KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!





The hack that caused Axie Infinity losses of $620 million in crypto started with a fake job offer from North Korean hackers to one of the gameโs developers.
The attackย happenedย in March 2022ย and pushed into the ground the then massively popular and quickly-growing game from Sky Mavis.
By April 2022, the FBI was able to link the attack to theย Lazarus and APT38ย hackers, two groups who are often involved in cryptocurrency heists for the North Korean government.
In a recentย reportย from news publication on digital assets The Block, sources with knowledge about the attack said that the threat actors contacted staff atย Sky Mavis over LinkedIn, posing as a company looking to hire them.
Also Read: Ways to protect HR data and avoid penalties for data breaches
One senior engineer atย Axie Infinity showed interest in the fake job offer, due to the very generous salary, and went through multiple rounds of interviews.
At one point, the engineer received a PDF file with details about the job. However, the document was the hackers’ way into the Ronin systems –ย the Ethereum-linked sidechainย that supports the Axie Infinity non-fungible token-based online video game.
The employee downloaded and opened the file on the companyโs computer, initiating an infection chain that enabled the hackers to penetrate Roninโs systems and corrupt four token validators and one Axie DAO validator.
According to the firmโsย post-mortem, the employee who fell victim to the spear-phishing attack has since been removed from its workforce. However, the game is still launchingย investment initiativesย andย technical restartsย trying to regain itsย momentum.
The financial damage was so fundamental that Sky Mavis is stillย in the processย of reimbursing the players who were affected by the hack.
North Korean hackers working for the government have been linked to multiple cryptocurrency hacks over the years.
Last year, a report from Google’s Theat Analysis Group noted that a North Korean hacker groupย targeted security researchersย with custom malware after approaching them over various platforms, including LinkedIn.
In the summer of 2020, members of the Lazarus group targeted employees of cryptocurrency organizations inย at least 14 countriesย using fake job offers.
Earlier this year, theย U.S. government warnedย thatย the Democratic Peopleโs Republic of Korea (DPRK) is dispatchingย IT workers to get freelance jobs that could sometimes be used in state-backed attacks.
Research from Cyphereย released a year ago showed how easy it was for anyone to post job offers on behalf of a company’s on LinkedIn.
The FBI hasย recently warnedย about the perils of fake job postings, highlighting some common signs of fraud that internet users should keep in mind when receiving unsolicited job offers.