← Radar

Incident case file

Sign in to watch

Zerion — DPRK UNC1069 AI-Enabled Social Engineering Attack

Incident date April 11, 2026

0 views

ResolvedMulti-chain EVMPhishingCluster: DPRK-UNC1069-ZERION-2026-04

Estimated loss

$100K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

80%

Facts and investigation

Attacker: DPRK UNC1069 group (TraderTraitor cluster); wallet addresses TODO

Funds moved to: TODO
Clustered with SEAL-blocked UNC1069 infrastructure (164 malicious domains)

Timeline: Pre-April 11: DPRK actor UNC1069 runs AI-enhanced social engineering targeting Zerion staff via Telegram/LinkedIn/Slack, compromising a team-member device, sessions, credentials, and private keys to internal hot wallets. April 10, 21:17 GMT: Zerion engineering detects abnormal activity on app.zerion.io; full proactive shutdown by 23:38 GMT. April 11: Web app remains offline; Blockaid blocks the domain. April 11-13: Investigation; iOS/Android/browser extension confirmed safe. Web app restored after ~48h. April 14: Zerion publishes post-mortem confirming ~$100K from internal hot wallets stolen. April 15: Final disclosure; attribution to DPRK UNC1069 stated by Zerion and SEAL.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)