North Korea's WaterPlum Stole 7,000 Bitcoin (BTC) Wallet Records, Japan and FBI Say
Japan's NPA and FBI say North Korea-linked WaterPlum infected 30,000+ devices, stole 7,000 crypto wallet records and moved about $10.7 million.
AI SummaryAI
- WaterPlum infected over 30,000 devices across 100-plus countries between December 2025 and July 2026.
- The Japanese police report says WaterPlum stole data from more than 7,000 crypto wallet records.
- WaterPlum-controlled wallets received at least 1.7 billion yen, roughly $10.7 million.
- Japan dismantled its first domestic laptop farm supporting North Korean IT workers.
Japan Unravels WaterPlum's 7,000-Wallet Theft
Japan's National Police Agency said on Sept. 18 that a joint probe with the National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center and agencies in Australia and Germany has mapped the full toolkit of WaterPlum, a North Korea-linked cluster also tracked as Contagious Interview. The official NPA report states that between roughly December 2025 and July 2026 the group infected more than 30,000 computers across over 100 countries and regions and stripped data from more than 7,000 cryptocurrency wallet records, with private keys and seed phrases prime targets. Wallets controlled by WaterPlum received at least 1.7 billion yen, about $10.7 million at the rate Japanese authorities used. Japanese and U.S. investigators assessed the operation, alongside some North Korean IT worker schemes, sits under Bureau 313 of the Workers' Party of Korea's Munitions Industry Department. Attackers posed as crypto, AI and NFT recruiters, planting malware including BeaverTail, InvisibleFerret and OtterCookie inside malicious NPM packages.
First Domestic Laptop Farm Dismantled
The same investigation dismantled Japan's first known domestic laptop farm linked to North Korean IT workers. A local facilitator kept machines at a residence while workers abroad controlled them remotely, impersonating Japanese residents with supplied identity documents; payments routed through facilitator bank accounts, and workers tied to the probe sent crypto worth hundreds of millions of yen overseas. Separately, a suspected North Korean applicant sought an engineering role at exchange bitFlyer in May 2025, applying under another person's identity with a Gmail contact masked behind NETNUT Proxy, Astrill VPN and High Speed Rabbit Proxy. The candidate claimed to be Malaysian and living in Finland, resisted relocating to Japan and insisted on salary in cryptocurrency; investigators cited contradictory answers, background voices and repeated checks of a second monitor, and bitFlyer declined to hire with no damage reported. Crucially, the NPA found the applicant's IP addresses matched infrastructure used in WaterPlum attacks, and security researchers have separately documented North Korean-linked developers embedded in more than 40 DeFi projects over seven years.
OFAC Sanctions Iran's BitBank
Washington moved against a separate state-linked crypto channel as the Japanese disclosure landed. The Treasury Department's Office of Foreign Assets Control sanctioned Iranian digital asset platform BitBank, its developer Pishtaz Simorgh Electronic Trade Company and three associated individuals. Treasury assesses BitBank is controlled by Babak Zanjani, the already-sanctioned Iranian financier, as part of a sanctions-evasion network: between June and July 2026, Zanjani moved several hundred million dollars in Bitcoin through BitBank to the Islamic Revolutionary Guard Corps, and the sanctioned Hormuz Safe Marine Services Authority also used the platform to move funds. Under the designation, all U.S.-connected assets of the listed parties are frozen, and any entity owned 50% or more, directly or indirectly, by sanctioned persons is blocked as well.
Hyperliquid Opens Manual Lending
On the infrastructure side, Hyperliquid launched a manual lending function that lets users post HYPE and Bitcoin (BTC) as collateral to borrow USDC and USDT. Borrowers pay interest on drawn assets, suppliers of quote assets earn interest, and rates are set by capital utilization. The feature shares HyperCore infrastructure with the platform's portfolio margin system, and borrowed asset volume had already reached $269 million on launch day. Co-founder Jeff Yan framed the rollout as deliberately modular: a standalone lending protocol built on HyperCore first, then integrated with perpetuals, spot and trading outcomes through portfolio margin, so lending risk can be managed independently while idle stablecoin collateral generates yield and system-wide risk stays easier to analyze. Readers tracking the market in real time can follow live spot and futures prices on Bitget.
Pyongyang's Multifront Playbook
The four developments trace one arc: as digital assets become core financial rails, nation-state operators and regulators are now working inside those same rails, and the week's disclosures show theft, sanctions evasion and hiring infiltration treated as one coordinated threat picture. COINOTAG's reading of the joint advisory is practical: run untrusted code only inside sandboxes or virtual environments, deploy endpoint detection and response tooling, open unknown VSCode projects in restricted mode to block tasks.json auto-execution, and keep seed phrases stored offline. With Bitcoin (BTC) trading near $80,810 as of this writing and holding within our composite support and resistance levels, the open question is whether repeated state-actor disclosures cool institutional risk appetite or reinforce the case for hardened, regulated infrastructure.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


