WaterPlum Hackers Target 7,000 Crypto Wallets in $10.7M Theft
The campaign infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026.

The North Korean-linked hacking group WaterPlum reportedly obtained funds or credentials from more than 7,000 crypto wallets and moved about $10.7 million to North Korea, highlighting the financial reach of fake recruitment attacks against crypto workers.
The campaign infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026. WaterPlum posed as AI, crypto and NFT companies and contacted developers through social media, recruitment websites and freelance platforms.
Attackers used technical interviews and programming assignments to persuade targets to download files containing malware. The targets included web designers, engineers and workers in the crypto, blockchain and Web3 sectors.
Japanese law enforcement also uncovered a laptop farm linked to the operation, with crypto assets worth hundreds of millions of yen transferred overseas. Investigators connected WaterPlum and some North Korean remote IT workers to the country’s General Bureau 313, which is associated with the defense industry.


