A Chinese advanced persistent threat group, known for its sophisticated hacking operations, has been linked to a lucrative cryptocurrency fraud scheme. Researchers from Broadcom have uncovered evidence suggesting that this group, dubbed 'Jewelbug', may be involved in hack-for-hire operations, expanding its scope beyond traditional espionage activities. The discovery has significant implications, as it blurs the lines between state-aligned and criminal activities, potentially indicating a shift in the threat model. This development is particularly noteworthy, as it may signal a change in the way threat actors operate, with geopolitical motivations potentially driving their actions1. The involvement of a Chinese APT group in crypto fraud operations raises concerns about the group's capabilities and intentions, highlighting the need for a more nuanced understanding of the threat landscape. This new information matters to practitioners, as it requires a different approach to threat mitigation, one that takes into account the complexities of state-aligned activity.