The flagship casework: exchange freezes, fund recoveries, and exploit attributions, documented in public from the first tip to the final outcome.
Tagged “DPRK”Clear tag
Analysis of a breach exposing an internal payment site used by DPRK-linked operators, offering a rare view into how sanctioned IT-worker earnings move.
A project unknowingly hired DPRK IT workers who exploited it for $1.3M; rapid tracing recovered $1M and exposed the hiring network behind it.
Investigation connecting 25+ exploits totaling over $200M to the Lazarus Group through shared laundering infrastructure; $7M recovered.
The Munchables protocol was exploited for $62M by an embedded DPRK IT worker; within a day, pressure and negotiation produced a full return of funds.