Ripple says it is now sharing DPRK-related threat intelligence with other crypto companies through Crypto ISAC, marking a more formal attempt to turn scattered security findings into a shared industry defense layer.

What Ripple is contributing

According to Crypto ISAC's May 5 post, Ripple is feeding the group's new API with domains, wallets, indicators of compromise, and enriched profiles tied to active North Korean campaigns. The post says those profiles can include details such as LinkedIn accounts, email addresses, phone numbers, locations, and other signals that help security teams connect one suspicious applicant or contractor to a broader operation.

Ripple's own X post framed the move in similar terms, arguing that a threat actor rejected by one company can quickly reappear at several others if firms are not sharing intelligence.

Why this matters

The announcement follows a run of crypto breaches that have been publicly linked to North Korean operators, including campaigns built around long-running social engineering rather than a simple smart contract bug. Crypto ISAC explicitly points to the recent Drift incident as an example of attackers spending months building trust before compromising devices and multisig access.

The conservative takeaway is not that shared feeds will stop these campaigns on their own. It is that parts of the industry are starting to treat hiring pipelines, contractor screening, and cross-company intelligence sharing as core security infrastructure instead of side-channel coordination.