On September 4, 2024, SecurityWeek reported an FBI warning that North Korean threat actors were targeting people connected to cryptocurrency and decentralized-finance businesses with researched, individualized approaches. Fake job offers, investment pitches, and familiar-looking contacts could lead to malware—especially when a target is persuaded to run code or an application on a company device. Treat an unexpected opportunity as unverified until you confirm it independently, and never run unknown code on an employer’s equipment.
How the reported attacks worked
According to SecurityWeek’s account of the FBI warning, the actors researched prospective victims and built scenarios tailored to them. Some centered on employment or corporate investment; others involved impersonating someone the target might know. Realistic images—including photos taken from social media and fabricated images of time-sensitive events—could help make the approach seem credible.
Conversations could continue long enough to establish trust before malware arrived in an apparently ordinary context. SecurityWeek quoted the FBI as saying, “North Korean social engineering schemes are complex and elaborate, often compromising victims with sophisticated technical acumen. Given the scale and persistence of this malicious activity, even those well versed in cybersecurity practices can be vulnerable.” The coverage did not identify an individual FBI official as the speaker.
Should I run a coding test on my work laptop?
No. Do not run code, applications, or unfamiliar packages supplied by a recruiter, investor, or other contact on a company-owned device. A coding challenge can be the delivery mechanism for malware, even if the role and conversation appear plausible. SecurityWeek reported that the FBI warning specifically called out requests to run code or applications on company-owned devices and tests involving non-standard code packages.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Mandiant described a related fake-recruiting intrusion against an employee of a cryptocurrency exchange. An alleged North Korean actor contacted an engineer about a job on LinkedIn, then sent a ZIP file presented as a Python coding challenge that delivered malware. The format of a test or the apparent familiarity of the contact does not establish that a file is safe.
How can I verify an unexpected job or investment offer?
Verify the person, organization, and request through a separate channel you already trust—not only through contact details, links, or accounts supplied in the approach. If someone claims to represent a colleague or business partner, contact that person using a known number or established company account. Ask your security team to review suspicious files or messages rather than opening them yourself.
Rank #2
- Be cautious about offers of employment or investment that arrive unexpectedly, particularly when the contact quickly asks you to install software or complete a technical test.
- Do not let pressure to move the conversation to another messaging platform replace independent identity checks.
- Do not provide cryptocurrency-wallet information in response to an unexpected request.
- Avoid opening unsolicited contacts containing links or attachments until your organization’s security process has assessed them.
- Report suspicious recruiting, investment, or impersonation approaches to your security team and follow your employer’s incident-reporting process.
What controls should a crypto business put in place?
Employee caution is only one layer. SecurityWeek’s account of the FBI recommendations included multifactor authentication (MFA), closed platforms for business communications, identity-verification procedures, and restricted access to sensitive network documentation and code repositories. Organizations should also make clear that staff must not run interview tests or recruiter-supplied code on work devices.
MFA is useful, but it cannot prevent every part of this attack chain: it does not make a malicious file safe or stop someone from executing malware on a device. A FIDO2 hardware security key is one possible MFA option, not a specific FBI-recommended product or a substitute for employer policy, endpoint protections, least-privilege access, and incident response.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
How social engineering differs from other Web3 attack paths
Not every cryptocurrency theft begins with a deceptive message, and the FBI warning should not be read as attributing every Web3 heist to North Korean social engineering. Mandiant’s September 2024 analysis describes distinct routes with different initial weaknesses and defenses:
| Attack path | Initial access or weakness | Relevant defense |
|---|---|---|
| Tailored social engineering | A fake job or investment approach, or impersonation, builds trust and prompts a target to execute supplied code. | Verify identity independently, refuse unknown code on work devices, and report suspicious approaches. |
| Supply-chain compromise | Malware or access enters through a trusted supplier or software relationship and can affect downstream organizations. | Monitor supplier access and investigate unexpected endpoint or account activity. |
| Smart-contract exploit | Flawed contract logic, including patterns such as reentrancy or flash-loan attacks, can be exploited without deceiving an employee. | Review and test contract code; social-engineering controls alone do not address contract flaws. |
Mandiant also describes how an intrusion can progress beyond initial malware to password managers, internal documentation and code repositories, cloud environments, and ultimately hot-wallet credentials or keys. Its analysis discusses supply-chain incidents including the 2023 JumpCloud and 3CX cases affecting downstream customers.
What the reported losses figure does—and does not—show
Mandiant stated that more than $12 billion in digital assets had been stolen across hundreds of reported Web3 heists since 2020, attributing that figure to Chainalysis’ 2024 Crypto Crime Report. This is Mandiant’s attribution of the Chainalysis figure, not an independently recalculated total, and it covers Web3 heists generally rather than losses from the specific FBI-described recruiting approaches.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How current is the warning?
The reporting date is September 4, 2024. SecurityWeek linked to an FBI/IC3 advisory, but that link returned a 404 when checked for the reporting summarized here; the warning’s details are therefore conveyed through SecurityWeek’s contemporaneous coverage, with technical context from Mandiant’s September 3, 2024 analysis. These sources do not establish the level of activity in 2026 or whether the FBI has since issued a successor advisory.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
Sources: SecurityWeek, “FBI: North Korea Aggressively Hacking Cryptocurrency Firms,” September 4, 2024; Mandiant / Google Cloud, “DeFied Expectations — Examining Web3 Heists,” September 3, 2024.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




