North Korean developers hijacked dormant Waves repositories, embedding code to steal credentials in wallet updates.
PANews reported on June 19 that according to Cryptoslate, a North Korean developer was granted advanced access to the Keeper-Wallet codebase of Waves Protocol. The account "AhegaoXXX", which has been pushing updates to the dormant codebase since May 2025, has been linked to North Korean IT outsourcing organizations. The code review found that one commit added the ability to send wallet logs and runtime errors to an external database, potentially stealing the mnemonic phrase and private key. Although the branch was not merged, the attackers took control of former Waves engineer Maxim