Kraken thwarts hacker’s ill-intentioned job application

Kraken’s chief security officer Nick Percoco said the exchange turned the tables on a North Korean hacker

article-image

Kraken and DC Studio/Shutterstock and Adobe modified by Blockworks

share

This is a segment from the Empire newsletter. To read full editions, subscribe.


Picture the iconic Spider-Man meme with the various Spider-Men pointing at each other.

Got it in your head?

Kraken said yesterday that it turned the tables on a North Korean hacker who was trying to get a job at the exchange.

I spoke to Kraken’s chief security officer, Nick Percoco, who gave me some details that are, honestly, just perfect for a Friday edition.

Percoco told me Kraken had received a list of email addresses tied to hackers. They, as one would expect, checked to see if any of those addresses would pop up around Kraken. One did. The person had applied for a job and was in a pool of candidates.

Basically, he explained, the person’s resume wasn’t standout enough for the hiring team to otherwise pay attention. But the team decided to see what would happen if they proceeded with the hacker.

According to Percoco, given some red flags, the person wouldn’t have gotten very far in the job application process. For example, when the person joined a Zoom call, it was under a different name (not the name he’d used on the application), and then he quickly changed it.

When Percoco virtually sat down with the individual for one of the cultural interviews, things got interesting. It was Halloween, so naturally, Percoco asked the individual what he was doing for Halloween. After an extensive conversation, he claims it was pretty clear the person didn’t understand the holiday.

Then, when asked to pull out his phone and show his Google map location (to verify that he was in Houston, Texas), the individual struggled with that, too, Kraken said. It took him a few minutes of pretty obvious scrolling to find Texas on his Google Maps, per Percoco.

While this story is amusing now, it pulls back the curtain on a bigger problem in crypto. These bad actors are actively trying to infiltrate US crypto companies.

Percoco warned that companies have to be more careful about who they’re hiring and how they verify them. In Kraken’s case, the individual had enough missteps that he wouldn’t have made it through the normal process. But hiring someone directly through Discord, for example, could leave a project at risk.

His advice for screening a candidate that’s raising some red flags is to have them go to a place like a local Starbucks or McDonald’s and order something. That way — on a Zoom or virtual call — you can see where they are and it gives the interviewer insight into the location. For example, a McDonald’s in Germany would have German on the packaging instead of English, he said.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates.png

Research

Maple Finance has successfully navigated significant market challenges through its strategic pivot to secured lending (Maple v2) and the launch of its Syrup product. Syrup has become a primary growth driver, delivering sustainable, outperforming stablecoin yields and rapidly increasing TVL. The upcoming custody-first Bitcoin staking product (istBTC) presents another significant avenue for expansion. Crucially, Maple has achieved operational profitability, a key inflection point that, combined with a fully vested token and active buyback mechanism, strengthens its investment case. While valuation metrics suggest potential undervaluation relative to peers and growth, the primary forward-looking risk identified is the long-term sustainability of its current high-take-rate collateral staking revenue model.

article-image

In 2014, Microsoft virus scanners were detecting viruses in Bitcoin software

article-image

Ledn’s Mauricio Di Bartolomeo explained how this cycle’s been different for the lender

article-image

The shorts looking for funding range from charming animated series to gritty live-action dramas

article-image

Money, it turns out, is emergent, like consciousness

article-image

Bridge flows churn in both directions as risk appetite returns