A security researcher who spent nearly two years quietly embedded inside North Korean hacking infrastructure has revealed the operation's true scale: 1,640 breached companies across 57 countries, including crypto giants Coinbase and Uniswap Labs. Vangelis Stykas, chief technology officer at cybersecurity firm Kumio, gained access to the group's command-and-control servers and, in some cases, the hackers' own workstations, Slack channels, and Discord servers after the attackers apparently infected themselves with their own malware.

Stykas maintained that access for 22 months before presenting his findings at the Black Hat security conference in Las Vegas this month. Of the 1,640 companies he found evidence of compromise at, he described 700 to 800 as having suffered intrusions serious enough to cause real damage — not just superficial network access.

Researcher Infiltrated North Korea's Hackers, Found Coinbase and Uniswap Among 1,640 Victims
Image via @WuBlockchain on X

Fake Job Offers as the Entry Point

The primary attack vector, a campaign researchers call Contagious Interview and which Microsoft has tracked since as early as 2022, relies on social engineering rather than sophisticated exploits. Operatives lure software developers and contractors with fake job offers, then ask targets to complete what looks like a routine coding test — a program that secretly installs malware the moment it's run. The technique has proven effective precisely because it targets an unguarded moment: developers evaluating a job opportunity, not defending a network.

What the Hackers Actually Got

According to Stykas, the level of access varied by target but frequently went well beyond a foothold. In multiple cases the attackers obtained company-wide access, root access to servers, and root access to AWS infrastructure. For crypto companies specifically, that included private keys and direct blockchain access — the kind of compromise that can translate straight into stolen funds rather than just stolen data.

Related: Violent Crypto Attacks Cost Victims $30M in H1 2026, France Hit Hardest

The list of named victims — which also includes Boston Children's Hospital and Chinese smartphone maker OPPO — underscores that the campaign was never limited to crypto firms, even though crypto companies appear to have been treated as especially high-value targets given the direct path from server access to on-chain assets. North Korean state-linked hacking groups have long been associated with crypto theft used to fund the regime's weapons programs, and Stykas's findings suggest the actual footprint of that campaign has been far larger, and far more successful, than previously documented.