A post-incident report released by Zerion in April confirmed that a team member's device was breached by hackers linked to North Korea, using an AI-assisted social engineering attack similar to cases previously investigated by SEAL (Security Alliance, the crypto white-hat coalition backed by Paradigm). The intrusion led to a loss of approximately $100,000 from the company's hot wallet used for testing and internal purposes. Zerion stressed that all user funds were unaffected, as the wallet operates on a fully self-custodial model where no team member has access to user private keys or seed phrases.
What the Attacker Gained
The report detailed that the attacker gained access to the employee's device via social engineering, obtaining partially logged-in sessions, authentication credentials, and the private keys to the company's hot wallet. These three elements were sufficient to drain the internal test funds. The damage did not escalate further due to isolation design: builds for mobile apps and browser extensions are separated, preventing any malicious versions from being pushed to production even if deployment credentials were compromised. Zerion locked down the deployment infrastructure immediately upon discovering the credential theft. Additionally, backend APIs and internal services remain fully isolated, and the wallet's self-custody architecture means team members never hold user private keys.
Post-Incident Response
Zerion outlined six immediate countermeasures: locking deployment infrastructure to block malicious versions; switching the web app to maintenance mode to reduce attack surface, with restoration expected within 48 hours; rotating all affected credentials, private keys, and reconfiguring multi-signature accounts; scanning all team devices for similar malware and assessing credential rotation needs for critical access points; partnering with Blockaid, ZeroShadow, and ChainPatrol to identify, tag, and takedown attacker wallets and accounts—Blockaid independently flagged and blocked the app.zerion.io domain; and reporting the attacker's wallet address to law enforcement, with Zerion stating it has traced the stolen funds to specific addresses and alerted authorities.
Fourth DPRK AI Social Engineering Attack in April
Zerion attributed the incident to DPRK and classified it as an AI-assisted social engineering attack, making it the fourth such case in the crypto space in April. By date: on April 1, Drift Protocol lost $285 million, which TRM Labs and Drift linked to UNC4736, a North Korea-aligned group that reportedly used a six-month social engineering infiltration; on March 31, the Axios npm package supply chain was compromised by UNC1069, another DPRK-linked group that set up fake Slack workspaces and disguised Microsoft Teams update prompts to distribute remote access trojans; in March, Bitrefill was hacked, attributed to the Lazarus Group. A February 2026 report from Google Cloud noted that UNC1069 had already deployed AI lures, including customized LinkedIn messages and deepfake interview videos, specifically targeting the crypto industry. Zerion's report concluded with a warning: "Beware of AI-generated videos appearing in meeting contexts."

