How a Fake Security Researcher Persona Traced Back to North Korea's Lazarus Group
For more than a year, an account operating under the name Nick Franklin (0xNickLFranklin) built a reputation in the crypto security community as a sharp, fast-moving exploit analyst. The account produced detailed breakdowns of major hacks, often with timing that other researchers found remarkable, and steadily earned the trust of the community it operated within.
That persona collapsed after 1inch co-founder Anton Bukev flagged a suspicious file sent to him under the pretense of a security report. The file was a malicious APP disguised as legitimate research. The exposure triggered a broader investigation that ultimately connected "Franklin" not to an independent researcher, but to a state-sponsored operation.

Investigators tied the persona to a wider network linked to North Korea, implicated in several intrusions — including the $50 million Radiant Capital breach — as well as the construction of fake DeFi protocols and infiltration of the crypto security community itself.
Credit: Anton Bukev, Daniel Von Fange, tanuki42, Ketman, Tayvano, Protos, pcaversaccio, HackMD
01Building the persona
According to researcher Daniel Von Fange, the Franklin account routinely appeared around the scene of fresh exploits. Researcher tanuki42 noted that the account was active across relevant Telegram groups, in addition to maintaining a Twitter presence and a GitHub profile.
Security researcher Tayvano observed that Franklin's Twitter output tracked closely with real-world Web3 exploits, frequently being among the first accounts to post analysis.
Franklin was cited in earlier Rekt News coverage of the Polter Finance, PrismaFi, and Lifi/Jumper incidents, in each case surfacing details early. In hindsight, researchers say this speed is better explained by insider knowledge of the exploits than by analytical skill.
02The exposure
On March 27, Bukev publicly flagged the APP file Franklin had sent him. Once questioned, the account deleted its message history and blocked Bukev. The behavior, combined with the file itself, pointed toward North Korea's Lazarus Group — an entity linked to some of the largest thefts in crypto history.
Researchers who reviewed the account's activity described a persona built methodically over time: thousands of messages, hundreds of interactions, and an extensive web of connections established well before the exposure.
03The Radiant Capital link
In October 2024, Radiant Capital lost $50 million in a multisig compromise. Following the Franklin exposure, investigator tanuki42 and Taylor Monahan reviewed Franklin's on-chain activity and found a match: an address Franklin had used to request Sepolia testnet ETH corresponded to an address catalogued in Monahan's Lazarus/BlueNoroff address repository — specifically, one used to test the attack technique later deployed against Radiant.
Weeks before the Radiant exploit, the Franklin account was active in Telegram discussing the protocol with unusual intensity — messages that, in retrospect, read as reconnaissance rather than commentary. Separately, the account was asking about Radiant roughly two months before the attack while using one of the addresses later tied to executing the exploit.
Franklin's post-hack commentary reportedly mixed accurate technical detail with elements that appear designed to redirect attention away from the operation behind it. When Bukev confronted the account, Franklin's final message claimed that his "Telegram and personal site was compromised."
04A wider network
Radiant Capital was reportedly one piece of a larger operation. According to analysis published by Ketman researcher blackbigswan, Franklin was not operating alone but was part of a network running fake protocols, malware campaigns, and low-effort scams in parallel.
One example cited is Aqua Protocol, a fake lending platform that reportedly held around $800,000 in liquidity — described by researchers as a honeypot built by the same operators. After the Franklin exposure, Aqua Protocol's GitHub repository was deleted.
The Ketman analysis also identifies additional aliases tied to the network: "SonataM," attributed to front-end development, "CrazyDream000," described as reusing others' work under different names, and "Jewelas," described as a connecting figure across accounts. Researchers describe this as a single team maintaining multiple identities, engaged simultaneously in legitimate-looking security work, token scams, and job applications to crypto companies.

05Attribution
The file sent to Bukev is attributed to Lazarus Group's AppleJeus/Citrine Sleet operation, based on analysis by security researcher Pascal Caversaccio, who assessed the attribution to North Korean state actors as high-confidence.
Rather than deploying a novel technical exploit, the operation relied on social engineering — impersonating a trusted figure to gain direct access to targets. When challenged, the account reportedly declined to complete a simple test often used informally to identify North Korea-linked accounts: publicly criticizing Kim Jong-un. That request went unanswered.
06Takeaway
The Franklin persona operated for over a year before a single misstep — sending an executable file instead of a standard document — led to its unraveling. In that time, it built trust within the security research community, accessed sensitive information about upcoming or recent exploits, and reportedly played a role in preparing at least one major breach.
The case illustrates a gap distinct from smart contract vulnerabilities: the human layer of trust that security research depends on had, in this instance, no equivalent scrutiny applied to it.
Get new scam files the moment we publish them — usually 2–3 emails a week.