North Korea has denied allegations that it is involved in global cryptocurrency hacking, describing the claims as false, politically driven or slanderous, according to reports citing state media and the country’s Foreign Ministry . That denial is an important part of the diplomatic context.
At the same time, U.S. lawmakers and allied governments have continued to connect North Korea-linked actors to major crypto thefts. A letter from U.S. senators Elizabeth Warren and Jack Reed to the Treasury Department and Justice Department said that, in February 2025, Lazarus Group, described in the letter as a North Korean government-backed hacking syndicate, stole approximately $1.5 billion in digital currency from Bybit .
South Korea, the United States and Japan also said in a joint statement that North Korea-linked hackers stole at least $659.1 million in cryptocurrency in 2024 .
For security teams, however, the most immediately useful information is not a political label. It is a set of signals they can act on: a domain to block, a wallet to monitor, an email to investigate, a suspicious profile to scrutinise or a pattern of behaviour to flag .
Crypto ISAC functions as an information-sharing hub for the digital-asset industry, similar in concept to information sharing and analysis centers used in other critical sectors. Its purpose is to help participating companies exchange threat data quickly enough for it to be useful .
Ripple is contributing intelligence related to North Korea-linked hacking activity, including fraud-associated domains, wallet addresses and indicators of compromise . Some reports also describe shared data that includes enriched profiles of suspected IT workers, LinkedIn accounts, email addresses and other contact information associated with suspected attackers or infiltration attempts .
CoinMarketCap reported that the data will be available through a newly launched API designed for fast, actionable intelligence sharing . In practice, that means a company could compare its own logs, alerts or onboarding records against indicators found by others.
This matters because attackers rarely target only one organisation. A fake contractor profile, malicious domain or wallet address seen at one crypto firm may reappear elsewhere. Sharing turns one company’s hard-earned clue into an industry-wide warning .
The reported shift in tactics is the key reason Ripple’s move is getting attention. Recent coverage has described attackers moving away from purely technical exploits and toward social-engineering operations that target people inside crypto companies .
Crypto.news reported that security teams have identified a move toward long-term infiltration, where attackers build trust, gain access and only later move funds . That is a different problem from a visible bug in a smart contract. It can involve hiring pipelines, private messages, collaboration tools, developer machines and privileged credentials.
The Drift Protocol case has been cited as an example of this change. Binance Square reported that the $285 million Drift Protocol heist in April was not caused by a smart-contract exploit, but by a six-month social-engineering infiltration in which North Korean operatives allegedly built trust, installed malware and stole private keys .
If that description is accurate, it points to a hard lesson for crypto companies: code audits are necessary, but they are not enough. A protocol can have reviewed code and still be exposed if attackers compromise the people, devices or credentials around it.
First, indicators of compromise can speed up detection. Fraud-linked domains, wallet addresses and other technical indicators can be fed into security operations so firms can block, monitor or investigate them more quickly .
Second, social-engineering campaigns often cross company boundaries. If the same fake identity, LinkedIn account, email address or contact pattern is used against multiple firms, a warning from one target can help another avoid the same trap .
Third, defence cannot wait for final attribution. North Korea denies the allegations , while U.S. senators and allied governments have linked Lazarus Group and other North Korea-linked actors to large crypto thefts . Those disputes may take years to resolve, if they are ever resolved publicly. Security teams still need to decide what to block today.
Fourth, crypto risk is interconnected. Exchanges, DeFi protocols, bridges, custodians and infrastructure providers often depend on one another. A breach at one point in the ecosystem can create risk elsewhere. That is why Ripple’s information sharing is best understood as collective defence rather than a branding exercise by one company .
The phrase North Korea-linked should not be treated as identical to a final legal finding that the North Korean state directed a specific incident. Public reporting does not make every case equally certain, and North Korea continues to reject the accusations as politically motivated .
Threat intelligence works on a different standard. It is not a judgment; it is an alert. Companies share suspicious infrastructure, accounts and tactics because those signals may recur, not because a court has already settled every question of responsibility.
That distinction is the heart of the issue. Ripple and Crypto ISAC are not asking the industry to resolve a geopolitical argument before acting. They are trying to help firms notice the same warning signs sooner, especially as attackers increasingly rely on trust, access and social engineering rather than only on code flaws .