TraderTraitor
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
TraderTraitor is a North Korean‑linked threat actor also known by the alias TraderTraitor, operating under the direction of the state to generate revenue for its nuclear program. The actor primarily targets decentralized finance protocols and cross‑chain asset platforms, seeking financial gain through the theft of cryptocurrency that is subsequently funneled to support state objectives. Public reporting attributes these activities to North Korean APT groups, establishing a clear state nexus rather than a criminal consortium. The actor’s strategic objective is explicitly tied to financing the regime’s nuclear ambitions, as evidenced by the large sums of cryptocurrency stolen in multiple incidents.
Observed tactics, techniques, and procedures include prolonged social engineering campaigns that leverage artificial intelligence to craft convincing lures and generate malicious code. Initial access has been achieved through compromised code repositories, malicious TestFlight wallet applications, and undisclosed vectors that allow the actor to obtain private‑key control. Once inside a protocol, TraderTraitor has altered multi‑signature approval mechanisms—such as reducing required signatures from five to two and removing delays—to facilitate unauthorized actions. The actor has minted large quantities of fake tokens that are accepted as collateral, enabling inflated borrowing limits and rapid withdrawals of stablecoins and other assets. Stolen funds are routinely swapped to USDC on the originating chain, bridged to Ethereum, and laundered through mixing services before the affected protocol suspends operations. AI‑assisted scams and code generation are repeatedly cited as force multipliers that increase the speed and effectiveness of these operations.
Representative operations include the six‑month compromise of the Solana‑based perpetual futures protocol Drift, in which the actor obtained private‑key access, manipulated approval controls, minted 750 million fake CarbonVote tokens, and drained roughly $285 million in assets before laundering the proceeds. This incident is linked to a broader pattern of North Korean‑linked DeFi thefts reported in mid‑2026, where AI‑enhanced social engineering and code generation contributed to a 500 percent rise in AI‑assisted scams and resulted in billions of dollars of cryptocurrency stolen from various protocols. These campaigns demonstrate the actor’s focus on exploiting trust assumptions, provenance gaps, and slow governance in blockchain ecosystems to fund state‑directed priorities.
Incidents
Attributed incidents are available to members.
2 incidents