North Korean hackers, under the BlueNoroff subgroup of the Lazarus Group, have escalated their cyberattacks, shifting from social media manipulation to targeted phishing emails in their 'Hidden Risk' campaign.
These emails, disguised as crypto news or DeFi updates, lead to malware-laden links that bypass security features like macOS’s Gatekeeper, allowing hackers to steal sensitive data.
As the cryptocurrency sector grows, North Korean hackers are increasingly focusing on DeFi and ETF firms, using phishing and social engineering to target employees.
The FBI has issued warnings, urging firms to strengthen security and cross-check wallet addresses.
The Lazarus Group has also exploited privacy protocols like RailGun for crypto money laundering, prompting U.S. sanctions on services like Tornado Cash.
Experts advise cryptocurrency firms, particularly those on macOS, to enhance security with regular malware scans and careful scrutiny of email attachments to defend against these evolving threats.
A legal clash between Coin Center and the U.S. Treasury Department over sanctions imposed on Tornado Cash has officially come to an end, following a joint decision to dismiss the case.
A sophisticated cyberattack targeting Brazil’s central bank reserve accounts has resulted in the theft of over $140 million (R$800 million), much of which was swiftly funneled through cryptocurrency channels.
A malicious open-source project on GitHub disguised as a Solana trading bot has compromised user wallets, according to a July 2, 2025, report by cybersecurity firm SlowMist.
The U.S. Department of Justice has sentenced Dwayne Golden, 57, of Pennsylvania to 97 months in prison for orchestrating a fraudulent crypto investment scheme that stole over $40 million from investors.