The cryptocurrency community is reeling after THORChain co-founder JP lost $1.35 million from a personal wallet on September 9, 2025, falling victim to a sophisticated phishing attack linked to North Korean operatives. The incident, first reported by blockchain investigator ZachXBT on September 12, exposes the growing threat of state-sponsored cybercrime targeting even the most experienced figures in decentralized finance.
The attack began when a compromised Telegram account sent JP a convincing message designed to appear as a legitimate business inquiry. The threat actor, believed to be affiliated with North Korean hacking groups that have increasingly targeted the crypto sector throughout 2025, employed deepfake technology to enhance the credibility of their social engineering approach. JP, who had recently retrieved an old MetaMask wallet containing the funds, authorized a transaction that drained the entire balance within minutes.
The Exploit Mechanics
The attack vector represents a significant evolution in cryptocurrency-targeted social engineering. Rather than deploying malicious smart contracts or exploiting protocol vulnerabilities, the attackers focused entirely on human manipulation. They first gained access to a trusted contact’s Telegram account, then used that compromised identity to approach JP with what appeared to be a routine DeFi discussion. The deepfake elements made the interaction feel authentic, as the attacker could reference real conversations and shared contexts.
Once JP engaged, the attacker directed him to connect his wallet to a fraudulent interface. The malicious site, hosted on a domain designed to closely mimic a legitimate DeFi platform, prompted a wallet signature request. What appeared to be a standard token approval was actually a transaction granting the attacker full spending access to JP’s wallet. The $1.35 million in various cryptocurrencies was transferred out in a matter of minutes, moving through a series of intermediary wallets designed to obscure the trail.
Affected Systems
The primary system affected was JP’s personal MetaMask wallet, which contained a mix of ETH and ERC-20 tokens. While THORChain’s protocol itself was not compromised, the incident highlights how individual wallet security remains the weakest link in the decentralized finance ecosystem. The attack leveraged off-chain communication channels, specifically Telegram, which has become the primary target for crypto-focused phishing campaigns in 2025.
North Korean hacking groups, including the notorious Lazarus Group, have been linked to over $1.5 billion in cryptocurrency thefts in 2025 alone. Their tactics have shifted from exchange breaches toward targeted phishing of high-net-worth individuals and project founders. The use of deepfake technology represents a troubling escalation, as it allows attackers to impersonate known contacts with a high degree of accuracy.
The Mitigation Strategy
Security researchers recommend several immediate measures for high-value wallet holders. Hardware wallets should be the default for storing significant amounts of cryptocurrency, as they require physical confirmation of transactions and are immune to the type of blind signing that led to JP’s loss. Multi-signature wallets add an additional layer of protection by requiring multiple approvals before funds can move.
For DeFi founders and public figures, limiting the amount of cryptocurrency held in hot wallets connected to messaging platforms is essential. Establishing verified communication protocols, such as confirming transaction requests through a secondary channel before signing, can prevent even the most convincing phishing attempts from succeeding.
Lessons Learned
The THORChain incident serves as a stark reminder that technical expertise does not confer immunity to social engineering attacks. JP, as a co-founder of one of the most technically sophisticated cross-chain protocols in the space, was targeted precisely because his public profile made him identifiable as a high-value target. The attack’s success demonstrates that the human element remains the most exploitable vulnerability in cryptocurrency security.
The speed at which the funds were moved underscores the irreversible nature of blockchain transactions. Unlike traditional banking, where fraudulent transfers can sometimes be reversed, cryptocurrency transactions are final once confirmed. This makes prevention, rather than recovery, the only viable strategy.
User Action Required
All cryptocurrency users should take this incident as a catalyst to review their security practices. Migrate funds from hot wallets to hardware wallets, enable all available security features on messaging accounts, and never sign transactions prompted through unsolicited messages. Project founders should consider employing dedicated security personnel to manage communication verification protocols. As North Korean hacking groups continue to refine their tactics, the crypto community must match that sophistication with equally advanced defensive measures.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making security decisions.
ZachXBT catching another one. The on-chain tracking community is doing more for crypto security than most institutional compliance teams.
on-chain investigators doing more for security than most institutional compliance teams says everything about where the industry is at
chain forensics investigators do more than compliance teams because they actually follow the money. compliance just fills out forms
Co-founder of a major DeFi protocol getting phished for $1.35M via a fake Telegram message. If it can happen to them, it can happen to anyone.
old MetaMask wallet retrieved and drained within minutes. the lesson is clear: if you recover an old wallet, move everything to a fresh address immediately
north_korea_ the old MetaMask wallet detail is what kills me. retrieved it, probably felt lucky finding old funds, then immediately got social engineered. brutal sequence
metamask_ghost recovering an old wallet and immediately signing a tx from a stranger. the deepfake made it look legit but the opsec was zero
north_korea_ first rule of recovering an old wallet: sweep to a fresh address before touching anything. JP imported his seed and immediately signed a tx from a stranger. heartbreaking sequence
Lars Henriksen its worse than that. a DeFi founder should know better than to sign transactions from a random Telegram message. deepfake or not, signing blindly is the real failure
Lars Henriksen a DeFi co-founder should be the last person signing blind from a Telegram ping. if JP used a hardware wallet for anything above lunch money the deepfake wouldnt have mattered
Deepfake + compromised Telegram + fraudulent DeFi interface. Three layers of social engineering. These arent script kiddies anymore, this is state-sponsored tradecraft.
wallet forensics nailed it. three layers: deepfake + compromised Telegram + fake DeFi UI. NK groups are running full spectrum social engineering operations now
deepfake video plus compromised telegram plus fake defi UI. three layers of social engineering and the target was a protocol founder
ZachXBT is doing more for crypto security than the FBI at this point. tracks stolen funds on chain and publicly names the thieves for free
onchain_bounty zachxbt out here doing forensic work for free while the FBI files paperwork. give the man a government contract already
onchain_bounty zachxbt working for free and outpacing every three letter agency on earth. the guy deserves a medal and a salary
a defi co-founder signing blind from a telegram message. if JP can get caught anyone can. hardware wallet for everything above grocery money
Dejan P. right. a defi cofounder signing blind from a telegram ping. hardware wallet for anything above lunch money, no exceptions
retrieving an old MetaMask wallet and signing within minutes is the part nobody talks about. first rule of recovering old wallets is sweep to a fresh address BEFORE touching anything
opsec_failure_ exactly. the moment you import an old seed the only tx should be a full sweep to a newly generated address. anything else is asking to get drained
opsec_failure_ the deepfake angle gets headlines but the real failure was importing a seed into a hot wallet connected to the internet. hardware wallet makes the deepfake irrelevant
recovering an old MetaMask wallet and signing a tx within minutes. first rule of old seed recovery is sweep to fresh hardware wallet before breathing
a DeFi co-founder getting phished via Telegram should be a wake up call for everyone. no amount of crypto knowledge protects you from social engineering
Ingrid B. exactly. JP built THORChain and still got caught. experience doesnt save you from a well crafted social engineering attack
deepfake video on top of a compromised Telegram account. the attack surface keeps growing and hardware wallets only help if you actually use them