Ripple to Share North Korean Hacker Threat Intelligence With Crypto Industry
North Korean hackers have increasingly targeted crypto-asset companies, shifting from hunting for smart-contract vulnerabilities to prolonged social-engineering and malware campaigns in which they pose as job applicants or business partners. TRM Labs estimates that North Korea-linked attacks accounted for 64% of global crypto theft losses in 2025, making industry-wide intelligence sharing critical to preventing repeat attacks.
On May 4, 2026, Ripple said it would share suspicious employees’ LinkedIn profiles, email addresses, malicious domains, wallet addresses and indicators of compromise with crypto companies through the nonprofit cybersecurity organization Crypto ISAC. The move followed attacks on Drift and KelpDAO in April that caused combined losses of about $570 million, including roughly $280 million at Drift.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →