Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    STRC Drops 19% Below Par Was Peter Schiff Right About Saylor Deceiving Investors
    STRC Drops 19% Below Par: Was Peter Schiff Right About Saylor Deceiving Investors?
    Litecoin Summit Day 2 LitVM's $50M Bet and BasicSwapDEX's Bold Vision
    Litecoin Summit Day 2: LitVM’s $50M Bet and BasicSwapDEX’s Bold Vision
    Litecoin Summit Day 1 Quantum Warnings, Privacy Coin Breakthroughs, & MiCA's Looming Deadline
    Litecoin Summit Day 1: Quantum Warnings, Privacy Coin Breakthroughs, & MiCA’s Looming Deadline
    Inside the High-Stakes Corporate War Over the GENIUS Act
    Inside the High-Stakes Corporate War Over the GENIUS Act
    From Demonetization to Digital Rupee India's Decade-Long Blockchain Journey
    From Demonetization to Digital Rupee: India’s Decade-Long Blockchain Journey
  • Opinion
    OpinionShow More
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

North Korea-Linked Hackers Target Crypto Supply Chain in Cloud Breach

Exploiting the React2Shell vulnerability, attackers stole backend code, Docker images, and AWS Terraform files, setting the stage for future digital asset heists.

Written By Kenrodgers Fabian Kenrodgers Fabian
Fact Checked by Divya Mistry Divya Mistry
Published 2026-03-09
Make The Crypto Times preferred on GoogleGoogle
Last updated: March 9, 2026 12:41 PM
Published 2026-03-09
Share
Last updated: March 9, 2026 12:41 PM
Published 2026-03-09
North Korea-Linked Hackers Target Crypto Supply Chain in Cloud Breach

Key Highlights

  • North Korea-linked hackers targeted crypto platforms and staking services, stealing source code, private keys, and sensitive cloud data across the entire supply chain.
  • Attackers exploited AWS credentials, Docker, and Kubernetes, showing advanced cloud hacking skills.
  • Security firm Ctrl-Alt-Intel attributes the campaign to TraderTraitor (UNC4899), the same group behind the $1.5 billion Bybit hack and the 2023 JumpCloud supply chain breach.

A hacking campaign tied to North Korea has hit multiple cryptocurrency platforms, staking services, and exchange software vendors. According to security firm Ctrl-Alt-Intel, the attackers exploited vulnerabilities in web applications and misused stolen AWS login credentials to infiltrate cloud environments and steal sensitive data.

As per the findings report, the attack affected the entire crypto supply chain, raising worries about possible future theft of digital assets. The hackers focused on stealing backend source code, Docker container images, and configuration files that contained sensitive information like passwords and keys.

Ctrl-Alt-Intel reported that the attackers used valid AWS credentials to explore cloud storage, Terraform files, Lambda functions, and Kubernetes clusters. They also ran large-scale scans to find React2Shell vulnerabilities in web applications, showing both their skill and the wide reach of the campaign.

Exploitation tactics and infrastructure

The attackers demonstrated highly advanced cloud hacking skills. They first checked that their access worked using AWS commands and quickly mapped out storage and database resources. Then, they copied Terraform configuration files, which can contain passwords, admin accounts, and internal network details, to find valuable information.

They also stole Docker images from Amazon’s container registry and explored Kubernetes pods to grab secrets stored in configuration files and AWS Secrets Manager. Ctrl-Alt-Intel confirmed that five Docker images were taken, all containing proprietary code for cryptocurrency exchanges.

The hackers operated through infrastructure based in South Korea, specifically the server 64.176.226[.]36 and the domain itemnania[.]com. They also used FlyVPN services to hide their true location. The report notes that security teams often focus on IPv4 addresses, so using IPv6 helped the attackers evade detection.

Attribution and threat context

Ctrl-Alt-Intel thinks it’s likely that North Korea-linked hackers carried out the attacks, probably the group called TraderTraitor (UNC4899). This group has a documented pattern of targeting crypto supply chain providers. It has previously targeted companies that provide software to crypto platforms, including JumpCloud in 2023 and Safe{Wallet}/ByBit in 2025. In those earlier attacks, they also misused AWS credentials and set up systems for possible future theft.

However, researchers caution that some details remain unclear. They do not know exactly how the hackers got the AWS credentials, and they didn’t find any malware uniquely tied to North Korea. 

The attackers used tools called VShell and FRP to control systems remotely—tools often associated with Chinese hackers but publicly available. As a result, investigators rely on patterns of activity, the infrastructure used, and attack methods to connect the attacks to TraderTraitor rather than a single technical clue.

The attack represents a severe supply chain compromise. By stealing proprietary code and infrastructure blueprints today, these attackers are laying the groundwork for catastrophic financial exploits in the future. 

Also Read: Vitalik Warns of ‘Authoritarian Wave,’ Calls for Rethinking Crypto Governance

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Crypto Journalist at The Crypto Times, based in Kenya. He reports on high-profile global financial fraud, investment scams, phishing schemes, and cross-chain protocol exploits. His coverage heavily tracks systemic crypto vulnerabilities, ecosystem security breaches, and central bank shifts toward stablecoins and tokenized finance infrastructure. All investigative coverage on crypto cybercrimes and security events passes through his desk before publication. His four years in fast-paced crypto media have shaped his structured approach to deciphering malicious smart contracts, verifying data-heavy fraud cases, and providing accurate reporting on digital currency risks.
Divya Mistry
By Divya Mistry
Follow:
Divya Mistry is the Senior Editor at The Crypto Times. She leads the central editorial desk, overseeing the review and publication of policy analyses, investigative reports, exchange coverage, and protocol exploit stories. Her editorial remit spans digital asset markets, global exchange operations, cross-border digital asset settlements, regulatory developments, and other key developments shaping the cryptocurrency industry. Divya brings more than a decade of experience in editorial strategy, content development, public relations, marketing communications, and research. Before joining The Crypto Times, she worked across multiple sectors, including finance, technology, education, healthcare, real estate, entertainment, lifestyle, and vertical transport, contributing to both digital and print publications. Her research and content work has been featured on platforms including DNA India, Zee, Forbes, and Elevator World India. She holds a Master's degree in English Literature from the University of Mumbai. Drawing on her background in long-form publishing, research, and editorial leadership, she reviews and refines complex stories to ensure accuracy, clarity, and strong editorial standards before publication.

Latest News

Cardano's SecondFi Hack EMURGO Sets 2-Week Timeline to Return Stolen ADA
Cardano’s SecondFi Hack: EMURGO Sets 2-Week Timeline to Return Stolen ADA
Why AAVE Price Surged 20% Today: 3 Major Catalysts Driving the Rally
Why AAVE Price Surged 20% Today: 3 Major Catalysts Driving the Rally
Base Postpones B20 Activation Due to Network Issues
Base Postpones B20 Activation Due to Network Issues
US Rep. Maxine Waters Opposes DOL Plan to Allow Crypto in 401(k)s
US Rep. Maxine Waters Opposes DOL Plan to Allow Crypto in 401(k)s
ASIC Pushes Crypto Licensing Deadline Back to September 2026
ASIC Pushes Crypto Licensing Deadline Back to September 2026

Find Us on Socials

You may also like

Crypt Investor Lost 2.3M ADA on Ledger Without Signing Anything

Crypto Investor Lost 2.3M ADA on Ledger Without Signing Anything

Tether-Backed Dreamcash Cuts CASH Markets Amid Hyperliquid USDC Surge

Tether-Backed Dreamcash Cuts CASH Markets Amid Hyperliquid USDC Surge

Aave Founder Denies 70% Discount Sale to Kraken’s Payward

Aave Founder Denies 70% Discount Sale to Kraken’s Payward

Sei DEX Oxium to Shut Down August 1 as Revenue Hits Critical Lows

Sei DEX Oxium to Shut Down August 1 as Revenue Hits Critical Lows

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information