
WaterPlum Used Fake Crypto Jobs to Breach 30,000 Devices

WaterPlum Used Fake Crypto Jobs to Breach 30,000 Devices
WEEX View
- The near-term issue for exchanges, wallet providers and employers is whether additional WaterPlum-linked addresses, malware indicators or compromised hiring channels are publicly identified. That would shape screening, account monitoring and incident response across the crypto stack.
- The case also puts renewed focus on developer-side security. The campaign targeted people likely to run code, test repositories or open project files, making recruitment workflows and technical interview materials a direct attack surface for crypto firms.
- Another point to watch is whether authorities disclose more detail on how stolen assets moved on-chain and where they touched centralized platforms. That could affect sanctions compliance, wallet risk controls and fund tracing efforts.
A joint advisory from authorities in Japan, the U.S., Australia and Germany said North Korean-linked cyber actor WaterPlum infected at least 30,000 devices in more than 100 countries from around December 2025 through July 2026, using fake job offers tied to AI, cryptocurrency and NFT companies to steal funds or credentials from more than 7,000 crypto wallets.
The advisory said WaterPlum approached job seekers on social media, recruitment sites and freelance platforms while posing as legitimate employers. Victims were lured into downloading malicious files presented as coding tests, interview assignments or development projects. The primary targets were web designers, engineers and specialists working in cryptocurrency, blockchain and Web3.
Authorities said the operation infected at least 30,000 PCs across more than 100 countries, including Japan and the United States. The actors exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets and transferred at least 1.7 billion Japanese yen, or about $10.71 million, in crypto assets on behalf of North Korea.
The same advisory assessed that WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers' Party of Korea. Investigators also linked the campaign to the activity commonly referred to as “Contagious Interview,” a social-engineering pattern in which attackers impersonate recruiters and push malware through supposed hiring processes.
Authorities and security researchers have previously described similar operations aimed at Web3 developers, including campaigns that used fake recruiting outreach, malicious code repositories and infected technical tests. In WaterPlum’s case, the reported scale suggests a broad theft pipeline rather than a small number of highly targeted intrusions.
Why It Matters
The case highlights how crypto theft is increasingly tied to attacks on people who sit close to code, wallets and infrastructure rather than only on exchanges or protocols themselves. Hiring channels, freelance marketplaces and developer collaboration tools are becoming part of the threat surface for digital asset firms.
It also underscores the compliance dimension of DPRK-linked crypto crime. Once stolen funds move through wallets, bridges or centralized venues, exchanges and service providers may face greater pressure to strengthen address screening, transaction monitoring and internal controls around sanctioned or high-risk counterparties.
Milestones
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreMultiversX Says Mainnet Was Exploited and Network Has Been Paused
MultiversX said its mainnet was hacked through a virtual machine atomicity issue that caused invalid state changes, prompting a network pause while the team tests a fix and prepares a recovery plan with validators and exchanges.
Coinbase Taps Stablecore to Extend Crypto Tools to US Banks
Coinbase has partnered with Stablecore to make crypto trading, custody and stablecoin payment services available through banking technology used by more than 3,000 U.S. banks and credit unions, though adoption will depend on each institution activating the services.
US Treasury Sanctions Iran-Linked Crypto Exchange BitBank
The U.S. Treasury sanctioned Iranian digital asset exchange BitBank, its software developer, and three associates tied to Babak Zanjani, alleging the platform helped move hundreds of millions of dollars in Bitcoin to the IRGC.
NYSE Explores Avalanche for Tokenized Securities Infrastructure
NYSE has been testing Avalanche technology for possible use in tokenized securities infrastructure, according to remarks at Avalanche Summit, as the exchange group weighs technical and economic fit for a broader tokenized stocks and ETFs push.