Guide for crypto companies: how to prevent infiltration through employment
Employees of the Kraken crypto exchange managed to identify a Lazarus Group hacker who claimed to be in a technical position at the company
05.05.2025
769
4 min
0
For years now, hackers have been trying to overcome the defenses of financial and crypto companies in a rather clever way — through employment. Attackers create fake identities and take jobs at companies they are interested in, making the hacking process much easier. GetBlock AML Research publishes a recent case study of the crypto exchange Kraken, which prevented a hacker from infiltrating.
Kraken routine
Kraken is one of the largest crypto exchanges in the United States. As of early May 2025, it has 30 active openings. Kraken carefully monitors and scrutinizes each of the potential candidates, as the company has a culture of “productivity paranoia.” The exchange’s management believes that in the current environment where hackers are able to break into financial companies to the tune of billions of dollars, security must be achieved through collective organizational thinking.
One of the exchange’s open positions was claimed by a suspicious applicant. Employees decided not to distance themselves from the candidate, but to ferret him out and investigate the methods used by attackers.
Red flags
A hacker trying to impersonate someone else immediately made many mistakes. When first communicating via video call — he connected to the call under a different name (not the one on his resume), and then quickly changed it to the correct one. During the communication, the candidate’s voice changed several times, which may indicate the use of a neural network to change his voice.
Kraken had a database of email addresses that Lazarus Group hackers used in their attacks. The address provided by the jobseeker was in that database. Kraken employees then launched an in-depth investigation to ferret out the attacker.
Lazarus Group hacker who tried to impersonate another person
The exchange’s staff scrutinized the email address provided by the hacker and found that it had been used for mass mailings to other companies and under other aliases.
Kraken gathered some more evidence in favor of the fact that an infiltration operation was being conducted against them:
- The job candidate used remote Mac desktops as well as VPNs to hide his location;
- The repository on GitHub that the candidate provided contained an already different email address. It was also used by the Lazarus Group hackers;
- The personal data and identity document used by the attacker was leaked several years ago in a massive user data leak.
Fake driver’s license used by hacker
Investigative experiment
Even though the Kraken team found enough evidence, they decided to work further and try to publicly uncover the hacker. He completed all the technical tests and verification tasks and then was invited to a final interview with Kraken’s head of security, Nick Percoco.
During the interview, the exchange staff casually threw in questions to identify the individual. For example, the candidate was asked to confirm his real-time location, show a government-issued ID, and recommend several restaurants in the location where he was said to be. The hacker was unable to complete any of the verification questions, confirming Kraken’s suspicions.
What lessons Kraken has learned
After successfully identifying a hacker and successfully countering the threat, the exchange’s employees have highlighted a number of theses that should be adhered to ensure security.
- Hacker groups are increasingly using stealth methods to make it easier to steal assets. Financial and cryptocurrency organizations must build effective internal compliance systems to counter the new threat;
- Artificial Intelligence systems have changed the rules of the game and made it much easier to spoof identities, change voices, and even handle complex technical tasks. Therefore, security officers must also learn how to effectively utilize AI to counter attackers;
- Kraken’s culture of “productive paranoia” is a liability in the world of modern technology.
Useful material?
Research
One and the same cryptocurrency address received two completely opposite assessments from different analytics systems: from an ordinary gambling service to an extremely severe criminal offense. This story has become the starting point for a broader conversation about what the scientific standards of blockchain analysis should look like — and why errors in systems like these can shape the fates of real people.
Jul 1, 2026
Research
The blockchain has helped uncover the ties between cryptocurrency fundraising campaigns, exchangers in Syria, and intermediaries in several countries around the world. A telltale pattern has emerged in which the same addresses were used across multiple donation drives at once
Jun 24, 2026
Research
Four Iranian cryptocurrency exchanges accounted for roughly 78% of all digital asset volume tied to the country in 2025. They have now become the focal point of the largest U.S. sanctions campaign against Iran's cryptocurrency infrastructure.
Jun 5, 2026
Research
A financial system is already up and running on public blockchains, with loans, analogues of U.S. Treasuries, and automated capital markets. More than $551 billion has flowed through DeFi protocols — but most of that activity has nothing to do with the real economy and everything to do with the speculative build-up of risk.
May 29, 2026
Research
Around 97% of Chinese suppliers of chemicals used to make fentanyl accept payment in cryptocurrency. The volume of such transactions continues to grow alongside the global market for synthetic drugs
May 22, 2026
Research
For the first time, the new law makes blockchain analytics an officially mandatory tool of financial oversight in the United States. Authorities will also gain the power to restrict transactions with foreign crypto services tied to money-laundering risks.
May 20, 2026
Telegram
Twitter