BlocktoBlockto

Trending

Ripple Shares North Korea Threat Intelligence to Counter New Crypto Attack Tactics
ALTCOIN NEWS

Photo: Illustrative

Ripple Shares North Korea Threat Intelligence to Counter New Crypto Attack Tactics

Ripple is distributing internal threat intelligence on North Korean cyber actors to the wider crypto industry through Crypto ISAC. The move follows a series of high-profile breaches, including the $285 million attack on Drift, which revealed a shift away from traditional smart contract vulnerabilities.

Tristan R.
By Tristan R.

Senior Author · May 5, 2026

2 min
Key takeaways
Shift From Smart Contract Exploits to Social Engineering Ripple is distributing internal threat intelligence on North Korean cyber actors to the wider crypto industry through Crypto ISAC.
The move follows a series of high-profile breaches, including the $285 million attack on Drift, which revealed a shift away from traditional smart contract vulnerabilities.
Instead of exploiting code, attackers reportedly relied on long-term social engineering, embedding operatives within teams, deploying malware, and gaining access to critical systems over time.

Shift From Smart Contract Exploits to Social Engineering

Ripple is distributing internal threat intelligence on North Korean cyber actors to the wider crypto industry through Crypto ISAC. The move follows a series of high-profile breaches, including the $285 million attack on Drift, which revealed a shift away from traditional smart contract vulnerabilities.

Instead of exploiting code, attackers reportedly relied on long-term social engineering, embedding operatives within teams, deploying malware, and gaining access to critical systems over time.

Lazarus Group Activity Drives Industry Response

The attacks have been widely linked to Lazarus Group, with combined losses from the Drift and Kelp incidents exceeding $500 million in April alone. These operations highlight a growing trend where human vulnerabilities, rather than technical flaws, are the primary entry point.

Ripple is now sharing detailed intelligence including digital identities and behavioral patterns to help firms identify coordinated infiltration attempts across multiple organizations.

Legal and Security Implications Expand

The alleged involvement of North Korean actors is also influencing legal disputes over frozen crypto assets. Efforts to claim funds tied to these exploits are already unfolding in courts, while companies like Aave challenge those claims.

The effectiveness of industry-wide intelligence sharing remains uncertain, but the initiative marks a significant step toward collective defense in an evolving threat landscape.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.