Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

North Korea-Linked Hackers Target Crypto Supply Chain in Cloud Breach

Exploiting the React2Shell vulnerability, attackers stole backend code, Docker images, and AWS Terraform files, setting the stage for future digital asset heists.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2026-03-09
Make The Crypto Times preferred on GoogleGoogle
North Korea-Linked Hackers Target Crypto Supply Chain in Cloud Breach

Key Highlights

  • North Korea-linked hackers targeted crypto platforms and staking services, stealing source code, private keys, and sensitive cloud data across the entire supply chain.
  • Attackers exploited AWS credentials, Docker, and Kubernetes, showing advanced cloud hacking skills.
  • Security firm Ctrl-Alt-Intel attributes the campaign to TraderTraitor (UNC4899), the same group behind the $1.5 billion Bybit hack and the 2023 JumpCloud supply chain breach.

A hacking campaign tied to North Korea has hit multiple cryptocurrency platforms, staking services, and exchange software vendors. According to security firm Ctrl-Alt-Intel, the attackers exploited vulnerabilities in web applications and misused stolen AWS login credentials to infiltrate cloud environments and steal sensitive data.

As per the findings report, the attack affected the entire crypto supply chain, raising worries about possible future theft of digital assets. The hackers focused on stealing backend source code, Docker container images, and configuration files that contained sensitive information like passwords and keys.

Ctrl-Alt-Intel reported that the attackers used valid AWS credentials to explore cloud storage, Terraform files, Lambda functions, and Kubernetes clusters. They also ran large-scale scans to find React2Shell vulnerabilities in web applications, showing both their skill and the wide reach of the campaign.

Exploitation tactics and infrastructure

The attackers demonstrated highly advanced cloud hacking skills. They first checked that their access worked using AWS commands and quickly mapped out storage and database resources. Then, they copied Terraform configuration files, which can contain passwords, admin accounts, and internal network details, to find valuable information.

They also stole Docker images from Amazon’s container registry and explored Kubernetes pods to grab secrets stored in configuration files and AWS Secrets Manager. Ctrl-Alt-Intel confirmed that five Docker images were taken, all containing proprietary code for cryptocurrency exchanges.

The hackers operated through infrastructure based in South Korea, specifically the server 64.176.226[.]36 and the domain itemnania[.]com. They also used FlyVPN services to hide their true location. The report notes that security teams often focus on IPv4 addresses, so using IPv6 helped the attackers evade detection.

Attribution and threat context

Ctrl-Alt-Intel thinks it’s likely that North Korea-linked hackers carried out the attacks, probably the group called TraderTraitor (UNC4899). This group has a documented pattern of targeting crypto supply chain providers. It has previously targeted companies that provide software to crypto platforms, including JumpCloud in 2023 and Safe{Wallet}/ByBit in 2025. In those earlier attacks, they also misused AWS credentials and set up systems for possible future theft.

However, researchers caution that some details remain unclear. They do not know exactly how the hackers got the AWS credentials, and they didn’t find any malware uniquely tied to North Korea. 

The attackers used tools called VShell and FRP to control systems remotely—tools often associated with Chinese hackers but publicly available. As a result, investigators rely on patterns of activity, the infrastructure used, and attack methods to connect the attacks to TraderTraitor rather than a single technical clue.

The attack represents a severe supply chain compromise. By stealing proprietary code and infrastructure blueprints today, these attackers are laying the groundwork for catastrophic financial exploits in the future. 

Also Read: Vitalik Warns of ‘Authoritarian Wave,’ Calls for Rethinking Crypto Governance

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Andrew Tate wearing sunglasses and silver chains sitting ringside at a public event
Andrew Tate Moves $1.87M of HYPE to Binance, Sitting on a 1,317% Gain
Gold Pepe PEPE meme coin displayed in front of a Canary Capital corporate logo
Canary Amends PEPE ETF Filing as Token Price Drops Nearly 7%
Treasury’s US Financial Literacy Plan Names Digital Assets, Prediction Markets 
Treasury’s US Financial Literacy Plan Names Digital Assets, Prediction Markets 
Bitcoin Price Slips to $84,600 as $433M Liquidations Hit Longs After $87K Rejection
Bitcoin Price Slips to $84,600 as $433M Liquidations Hit Longs After $87K Rejection
South Korean flag waving in front of the National Assembly dome representing crypto regulation and government blockchain initiatives
South Korea Proposes Rules for Tokenized Stocks, Bonds and Funds

Find Us on Socials

You may also like

NEAR Protocol (NEAR) physical coin standing next to stacked gold coins and a crypto wallet.

NEAR Intents Ends Exploit Probe After $3.8 Million Is Returned

Blast Layer 2 protocol logo in neon yellow against a dark background.

Blast Shuts Down Ethereum L2 as Operating Costs Exceed Revenue

Drift Protocol logo and wordmark set against a dark digital background.

Drift Opens DFX Claims at 1 Cent Per Token After April Exploit

Ronin Wallet 3D corporate branding logo and typography on a dark wall background.

Axie Infinity Ends Waypoint Wallets as October 16 Migration Deadline Nears

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information