{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k"},"incident":{"title":"Munchables loses $62.5M to a developer it hired who was linked to North Korea","date":"2024-03-26","date_precision":"day","victim_org":"Munchables (NFT game on Blast)","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Insider Access"],"loss_usd":62500000,"loss_note":"About $62.5 million in ether at the time of the exploit. All funds were recovered after the developer surrendered the private keys without a ransom being paid.","records_affected":null,"threat_actor":"A developer using the GitHub handle 'Werewolves0493', assessed by investigator ZachXBT as North Korea-linked","summary":"Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.","how_it_worked":"This was infiltration rather than intrusion: the attacker was hired. Working as a Munchables developer with contract-deployment privileges, they positioned control of stored user funds ahead of a scheduled contract upgrade, then transferred those funds to themselves before the upgrade landed, so the movement looked like part of routine deployment activity. ZachXBT's analysis of GitHub commit timing and cross-referenced accounts suggested the developer was part of a cluster of DPRK-linked personas that had recommended one another into crypto projects, meaning the vetting failure compounded across multiple hires. Recovery came from negotiation, not from any control the project held.","lessons":"Live identity verification, tied to independently corroborated employment history, is the gate for anyone who will hold deployment or upgrade keys, and no single developer should be able to move user funds without multi-party approval.","confidence":"Reported","sources":[{"title":"Munchables Exploited for $62M, North Korea-Linked Exploiter Returns Private Keys to Web 3 Firm","url":"https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","publisher":"CoinDesk"},{"title":"Explained: The Munchables Hack (March 2024)","url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k"}}