U.S. Treasury Sanctions Network Linked to North Korean Crypto Fraud

TheNewsCrypto發佈於 2026-03-13更新於 2026-03-13

文章摘要

The U.S. Treasury has sanctioned a network tied to North Korean IT workers involved in global cryptocurrency fraud schemes. These operatives used stolen identities and fake documents to secure remote IT jobs, then funneled their earnings to the North Korean government to fund weapons and ballistic missile programs. Many operated from countries like China and Russia while posing as legitimate employees, with companies unknowingly hiring them for software and crypto-related projects. Authorities linked the network to other cybercrimes, including hacking and identity fraud, which have generated billions in stolen crypto assets. Organizations are urged to strengthen identity checks to avoid inadvertently supporting sanctioned entities.

The United States Department of the Treasury sanctioned a network linked to North Korean IT workers. They were running cryptocurrency fraud schemes across the world. Reports indicate that the operatives secretly acquired remote IT jobs. Then, they redirected their earnings to the North Korean government through these networks. Investigators believe the program earned substantial revenues and used them to support Pyongyang’s weapons and ballistic missile programs worldwide. Reports indicate that North Korean operatives used stolen identities and fabricated documents to acquire remote IT jobs globally.

It is reported that many of these workers were operating in countries such as China and Russia. This was done while presenting themselves as legitimate workers worldwide. It is reported that many companies unknowingly recruited these workers to develop software, infrastructure, and cryptocurrency platforms globally. Michael Faulkender said that authorities will seek to block revenue channels that fund destabilizing activities in North Korea globally.

Cybercrime Network Raises Crypto Industry Security Concerns

Faulkender stated that the authorities remain committed to disrupting these cyber-enabled revenue operations in support of Pyongyang’s weapons development programs worldwide today. The investigators also associated the network with other worldwide cybercrime operations. Investigators recently revealed that operatives targeted cryptocurrency organizations and blockchain developers worldwide.

Security authorities have estimated that North Korea-sponsored cyberhackers stole billions from cryptocurrency organizations worldwide in recent years worldwide recently. Experts have revealed that these operations involve a combination of hacking activities, identity fraud schemes, and remote employment strategies. This was to raise revenue in cryptocurrencies worldwide.

Security authorities have urged organizations to heighten their identity verification when hiring remote technology workers worldwide in the global market. They have stated that this can help organizations avoid unknowingly remitting money to sanctioned networks associated with North Korea’s worldwide cyber operations and activities. The latest sanctions have revealed the ongoing efforts to restrict revenue streams associated with North Korea’s worldwide cyber activities and operations.

Highlighted Crypto News:

Kraken Announces Pi Network Listing Ahead of Pi Day, Boosting Interest in PI Coin

TagsBlockchainNorth KoreaU.SUS Treasury

相關問答

QWhat did the U.S. Treasury sanction in relation to North Korean IT workers?

AThe U.S. Treasury sanctioned a network linked to North Korean IT workers who were running cryptocurrency fraud schemes worldwide.

QHow did the North Korean operatives acquire remote IT jobs according to the report?

AThey used stolen identities and fabricated documents to secretly obtain remote IT jobs globally.

QWhat was the primary purpose of the revenue generated by this fraudulent program?

AThe substantial revenues earned were used to support Pyongyang's weapons and ballistic missile programs.

QWhich countries were mentioned as locations where many of these operatives were working?

AMany of these workers were operating in countries such as China and Russia.

QWhat did security authorities recommend to organizations hiring remote technology workers?

AThey urged organizations to heighten their identity verification processes to avoid unknowingly sending money to sanctioned networks.

你可能也喜歡

比特币提现仍在继续:Coldcard冷钱包8年存储终成空

硬件钱包Coldcard遭黑客攻击,导致大量资金从易受攻击设备中被持续转出。据Galaxy Research数据,截至2026年8月2日,已有4585个地址被盗,损失总额达1367.05 BTC(约合8860万美元),远超7月30日最初报告的594.5 BTC。大部分被盗资金仍停留在攻击者地址。 问题根源并非固件,而是设备生成的种子短语存在漏洞。2021年3月起,因程序员错误集成libNgU库,设备从使用STM32硬件随机数生成器转为使用软件生成器Yasmarang,该生成器由公开可获取的芯片序列号和计时器状态初始化,导致生成的种子短语可在离线状态下被暴力破解。即使固件后续已更新,只要用户未将资金转移至基于新种子短语生成的新地址,旧钱包就始终处于风险中。 受影响的设备包括特定固件版本的Mk2/Mk3、Mk4/Mk5及Q系列。仅当种子短语是通过至少50次独立掷骰子或强唯一性BIP-39密码短语创建时方可幸免。官方建议受影响用户立即在已修复的固件上生成新种子短语并转移资产。 报道提及一位39岁投资者的案例,他因该漏洞损失了2 BTC(约13万美元)。他多年来通过体力劳动积攒比特币,将其视为在制裁和高通胀国家中的财务保障与提前退休的途径。此次事件使他的长期持有策略和“冷存储”信心遭受重击,他因此决定彻底退出加密货币领域。 从历史数据看,随机数生成器缺陷并非首例,类似问题曾导致巨额损失。此次事件警示,即使离线存储也未必绝对安全,其安全性高度依赖于底层硬件和算法的可靠性。

cryptonews.ru2 小時前

比特币提现仍在继续:Coldcard冷钱包8年存储终成空

cryptonews.ru2 小時前

交易

現貨
活动图片