
		
		
			<media:content url="https://coinfea.com/wp-content/uploads/2026/07/IMG_20260718_201227-1024x613.jpg" medium="image" />
	</item>
		<item>
		<title>Cryptocurrency industry faces new threat as North Korean Konni group exploits WinRAR bug</title>
		<link>https://coinfea.com/cryptocurrency-industry-faces-new-threat-as-north-korean-konni-group-exploits-winrar-bug/</link>
		
		<dc:creator><![CDATA[Damilola Lawrence]]></dc:creator>
		<pubDate>Fri, 15 Sep 2023 13:14:54 +0000</pubDate>
				<category><![CDATA[Cryptocurrency News]]></category>
		<category><![CDATA[Konni]]></category>
		<category><![CDATA[North Korean]]></category>
		<category><![CDATA[WinRAR]]></category>
		<guid isPermaLink="false">https://coinfea.com/?p=6096</guid>

					<description><![CDATA[<p>In a first, North Korean APT group Konni exploits a newly disclosed WinRAR vulnerability to launch an attack on the cryptocurrency sector. A new frontier in cyber attacks The North Korean Advanced Persistent Threat (APT) group known as Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry. [&#8230;]</p>
<p>The post <a href="https://coinfea.com/cryptocurrency-industry-faces-new-threat-as-north-korean-konni-group-exploits-winrar-bug/">Cryptocurrency industry faces new threat as North Korean Konni group exploits WinRAR bug</a> first appeared on <a href="https://coinfea.com">Coinfea</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">In a first, North Korean APT group Konni exploits a newly disclosed WinRAR vulnerability to launch an attack on the cryptocurrency sector.</p>



<h2 class="wp-block-heading">A new frontier in cyber attacks</h2>



<p class="wp-block-paragraph">The North Korean Advanced Persistent Threat (APT) group known as Konni has made headlines by exploiting a recently disclosed WinRAR vulnerability (CVE-2023-38831) to target the cryptocurrency industry. This marks the first instance of an APT group leveraging this particular vulnerability for an attack.</p>



<p class="wp-block-paragraph">The group <a href="http://statement" title="">used a malicious </a>payload disguised as a wallet screenshot related to Qbao Network, a smart cryptocurrency wallet service. When the victim clicked on the HTML file within a compressed archive, the malicious payload was executed, exploiting the WinRAR vulnerability.</p>



<h2 class="wp-block-heading">Technical insights and implications</h2>



<p class="wp-block-paragraph">The attack was meticulously planned, using a bug in the WinRAR software to execute a malicious payload. The payload was designed to detect the type of operating system on the victim&#8217;s computer and download additional payloads accordingly. The malware then performed various tasks, such as running system information commands and task lists, which were encrypted and sent back to a server controlled by the attackers. This level of sophistication indicates a well-coordinated effort and raises concerns about the vulnerability of cryptocurrency platforms to advanced cyber threats.</p>



<h2 class="wp-block-heading">North Korea&#8217;s expanding cyber reach</h2>



<p class="wp-block-paragraph">While North Korean cyber activities targeting the cryptocurrency industry have generally been attributed to the Lazarus Group, this attack signifies a broader range of actors within the country focusing on this lucrative sector. The attack comes in the wake of other incidents involving cryptocurrency platforms like Stake and CoinEx, suggesting a concerted effort by North Korean hackers to target cryptocurrency exchanges. The use of a newly disclosed vulnerability also indicates that these groups are staying abreast of the latest developments in cybersecurity, ready to exploit any weaknesses they find.</p>



<p class="wp-block-paragraph">The attack serves as a wake-up call for the cryptocurrency industry, which has been increasingly targeted by sophisticated cyber threats. The exploitation of a newly disclosed vulnerability highlights the need for constant vigilance and timely patching of software vulnerabilities. With North Korea expanding its cyber-operations to include more groups targeting the cryptocurrency sector, the industry must bolster its defenses to protect against a growing range of threats.</p><p>The post <a href="https://coinfea.com/cryptocurrency-industry-faces-new-threat-as-north-korean-konni-group-exploits-winrar-bug/">Cryptocurrency industry faces new threat as North Korean Konni group exploits WinRAR bug</a> first appeared on <a href="https://coinfea.com">Coinfea</a>.</p>]]></content:encoded>
					
		
		
			<media:content url="https://coinfea.com/wp-content/uploads/2023/09/North-Korean-Konni.png" medium="image" />
	</item>
	</channel>
</rss>
