Google Warns Solana Projects That North Koreans Are Increasingly Targeting European Projects

Markets

Share this article

By Shaurya Malwa|Edited by Parikshit Mishra

Apr 2, 2025, 9:58 a.m. UTC

(Image via Shutterstock)
  • North Korean IT workers are increasing cyber activities in Europe, targeting blockchain projects, according to a Google Cloud report.
  • DPRK operatives pose as legitimate remote workers to infiltrate companies and steal sensitive data to fund the regime.
  • The report highlights the use of fake personas and sophisticated coding skills in their operations, including developing blockchain and AI applications.

North Korean “IT workers” are increasing illicit cyber activity across Europe with an eye on blockchain projects, Google Cloud warned in a Wednesday report.

Projects built on the popular Solana network, including applications and job boards, are getting hit by the rising attacks. Democratic People’s Republic of Korea (DPRK) operatives pose as legit remote workers to infiltrate companies, take over critical systems and steal sensitive data which is likely sold to “generate revenue for the regime.”

STORY CONTINUES BELOW

Don’t miss another story.Subscribe to the Crypto for Advisors Newsletter today.See all newslettersBy signing up, you will receive emails about CoinDesk products and you agree to ourterms of useandprivacy policy.

The increased threat in Europe is a shift from a U.S.-heavy focus as DPRK-linked entities faced heat from DOJ indictments and tighter hiring scrutiny stateside.

The report reveals that one such worker juggled 12 fake personas across the U.S. and Europe and sought employment by fabricating references, building a rapport with job recruiters, and using additional personas they controlled to vouch for their credibility.

It’s not like the workers lack coding chops either: Workers were found taking projects ranging from token hosting platform using Next.js, React and CosmosSDK, and Golang, and even created an entire Solana-based job marketplace.

More blockchain-related projects involved Anchor and Rust smart contract development. One worker even developed an artificial intelligence (AI) web application using Electron, Next.js, and blockchain applications.

A key culprit may be workplaces that let employees use their own devices.

“(Google Cloud) believes that IT workers have identified BYOD environments as potentially ripe for their schemes, and in January 2025, IT workers are now conducting operations against their employers in these scenarios,” the report said.

“Global expansion, extortion tactics, and the use of virtualized infrastructure all highlight the adaptable strategies employed by DPRK IT workers.”

DPRK entities and hacking groups are one of the biggest threat actors in the crypto ecosystem, stealing an estimated $1.3 billion from projects in 2024 and conducting a $1.5 billion hack on crypto exchange Bybit in February alone.

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.
Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.
He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa


Contact

DISCLOSURE & POLICES

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.

EthicsPrivacyTerms of UseCookie ConsentDo Not Sell My Info


© 2025 CoinDesk, Inc.

 

Leave a Reply

Your email address will not be published. Required fields are marked *