Incident case file
Sign in to watchZerion — DPRK UNC1069 AI-Enabled Social Engineering Attack
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: DPRK UNC1069 group (TraderTraitor cluster); wallet addresses TODO
Timeline: Pre-April 11: DPRK actor UNC1069 runs AI-enhanced social engineering targeting Zerion staff via Telegram/LinkedIn/Slack, compromising a team-member device, sessions, credentials, and private keys to internal hot wallets. April 10, 21:17 GMT: Zerion engineering detects abnormal activity on app.zerion.io; full proactive shutdown by 23:38 GMT. April 11: Web app remains offline; Blockaid blocks the domain. April 11-13: Investigation; iOS/Android/browser extension confirmed safe. Web app restored after ~48h. April 14: Zerion publishes post-mortem confirming ~$100K from internal hot wallets stolen. April 15: Final disclosure; attribution to DPRK UNC1069 stated by Zerion and SEAL.
Sources and coverage
- Articlecryip.cohttps://cryip.co/north-korean-ai-hack-hits-zerion-100k-lost-in-social-engineering-attack/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/04/15/north-korean-hackers-target-zerion-in-ai-driven-attack-steal-100k/
- Articlefinancefeeds.comhttps://financefeeds.com/north-korean-hackers-behind-100k-zerion-exploit/
- Articlemexc.comhttps://www.mexc.com/news/1029424
- Articlex.comhttps://x.com/zerion/status/2044167535231414727
- Articlethehackernews.comhttps://thehackernews.com/2026/04/threatsday-bulletin-17-year-old-excel.html
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)