What happened
Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.
How the deception worked
After direct infrastructure attacks failed, the operators changed target from the network to a person. Fake recruiters approached a CoinsPaid engineer over messaging and professional platforms with an offer well above market rate, then moved the conversation to an interview process. The 'technical task' the candidate was asked to run as part of that process was the payload. Running it on their working machine gave the attackers a foothold with the employee's credentials and access, from which they reached the infrastructure that authorised outbound transfers and drained more than $37 million. CoinsPaid noted the transaction patterns closely mirrored other Lazarus operations from the same period.
AI involvement · No AI reported
No AI involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Job-application code and take-home assessments must only ever run in a disposable, network-isolated VM, and recruiters approaching engineers with outsized offers should be treated as an active threat indicator, not an HR event.
Sources (2)
- CoinsPaid claims North Korean hacking group used fake job interview to steal $37MCointelegraph·cointelegraph.comOpen ↗
- The CoinsPaid Hack ExplainedCoinsPaid·coinspaid.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.