How did North Koreas WaterPlum steal crypto worth $10.7M with fake job interviews?

摘要:North Korea‘s threat to the crypto industry is getting bigger by the day. According to a report by Japan’s National Police Agency (NPA) and the U.S

North Korea‘s threat to the crypto industry is getting bigger by the day. According to a report by Japan’s National Police Agency (NPA) and the U.S Federal Bureau of Investigation (FBI), North Korean state-backed group WaterPlum stole $10.7M through fake headhunting.

WaterPlum reportedly posed as hiring managers for crypto firms, NFT businesses, and artificial intelligence companies and reached out to IT and software developers.

However, through a fake skill test, the victims were duped into downloading malicious programs that drained their wallets. Separately, the group also posed as employees and bagged lucrative offers with crypto firms only to gain access to their systems and compromise them.

According to the report, the group infiltrated 30K devices across over 100 countries, affecting over 7000 crypto wallets. And, it did this over an eight-month period from December 2025 to July 2026.

North Koreas evolving crypto heist strategy

For perspective, WaterPlum is just one of the threat actors backed by North Korea, tracked by most security firms. And, it appears WaterPlum is purely designed for wide-scale fake recruitment schemes to deliver malware and steal victims crypto assets.

However, some of the recent high-value exploits have also been done by state-backed actors from North Korea. For example, TRM Labs linked the $285M Drift protocol hack to AppleJesus, also known as Citrine Sleet or UNC4736. This involved a daring 6-month face-to-face social engineering plan and $1M of their committed capital to compromise the core protocols contributors.

Perhaps one of the most lethal and high-value operators is the Lazarus Group, which is also backed by the state. It was behind the historic $1.5B Bybit exchange heist and KelpDAOs $292M exploit.

Overall, these threat actors seem to be so sophisticated and organized, with each group with different targets and ways of compromising them. Interestingly, all the stolen crypto funds have become a crucial state revenue stream for North Korea, according to Certik.

In 2025, North Korean threat actors accounted for 60% or $2B of the $3.4B annual crypto losses, as per Certik. In fact, another security research firm, TRM Labs, estimated that the country drove 64% of overall crypto exploits last year.

Source: TRM Labs

As of H2 2026, North Korea-based hackers have accounted for 76% of total crypto losses, worth over $600M. Theyve marked a steady dominance and been a risk to the industry since 2020.

Final Summary

  • Japan, the United States, and other countries reported that over $10M have been lost to fake job interviews by WaterPlum.
  • North Korea now accounts for over 75% of stolen crypto funds in 2026.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

伊朗利用加密货币资助IRGC受限 美国财政部再制裁加密交易所

下一篇

WikiBit交易所跑路風險榜第31期CoinW:詐騙洗錢23億、扣下52萬美元賬戶、被韓國和土耳其封殺