FBI Says WaterPlum Hackers Drained $10.71M From Bitcoin (BTC) and Crypto Wallets

NPA and FBI say North Korea-linked WaterPlum hackers infected 30,000+ devices, hit 7,000+ wallets and drained $10.71M in crypto via fake job offers.

(05:07 PM UTC)
4 min read
AI SummaryAI
  • The group infected over 30,000 computers across more than 100 countries.
  • Data was stolen from more than 7,000 crypto wallets per the joint advisory.
  • Japan dismantled its first known laptop farm run by remote North Korean workers.
  • A suspected North Korean operative applied to bitFlyer in May 2025 with a stolen resume.
j5wc1pnr

30,000 Devices, 7,000 Wallets Compromised

A North Korea-linked hacking crew tracked as WaterPlum drained at least $10.71 million in digital assets from crypto users, according to a joint advisory issued Friday by Japan’s National Police Agency (NPA) and the US Federal Bureau of Investigation. The agencies report that WaterPlum — also tracked under the name Contagious Interview — infected more than 30,000 computers across 100-plus countries and exfiltrated data from more than 7,000 crypto wallets, with the wallet cluster receiving the funds between December 2025 and July 2026. The advisory describes a recruitment scam aimed squarely at software builders. Operatives pose as headhunters for artificial-intelligence, crypto and altcoin startups, contacting targets on social media, job boards and freelance marketplaces. Candidates are pushed into a technical interview or coding test and told to download files from code-sharing sites — the excuse being a broken video call or the assignment itself. Those files carry an infostealer that quietly harvests browser passwords, screenshots and keystrokes, and critically extracts the secret keys that control a crypto wallet, the software people use to hold digital money.

Japanese and US authorities say North Korea-linked hackers hit 30,000+ devices and 7,000+ wallets

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the joint advisory states. The personas borrow the credibility of the AI boom — a sector where high-profile token ventures such as Worldcoin (WLD) have made constant developer outreach a normal part of hiring. An earlier investigation, in which a researcher spent 22 months inside the group’s servers and mapped 1,640 victims across 57 countries, put the footprint at a fraction of Friday’s official tally, which is roughly 18 times larger. While the advisory does not break the $10.71 million down by asset, funds siphoned in Bitcoin (BTC) and other liquid coins are typically laundered through mixers and cross-chain swaps before reaching final destinations.

Tokyo’s First Laptop Farm Takedown

The dismantling of Japan’s first known laptop farm gives the advisory an operational edge. Investigators say local confidants kept laptops in their own homes while North Korean IT workers abroad controlled the machines remotely, posing as Japanese residents to win freelance contracts. Those workers moved several hundred million yen worth of crypto overseas, and the same internet addresses tied the farm to WaterPlum’s infrastructure. The NPA and FBI assess that WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, subordinate to the Workers’ Party of Korea’s Central Committee — placing the campaign inside the state’s sanctioned revenue apparatus. Analysts have long tied Pyongyang’s crypto theft and proof-of-work mining activity to weapons funding; Friday’s advisory formalizes that chain of command.

The staffing fraud reaches into Japan’s exchange sector. In May 2025, a suspected North Korean operative applied for an engineering role at bitFlyer, a venue covered in our guide to the best crypto exchanges, using a stolen resume. Interviewers flagged several tells: he refused to relocate, demanded payment in crypto and appeared to read answers off a second screen. He was not hired. Earlier campaigns leaned on deepfake recruitment calls to reach senior staff, and the same social-engineering playbook surfaces in retail-facing lures — from passive-income pitches to the mobile-mining narrative that drew users to Pi Network. Investigators now tell engineering teams to run recruiter-submitted code inside a sandbox, a sealed test environment walled off from production files and wallet software. Readers tracking the market in real time can follow live spot and futures prices on Binance.

Endpoint Compromise, Not Protocol Flaws

Read together, the advisory and the laptop-farm takedown describe one machine: a state-run pipeline that converts fake job offers into wallet keys, and wallet keys into hard currency for a sanctioned regime. COINOTAG’s reading of the filing is that the root cause is not a protocol flaw but endpoint compromise — infostealers extracting private keys from developer machines — and the remediation is procedural: sandbox every recruiter artifact, isolate signing keys from daily-use systems, and treat unsolicited hiring tests as hostile code. With $10.71 million confirmed drained and more than 7,000 wallets exposed, the developer community’s threat model must now assume the recruiter is the attack.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.