WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets
North Korean hackers posed as tech recruiters to compromise developers and siphon roughly $10.71 million in crypto assets over a seven-month campaign
A North Korean hacking operation known as WaterPlum compromised more than 30,000 devices worldwide and extracted data from over 7,000 cryptocurrency wallets, funneling at least 1.7 billion Japanese yen, roughly $10.71 million, into wallets tied to Pyongyang’s interests.
The campaign, which ran from December 2025 through July 2026, targeted a specific demographic: IT professionals and software developers. The attackers posed as recruiters offering jobs at companies in AI, cryptocurrency, and NFTs.
How the operation worked
WaterPlum, also tracked under the name Contagious Interview, exploited something every developer does: apply for jobs. The hackers created fake recruiter profiles on social media and employment platforms, then invited targets to participate in fraudulent job interviews or complete coding tasks that were laced with malware.
Once a victim engaged, a suite of custom malware did the heavy lifting. The toolbox included strains called BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The programs were designed to extract sensitive data, with a particular focus on crypto wallet credentials and private keys.
On September 18, 2026, a coalition of law enforcement agencies formally attributed the campaign to the 313th Bureau of North Korea’s Munitions Industry Department. That joint statement came from Japan’s National Police Agency and the US FBI, among others. The 313th Bureau is a known entity within North Korea’s weapons development infrastructure.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Part of a much bigger pattern
The country’s most notorious cyber unit, the Lazarus Group, was behind the $1.4 billion Bybit hack earlier in 2025, which remains the largest single crypto heist on record. Pyongyang-linked hackers have also been caught infiltrating companies by getting hired as remote IT workers, collecting paychecks while simultaneously exfiltrating sensitive data.
The WaterPlum campaign also utilized facilitated networks within Japan to expand its operational footprint, suggesting a level of on-the-ground coordination that goes beyond purely remote hacking.
What this means for the crypto industry
The breadth of the campaign, 30,000 infected devices across multiple countries, suggests that WaterPlum cast a wide net rather than targeting specific high-value individuals. In aggregate, thousands of smaller wallets added up to an eight-figure haul.
The formal attribution by the FBI and Japanese authorities also carries diplomatic weight. Joint public attributions are relatively rare and typically signal that law enforcement agencies have high confidence in their findings.