Mark RadarMARK RADAR
About
EN
Sign in

Ripple to Share North Korean Hacker Threat Intelligence With Crypto Industry

2 reports · First detected 2026-05-05 · Last active 2026-05-05

North Korean hackers have increasingly targeted crypto-asset companies, shifting from hunting for smart-contract vulnerabilities to prolonged social-engineering and malware campaigns in which they pose as job applicants or business partners. TRM Labs estimates that North Korea-linked attacks accounted for 64% of global crypto theft losses in 2025, making industry-wide intelligence sharing critical to preventing repeat attacks.

On May 4, 2026, Ripple said it would share suspicious employees’ LinkedIn profiles, email addresses, malicious domains, wallet addresses and indicators of compromise with crypto companies through the nonprofit cybersecurity organization Crypto ISAC. The move followed attacks on Drift and KelpDAO in April that caused combined losses of about $570 million, including roughly $280 million at Drift.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)