• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto and Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home Β» Cryptocurrency

ZachXBT Uncovers $1M Per Month DPRK Crypto Pipeline

Published on: April 9, 2026
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor • 1,679 Articles
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
Crypto.com Exchange Launches TradingView Integration
Franklin Templeton Expands BENJI Access Through MoonPay
Tessera DAO Hit by Exploit as TSR Drops 99%
Barry Elad
Reviewed By
Barry Elad
Barry Elad
Founder & Senior Journalist • 560 Articles
Barry Elad is a finance and tech journalist who loves breaking down complex ideas into simple, practical insights. Whether he's exploring fi... See full bio
LATEST POSTS:
How to Understand Crypto Market Cycles 2026: Winning Moves
How to Participate in a Crypto Airdrop Safely 2026: Avoid Scams
Toast Statistics 2026: ARR, GPV & Revenue Data
Zachxbt Uncovers 1m Per Month Dprk Crypto Pipeline
As Featured In
FortuneYahoo! FinanceCoinDeskSeeking AlphaCoin Market Cap
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A new investigation by blockchain analyst ZachXBT reveals a North Korea linked IT worker network generating nearly $1 million per month through crypto based payment flows and fraudulent employment schemes.

Key Takeaways

  • Over $3.5 million in crypto payments traced to a DPRK linked IT worker network since late November 2025.
  • Roughly $1 million per month flowing through crypto to fiat conversion channels.
  • Leaked internal server data exposed 390 accounts, chat logs, and transaction records.
  • Sanctioned entities and frozen wallets tied to the operation highlight ongoing enforcement pressure.

What Happened?

Blockchain investigator ZachXBT published findings from a large dataset extracted from an internal DPRK payment server. The data revealed a coordinated network of IT workers using fake identities and crypto payments to generate millions in revenue.

The investigation showed how funds were routed through cryptocurrency wallets and later converted into fiat through Chinese bank accounts and platforms like Payoneer, pointing to a structured and ongoing financial pipeline.

1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.

I spent long hours going through all of it, none of which has ever been publicly released.

It revealed an intricate… pic.twitter.com/aTybOrwMHq

β€” ZachXBT (@zachxbt) April 8, 2026

Inside the DPRK Payment Network

The investigation centers around an internal platform known as WebMsg, also linked to the domain luckyguys.site. This system functioned like a messaging and payment coordination tool where workers reported earnings and received instructions from a central administrator account identified as PC-1234.

According to the leaked data, the network included:

  • Around 390 user accounts with detailed identity records.
  • Internal chat logs showing communication between dozens of workers.
  • Wallet activity and transaction histories tied to crypto flows.
  • Organizational structures mapping payments across groups.

At least 33 workers were actively communicating within the same messaging system, highlighting a coordinated structure rather than isolated actors.

Weak Security and Operational Gaps

Despite handling millions in crypto, the operation showed surprisingly weak security practices. Several users reportedly kept the default password set to β€œ123456,” exposing critical vulnerabilities within the system.

The data was obtained after an infostealer malware compromised a DPRK worker’s device. An anonymous source later shared the files with ZachXBT, who confirmed the dataset had not been previously made public.

The platform went offline shortly after the findings were published, though the full dataset had already been archived.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

βœ… Join readers from Visa, Vanguard, and the FDIC.

Fake Identities and Global Payment Flows

The network relied heavily on forged documents and fake personas to secure remote employment opportunities. Workers used VPN services to hide their locations while applying for jobs across global platforms.

Once payments were received, the funds followed a consistent path:

  • Crypto payments collected from employers or platforms.
  • Transfers routed through blockchain wallets.
  • Conversion into fiat currency via exchanges or Payoneer.
  • Deposits into Chinese bank accounts.

Some internal messages even referenced Hong Kong addresses, although their authenticity remains unverified.

Links to Sanctioned Entities and Blockchain Traces

The leaked records included references to three entities sanctioned by the U.S. Treasury’s Office of Foreign Assets Control, namely Sobaeksu, Saenal, and Songkwang.

Onchain analysis further connected wallet addresses used in the operation to known DPRK IT worker clusters. One Tron wallet linked to the network was frozen by Tether in December 2025, indicating prior detection by authorities.

Broader Cyber Activity and Emerging Risks

While this network appeared less advanced than high profile DPRK groups such as Lazarus, Applejeus, or TraderTraitor, its scale remains significant. The operation aligns with previous estimates suggesting that North Korean IT worker schemes generate multiple seven figure revenues each month.

Internal logs also revealed potential targeting of crypto projects, including discussions about exploiting a blockchain based game using proxy setups. It remains unclear whether these plans were carried out.

Recent developments across the crypto sector further highlight the threat:

  • A Solana based project warned users after identifying a former DPRK linked employee.
  • Another protocol tied a major exploit to long running social engineering activity.
  • U.S. authorities have sanctioned facilitators connected to an $800 million crypto linked scheme.

CoinLaw’s Takeaway

In my experience, this investigation clearly shows how simple methods can still generate massive results in crypto crime. What stands out to me is not just the scale, but how basic some of the tactics were.

I found it surprising that a network moving millions relied on weak passwords and standard tools. This tells me the real advantage comes from coordination and persistence rather than technical brilliance.

For readers and builders in crypto, this is a reminder that security gaps at any level can be exploited, and even low sophistication actors can create serious financial impact when systems are not carefully monitored.

Definition of Blockchain. Link to full glossary entry follows the description.Blockchain

A distributed digital ledger that records transactions across a network, with each block cryptographically linked to the previous one for security.

Read more

This article has been reviewed and fact-checked by Barry Elad. CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Related Posts

US Seizes $15 Billion in Bitcoin from Cambodia-Based Prince Group Fraud Empire
Cryptocurrency

US Seizes $15 Billion in Bitcoin from Cambodia-Based Prince Group Fraud Empire

Kelp DAO Exploit Drains $292M, Lazarus Group Suspected
Cryptocurrency

Kelp DAO Exploit Drains $292M, Lazarus Group Suspected

Cryptocurrency Security and Fraud Statistics 2026: Big Threats
Cryptocurrency

Cryptocurrency Security and Fraud Statistics 2026: Big Threats

Disclaimer:Β The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

South Korea Targets Illicit Crypto Flows in Major $102M Laundering Case
Secret $60K Crypto Posts Revealed in ZachXBT’s Latest Transparency Bombshell
Ripple Shares DPRK Hacker Intel After $577M Crypto Hacks

Table of Contents

  • Key Takeaways
  • What Happened?
  • Inside the DPRK Payment Network
  • Weak Security and Operational Gaps
  • Fake Identities and Global Payment Flows
  • Links to Sanctioned Entities and Blockchain Traces
  • Broader Cyber Activity and Emerging Risks
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Ethereum Gas Fees Statistics
  • Zelle vs. Venmo Statistics
  • Millennial vs. Gen Z Banking
  • Binance vs. Coinbase Statistics
  • Traditional Banks vs. Neobanks
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10β€―a.m. – 6β€―p.m. | Every day

Copyright Β© 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❀️

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Payments
Toast Statistics 2026: ARR, GPV & Revenue Data
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics 2026: TPV, Valuation & Licences
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Digital Payments Statistics 2026: Market Size, Users, and Growth
Digital Payments Statistics 2026: Market Size, Users, and Growth
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Worldpay Statistics 2026: Massive Payment Growth
Worldpay Statistics 2026: Massive Payment Growth
Finance
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
AI-Powered Robo Trading Statistics 2026: Big Insights
AI-Powered Robo Trading Statistics 2026: Big Insights
Banking
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics 2026: Customers & Profit
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Credit Union Statistics 2026: Assets, Members, Loans
Credit Union Statistics 2026: Assets, Members, Loans
Banking API Statistics 2026: Market Size, Adoption, and Growth
Banking API Statistics 2026: Market Size, Adoption, and Growth
Citigroup Statistics 2026: Growth Secrets Inside
Citigroup Statistics 2026: Growth Secrets Inside
Insurance
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics 2026: Powerful Data Insights
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics 2026: Growth Facts
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics 2026: What You Must Know Now
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics 2026: Growth Data
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
Visa, Mastercard and Stripe Plan New Stablecoin Platform
Visa, Mastercard and Stripe Plan New Stablecoin Platform
Tether-Backed Adecoagro Launches Bitcoin Mining in Brazil
Tether-Backed Adecoagro Launches Bitcoin Mining in Brazil
Mastercard Expands Crypto Settlement With USDC and RLUSD
Mastercard Expands Crypto Settlement With USDC and RLUSD
Crypto.com Exchange Launches TradingView Integration
Crypto.com Exchange Launches TradingView Integration
Franklin Templeton Expands BENJI Access Through MoonPay
Franklin Templeton Expands BENJI Access Through MoonPay
Tessera DAO Hit by Exploit as TSR Drops 99%
Tessera DAO Hit by Exploit as TSR Drops 99%
Investments
Keyrock to Buy Bankrupt Crypto Lender BlockFills for $3.25M
Keyrock to Buy Bankrupt Crypto Lender BlockFills for $3.25M
OKX Buys 19.6% of Coinone in $53M Korea Crypto Deal
OKX Buys 19.6% of Coinone in $53M Korea Crypto Deal
Samsung Buys $408M Stake in Upbit Parent Dunamu
Samsung Buys $408M Stake in Upbit Parent Dunamu
Nvidia to Invest $150 Billion a Year in Taiwan AI Expansion
Nvidia to Invest $150 Billion a Year in Taiwan AI Expansion
Binance Launches SpaceX Pre-IPO Futures for Retail Traders
Binance Launches SpaceX Pre-IPO Futures for Retail Traders
Tether Buys SoftBank Stake in Twenty One Capital
Tether Buys SoftBank Stake in Twenty One Capital
Compliance
FCA Flags Crypto Sponsorship Risks for Premier League Clubs
FCA Flags Crypto Sponsorship Risks for Premier League Clubs
Polymarket May Enforce KYC as Regulators Tighten Oversight
Polymarket May Enforce KYC as Regulators Tighten Oversight
CFTC and Gemini Ask Court to Undo $5M Settlement
CFTC and Gemini Ask Court to Undo $5M Settlement
Kenya Proposes New Crypto Taxes Under Finance Bill 2026
Kenya Proposes New Crypto Taxes Under Finance Bill 2026
Poland Passes MiCA Crypto Bill Amid Zondacrypto Probe
Poland Passes MiCA Crypto Bill Amid Zondacrypto Probe
Bitget Secures Mexico Crypto Approval for LatAm Expansion
Bitget Secures Mexico Crypto Approval for LatAm Expansion
Fintech
Tether Launches First Gold Backed Visa Card With Fasset
Tether Launches First Gold Backed Visa Card With Fasset
OpenPayd Targets Nasdaq Listing With $1.145B Deal
OpenPayd Targets Nasdaq Listing With $1.145B Deal
Sui Identifies Bugs Behind Three Mainnet Network Outages
Sui Identifies Bugs Behind Three Mainnet Network Outages
OKX X Layer Introduces Exchange OS for Onchain Markets
OKX X Layer Introduces Exchange OS for Onchain Markets
ICE Partners With OKX for Brent and WTI Oil Perpetuals
ICE Partners With OKX for Brent and WTI Oil Perpetuals
Foundation Launches Passport Prime After $6.4M Funding Round
Foundation Launches Passport Prime After $6.4M Funding Round
Finance
Binance Expands Into US Stocks With New bStocks Service
Binance Expands Into US Stocks With New bStocks Service
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
Mastercard Expands Stablecoin Strategy With NY BitLicense
Mastercard Expands Stablecoin Strategy With NY BitLicense
Russia Plans Full Exit of Visa and Mastercard From Market
Russia Plans Full Exit of Visa and Mastercard From Market
Ondo Finance Founder Nathan Allman Passes Away at 32
Ondo Finance Founder Nathan Allman Passes Away at 32
Ripple Prime Boosts Margin Lending With $200M Credit Line
Ripple Prime Boosts Margin Lending With $200M Credit Line
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

βœ… Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

βœ… Read by pros at Visa, Vanguard, and the FDIC.