Ripple Shares North Korea Threat Intelligence with Crypto ISAC to Combat Identity Risk

Ripple Shares North Korea Threat Intelligence with Crypto ISAC to Combat Identity Risk

N
News Editor 01
2026-07-09 00:50:14
Ripple provides Crypto ISAC with high-confidence threat data on DPRK-linked fraudulent domains, wallets, and attack indicators, enabling member firms to vet candidates, contractors, and vendors via an integrated API.
RippleCrypto ISACNorth Korea threat intelligencecrypto securityidentity verification

On May 4, 2026, Ripple announced it would share North Korea-linked threat intelligence with the Crypto Information Sharing and Analysis Center (Crypto ISAC), a move that places hiring, vendor verification, and identity-related risk at the center of crypto security. Attackers are increasingly targeting human trust rather than software vulnerabilities, making shared intelligence a critical defensive layer.

Shared Intelligence: Domains, Wallets, and Indicators of Compromise

Under the program, Crypto ISAC members gain access to Ripple's high-confidence data on Democratic People's Republic of Korea (DPRK)-linked activities. The shared data includes fraudulent domains, cryptocurrency wallets, and indicators of compromise associated with active campaigns. What sets this intelligence apart is the added context: identity details and signals that connect suspected actors to broader operations. Security teams can use these enriched identity signals to assess job applicants, contractors, and external partners before granting access.

Ripple stated on X: “The strongest security strategy in crypto is shared. An actor who fails a background check at one company will apply to three others the same week. Without shared information, every company starts from zero.”

API Standardization and Mitigating Identity Risk

The upgraded Crypto ISAC API provides the infrastructure to distribute intelligence, normalizing both Web2 and Web3 indicators so members can integrate them into security operations. Ripple and Coinbase are among the first firms to use the API. The model is designed to go beyond static threat alerts by preserving context, confidence levels, and links between separate signals. This distinction matters when attackers do not begin with an obvious exploit.

For example, in the Drift incident, malicious actors spent months building trust with collaborators before deploying malware and accessing multi-signature wallets. Had shared intelligence been available, other projects might have detected the suspicious identity pattern of the actors earlier.

Industry Collaboration: From Optional to Gold Standard

Justine Bone, CEO of Crypto ISAC, commented: “For too long, information sharing was treated as optional. Today, it is the gold standard for security. Ripple’s move via Crypto ISAC is a definitive proof of concept, showing how to turn shared data into actionable defense that the entire industry can build upon.”

Ripple's contribution positions shared intelligence as a practical defensive layer for an industry facing coordinated infiltration attempts. As North Korean hackers continue to exploit social engineering and identity deception, industry-wide intelligence sharing is becoming a critical barrier for protecting digital assets.

This partnership marks a major step from siloed defense to collective immunity. More companies are expected to join the API network, further enhancing the resilience of the entire crypto ecosystem.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.