Close Menu

    Subscribe to Updates

    What's Hot

    UAE Innovation City launches blockchain IDs for companies

    May 5, 2026

    Success Story: Tirthankar Sundaram’s Learning Journey with 101 Blockchains

    May 5, 2026

    Ripple begins sharing DPRK threat intel with crypto firms

    May 5, 2026
    Facebook X (Twitter) Instagram
    laicryptolaicrypto
    Demo
    • Ethereum
    • Crypto
    • Altcoins
    • Blockchain
    • Bitcoin
    • Lithosphere News Releases
    laicryptolaicrypto
    Home Ripple begins sharing DPRK threat intel with crypto firms
    Crypto

    Ripple begins sharing DPRK threat intel with crypto firms

    John SmithBy John SmithMay 5, 2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Ripple has begun sharing its internal threat intelligence on North Korean hacking operations with the crypto industry, expanding how firms respond to insider-driven attacks.

    Summary

    • Ripple has begun sharing internal data on North Korean threat actors with Crypto ISAC to help firms detect insider-driven attacks earlier.
    • Security teams have identified a shift from smart contract exploits to long-term infiltration, where attackers gain trust and access before moving funds.

    According to Crypto ISAC, the move follows incidents where attackers bypassed code vulnerabilities and instead infiltrated teams over months, a pattern highlighted in the Drift case.

    Details released by Ripple and Crypto ISAC describe the Drift incident as a prolonged social engineering campaign, where North Korean-linked actors built trust with contributors before deploying malware on their systems. That access allowed attackers to compromise multisig wallets and move funds without triggering conventional alerts, as no smart contract flaw had been used.

    Security teams cited in the announcement said this approach differs from the 2022 to 2024 wave of DeFi breaches, which centred on exploiting code-level vulnerabilities. In the Drift case, attackers operated from within after clearing hiring processes and establishing credibility across teams.

    “The strongest security posture in crypto is a shared one,” Ripple said in a statement on X, adding that a threat actor rejected by one firm often reapplies to several others within the same week, leaving gaps when intelligence is not shared.

    Ripple said it is now contributing enriched datasets to Crypto ISAC, including domains, wallet addresses, and indicators of compromise tied to active campaigns. These datasets also carry contextual identifiers such as LinkedIn profiles, email addresses, phone numbers, and location details that link individuals to coordinated operations across firms.

    “Crypto ISAC’s newly updated API represents a meaningful step forward in how intelligence is shared across the ecosystem,” said Erin Plante, Director of Brand Security and Intelligence at Ripple, adding that the integration has allowed Ripple to bring “higher-quality, more actionable intelligence” directly into its security workflows.

    Crypto ISAC said its new API is designed to standardise intelligence across Web2 and Web3 systems, allowing firms to act on high-confidence threat data in real time. Early adopters, including Coinbase, have started integrating the system into their operations.

    “One of the biggest challenges in crypto threat intelligence is bridging the gap between raw signals and operational decisions,” Jeff Lunglhofer, Chief Information Security Officer at Coinbase, noted, adding that the updated data model helps preserve context and confidence while improving real-time response.

    Legal disputes emerge alongside security response

    At the same time, activity tied to the same threat actors has begun surfacing in U.S. legal proceedings. An attorney representing victims of North Korean terrorism has served restraining notices on Arbitrum DAO, arguing that 30,765 ETH frozen after the April Kelp exploit constitutes North Korean-linked property under U.S. enforcement law.

    Aave has challenged that claim, stating in its filing that a thief does not gain lawful ownership of stolen assets and backing Arbitrum’s position on the frozen funds.

    Public attribution from security firms has linked both the Drift incident and the Kelp exploit to the Lazarus Group, placing combined losses from the two events above $500M within a single month.

    “For too long, information sharing was seen as optional. Today, it is the gold standard for security,” said Justine Bone, Executive Director at Crypto ISAC, describing Ripple’s contribution as a working example of how shared intelligence can be turned into an actionable defence strategy.

    Crypto ISAC said the effectiveness of this model will depend on how quickly firms act on shared intelligence, as threat actors continue to operate across multiple organisations at once.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    John Smith

    Related Posts

    UAE Innovation City launches blockchain IDs for companies

    May 5, 2026

    Uphold rejects NYAG claims after $5M CredEarn settlement

    May 5, 2026

    Prediction markets enter institutional era after first Kalshi block trade

    May 5, 2026
    Leave A Reply Cancel Reply

    Demo
    Don't Miss
    Crypto

    UAE Innovation City launches blockchain IDs for companies

    By John SmithMay 5, 20260

    The United Arab Emirates Innovation City has rolled out a blockchain-based system that assigns every…

    Success Story: Tirthankar Sundaram’s Learning Journey with 101 Blockchains

    May 5, 2026

    Ripple begins sharing DPRK threat intel with crypto firms

    May 5, 2026

    Uphold rejects NYAG claims after $5M CredEarn settlement

    May 5, 2026

    LAI Crypto is a user-friendly platform that empowers individuals to navigate the world of cryptocurrency trading and investment with ease and confidence.

    Our Posts
    • Altcoins (18)
    • Bitcoin (1)
    • Blockchain (16)
    • Crypto (714)
    • Ethereum (434)
    • Lithosphere News Releases (37)

    Subscribe to Updates

    • Twitter
    • Instagram
    • YouTube
    • LinkedIn

    Type above and press Enter to search. Press Esc to cancel.