A suspected DPRK IT worker was employed at THORSwap
2026-05-11 • meowmfer •
A suspected DPRK IT worker allegedly gained employment at THORSwap and submitted eight pull requests to the official swapkit/SwapKit repository between July and September 2024, with at least three merged. The merged PRs changed wallet integration code for Talisman, Polkadot.js, and Chainflip, a layer handling user fund interactions across THORChain, Chainflip, and EVM chains. The investigation links four GitHub identities through shared email and username patterns, including a THORSwap employee identity, and says one linked email appeared on a DPRK-operated freelancing platform. The same cluster is tied to a Zoom screen-sharing hider, MEV tooling, collaboration with other suspected DPRK accounts, and possible access to THORSwap private development code.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0x0f8018Bd90c61EE0B4D3C75B0FbDE… | 2026-05-11 | 2026-05-11 |
| [email protected] | 2026-05-11 | 2026-05-11 | |
| [email protected] | 2026-05-11 | 2026-05-11 | |
| [email protected] | 2026-05-11 | 2026-05-11 | |
| [email protected] | 2026-05-11 | 2026-05-11 |