Kraken Outsmarts State-Backed Hacker Masquerading as Job Applicant
What looked like a routine job application turned into a live counterintelligence mission at Kraken, one of the world’s leading cryptocurrency exchanges. Behind the resume? A covert operative connected to a North Korean cyber threat group.
The incident came to light on May 1, 2025, when Kraken revealed it had intercepted a stealthy attempt by a suspected North Korean hacker to gain access to internal systems—not through brute force, but by applying for a job.
Instead of slamming the door shut, Kraken’s security experts took a different route. They moved the applicant through successive interview rounds—not to hire them, but to dissect their methods. It was a calculated move designed to extract intelligence on a growing wave of cyber infiltration efforts originating from North Korea.
An Unusual Candidate Raises Red Flags
The red flags were subtle at first. The applicant joined an early interview using a name that didn’t match the resume. Moments later, the name was changed. The interview itself was even stranger: the voice on the other end would shift mid-conversation, suggesting the person was receiving real-time instructions—likely from accomplices.
Kraken’s Chief Security Officer, Nick Percoco, noted that the inconsistencies “didn’t just seem odd—they fit a larger pattern we were trained to watch for.”
Industry insiders had already circulated warnings about similar schemes, where North Korean hackers infiltrate crypto companies by posing as remote engineers. Kraken had access to a list of compromised email accounts associated with such efforts. One of them matched the applicant’s GitHub and resume credentials.
Digital Footprints Reveal the Deception
Kraken’s team employed Open-Source Intelligence (OSINT) tools to scrutinize the applicant’s digital trail. What they found was revealing: remote Mac systems accessed via VPNs, identity documents that appeared tampered with, and a GitHub profile tied to a breached email address.
All indicators pointed toward an operation carefully engineered to appear legitimate—until the façade cracked.
During a final interview, the team subtly tested the applicant’s claimed location by asking for local restaurant recommendations. The response was hesitant and generic. The mask slipped.
A Warning to the Crypto Industry—and Beyond
The infiltration attempt adds to a growing body of evidence that North Korean actors, particularly the Lazarus Group, are escalating their focus on crypto firms. In 2024 alone, Lazarus is believed to have stolen over $650 million through cyberattacks, social engineering, and fake job applications.
Earlier this year, the same group was linked to a historic $1.5 billion theft from ByBit, with an estimated $300 million already funneled through laundering operations.
“This isn’t just about crypto,” Percoco emphasized. “This is about nation-state tactics. It’s about adversaries walking through the front door with a resume instead of breaching the firewall.”
Kraken’s experience underscores the new front line in cybersecurity: human trust. Organizations must now defend not only their systems, but their hiring pipelines.
As Percoco puts it, “In today’s world, zero trust isn’t a strategy—it’s a necessity.”




