A suspected DPRK IT worker was employed at THORSwap

2026-05-11 meowmfer

https://archive.md/5mrJC

Thumbnail for A suspected DPRK IT worker was employed at THORSwap

A suspected DPRK IT worker allegedly gained employment at THORSwap and submitted eight pull requests to the official swapkit/SwapKit repository between July and September 2024, with at least three merged. The merged PRs changed wallet integration code for Talisman, Polkadot.js, and Chainflip, a layer handling user fund interactions across THORChain, Chainflip, and EVM chains. The investigation links four GitHub identities through shared email and username patterns, including a THORSwap employee identity, and says one linked email appeared on a DPRK-operated freelancing platform. The same cluster is tied to a Zoom screen-sharing hider, MEV tooling, collaboration with other suspected DPRK accounts, and possible access to THORSwap private development code.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0x0f8018Bd90c61EE0B4D3C75B0FbDE… 2026-05-11 2026-05-11
EMAIL [email protected] 2026-05-11 2026-05-11
EMAIL [email protected] 2026-05-11 2026-05-11
EMAIL [email protected] 2026-05-11 2026-05-11
EMAIL [email protected] 2026-05-11 2026-05-11

Related Reports

« Back