ZachXBT discloses internal payment server data from North Korean IT workers, involving a $3.5 million flow of funds

TRX-0,13%

Gate News update. On April 8, on-chain investigator ZachXBT revealed that an anonymous source shared data stolen from internal North Korean payment servers, covering 390 accounts, chat logs, and information on cryptocurrency transactions. From the end of November 2025 to the present, the related payment wallet addresses have received more than $3.5 million in total. The funds were routed out via a certain CEX or exchanged through platforms such as Payoneer into fiat currency, which was then deposited into bank accounts in China. On-chain tracking shows that the internal payment addresses are linked to a known North Korean IT worker cluster, and one Tron payment address was frozen by Tether in December 2025. Among the user list, three associated companies have been sanctioned by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), including Sobaeksu. ZachXBT has compiled a complete organizational structure chart, with data scope covering from December 2025 to February 2026.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Tether-linked Super PAC’s first $300,000 spending went to a company co-founded by the CEO, allegedly involving pay-to-play and favoritism.

A super political action committee affiliated with Tether filed paperwork with the U.S. Federal Election Commission showing that its first $300k expenditure went to Nxum Group, founded by Tether U.S. CEO Bo Hines, to buy campaign ads for Georgia Republican candidate Clay Fuller, raising questions about pay-to-play.

GateNews21h ago

Tether Launches Open-Source Local AI SDK

Paolo Ardoino, CEO of Tether, criticizes centralized AI and champions decentralization through the QVAC SDK, allowing local AI model deployment. This shift enhances data privacy and user control, positioning Tether at the convergence of blockchain and AI, challenging dominant tech firms.

Coinfomania04-11 06:05

Tether CEO:USDT 在 Hyperliquid 上占 HIP-3 交易量 7.8%

Gate News message, on April 10, Tether CEO Paolo Ardoino posted that USDT’s adoption on Hyperliquid is rapidly increasing. Data shows that in less than three months, USDT has grown from having almost no share on Hyperliquid to accounting for the rest.

GateNews04-10 14:09

Tether launches open-source AI toolkit QVAC SDK, positioning it as a general-purpose artificial intelligence foundation module

Tether’s QVAC team launched the QVAC SDK, which is an open-source, cross-platform AI development toolkit aimed at building the intelligent ecosystem of the future and supporting a wide range of devices. QVAC is seen as a next-generation intelligent framework with modular and infinitely extensible features to adapt to future development.

GateNews04-09 12:11
Comment
0/400
No comments