North Korean IT workers duped by fake crypto startup sting
The DPRK has spent years turning remote crypto hiring into a sanctions-evasion pipeline, and documenting how the bait works is one of the only public defences the rest of the industry has.
Scams are the cost of doing business in crypto — and one of the few risks this market can't route around with a hardware wallet. The Scams beat at Zipp tracks how fraud operators find victims, where the money actually flows, and which enforcement actions, on-chain analytics, or platform changes are closing the gap. We cover the full range: Rug pulls and exit scams on newly launched tokens, phishing campaigns that drain wallets through fake websites or signatures, address-poisoning attacks that rely on copy-paste mistakes, fraudulent airdrops engineered to capture approvals, and large Ponzi schemes that surface only when authorities step in.
A crypto reader needs this beat because the threat surface changes weekly, and the same headline can mean different things depending on the venue. A "whale moving funds to an exchange" might be a routine rebalance, an over-the-counter desk trade, or the prelude to a dump. A "flash crash on launch" can signal thin liquidity, a coordinated exit, or a misconfigured emission. Zipp's newsroom follows suspicious-transaction reports from firms like TRM Labs, Chainalysis, and Elliptic, court filings, exchange and stablecoin issuer statements, and project governance votes tied to team-held supply — and we publish what we confirm, not what influencers amplify.
Day to day, we watch address-poisoning campaigns targeting high-value BTC and ETH holders, fake-airdrop lures around trending tickers like SOL ecosystem projects, SIM-swap rings operating across borders, and regulatory moves that shift liability (recent examples include U.S. state-level rules making crypto ATM operators responsible for scam refunds). When a major incident breaks — a suspected rug pull, a seized-funds transfer between wallets, or a DOJ case that gets dropped or revived — we publish the on-chain evidence alongside the court record so readers can judge for themselves.
The DPRK has spent years turning remote crypto hiring into a sanctions-evasion pipeline, and documenting how the bait works is one of the only public defences the rest of the industry has.
Over 1,600 victims handed $397M to a fund that promised crypto liquidity pool returns; the CFTC and SEC filed charges the same day, with Delgado already facing federal wire fraud counts.
The scale of the allegation puts investor protection and compliance risk at the center of the market impact, while the claims remain unproven in court.
Fraud losses, state bans, KYC rules and high fees are pushing the US Bitcoin ATM sector toward a broader business-model rethink.
The raid follows Russia's January ban on WhiteBit and treats unlicensed crypto desks as a sanctions-evasion vector funding Kyiv.
The decision keeps executive accountability at the center of crypto's post-FTX compliance debate.
MiCA turns authorization status into a frontline trust signal as EU users distinguish firms allowed to serve them from impersonators.
Tarsha allegedly drained SAFT proceeds into gambling, crypto speculation, and a Miami condo while staging a fake marketplace to keep investors in the dark.
The case lands before Judge Lewis Kaplan, who sentenced Sam Bankman-Fried, signaling federal prosecutors are treating NFT fraud with the same seriousness as the FTX collapse.
The law forces unlicensed operators to make victims whole, reframing the Bitcoin ATM from a quick-cash kiosk into a regulated money-transmission product.
Four wallets linked to the staffer bought 80% of supply for $10K then dumped for $638K, a textbook insider-extraction pattern that CZ himself called a scam.
Michael Coates, ex-Twitter and Mozilla security lead, says attackers are moving off smart contracts and onto people, with full spoofed voice calls as the near-term threat.
The layoffs hit hardest on employees two months out from multi-million-dollar token payouts, raising fresh questions about how memecoin platforms value and compensate the teams behind them.
The letters mimic official IRS correspondence and direct recipients to a "Digital Asset Compliance Portal" that does not exist, part of a broader wave of social-engineering attempts targeting crypto…
The confirmed take is 3.4M XRP from a one-week scam site, but Seoul police believe the real haul could approach $20M as investigators trace flows from blogs, Wikipedia and YouTube funnels.
Seoul's Metropolitan Police Agency tracked 3.4 million XRP on-chain and froze suspects' wallets within three days, but the market barely flinched.
The lawsuit alleges Apple promoted Sparrow impersonators inside curated crypto collections despite a year of warnings from the wallet's own developer, testing the App Store's 'safe and trusted' pitch…
The world's largest crypto exchange tells investigators to use slow treaty channels for most cases, while still answering direct calls on child exploitation, terrorism, and imminent threats to life.
A late-night comedy segment rarely moves a market, but this one lands on a sitting president's $1.4B crypto income stream and a $TRUMP memecoin already down 6% on the day.
Cross-platform spyware hiding in official app stores used OCR to lift wallet seed phrases straight out of users' camera rolls, with one Android app clearing 10K downloads before removal.
A rug pull is when the team behind a token project removes liquidity or sells its holdings, leaving buyers with a worthless asset. It is most common on newly launched tokens where developers retain a large share of the supply or control the liquidity pool.
Attackers send a tiny transaction from a wallet address that matches the first and last characters of a victim's real contacts, hoping the victim copies the wrong address during a future transfer. The attack relies on visual similarity, not on any code exploit.
It is a fraud that pays early participants with funds from new investors rather than with real revenue, and it collapses once inflows slow down. Crypto Ponzi cases are typically uncovered by chain analytics or whistleblower complaints rather than by users spotting the math.
Yes, established projects use airdrops to distribute tokens to active users, but the same word is also used by scammers to lure victims into signing malicious wallet approvals. Always verify the contract address and the official project channel before claiming.