Summary
Fireblocks CEO Michael Shaulov discusses a North Korea-linked recruiting impersonation scam that uses fake job interviews and GitHub coding assignments to install malware on crypto developers' devices and gain access to wallets, keys, and production systems. Fireblocks investigated the campaign, identified fake profiles, collected indicators of compromise, and worked with LinkedIn and law enforcement to take them down. Shaulov warns the tactic is likely to return in mutated forms and that AI is making attackers more sophisticated and harder to detect. The discussion highlights ongoing cybersecurity risks for crypto infrastructure and exchanges.
- Fireblocks investigated a recruiting scam that impersonated its hiring process.
- Hackers targeted developers with privileged access, including DevOps and staff engineers.
- Malware was hidden in take-home coding assignments and installed during routine setup.
- Fireblocks identified about a dozen fake profiles and gathered indicators of compromise.
- LinkedIn and law enforcement helped take down profiles, but the threat is not over.
- Shaulov said AI has made attackers more sophisticated and harder to detect.
- North Korea-linked crypto theft was described as a major source of regime funding.
- Bybit's earlier large crypto heist was cited as part of Lazarus Group's history.