Fake Crypto Recruiters Infected 30,000 Devices and Reached 7,000 Wallets
• September 20, 2026 11:19 pm • CommentsThe most dangerous part of this crypto theft campaign was not a clever wallet exploit. It was a job interview.
A joint international advisory says North Korea’s WaterPlum operation posed as legitimate employers, recruiters and technology companies to persuade developers to run malicious code. By the time investigators measured the damage, the campaign had infected at least 30,000 devices in more than 100 countries and reached more than 7,000 cryptocurrency wallets.
The reported theft totaled roughly 1.7 billion Japanese yen, equivalent to $10.71 million.
The numbers are serious. The method is worse, because it turns ordinary hiring steps—technical assignments, code repositories and video-call troubleshooting—into the initial attack surface.
The joint FBI and allied-agency advisory says WaterPlum actors approached software developers and other IT professionals through social media, job sites, gig platforms and freelance marketplaces. The attackers impersonated artificial-intelligence, cryptocurrency and NFT companies, then directed applicants to download files or run code during an interview.
That code could include malicious Node Package Manager packages carrying malware families such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Once inside a device, the operators used remote-access tools and information stealers to preserve access, harvest credentials and move sensitive data to command-and-control systems.
For crypto users, that means a hardware wallet is not a complete defense if the computer around it has already surrendered a seed phrase, private key, browser credential or malicious transaction approval.
INTEL: North Korea-linked hackers infected 30,000+ devices across 100+ countries, compromised data from 7,000+ crypto wallets and received at least $10.7 million into wallets they controlled, Japanese and U.S. authorities say pic.twitter.com/cnfsYvwBgp
— Solid Intel 📡 (@solidintel_x) September 18, 2026
The campaign did not stop at stealing from the first victim. The advisory warns that compromised developers can become a route into the companies that later employ them, opening the door to espionage, intellectual-property theft, extortion and lateral movement through corporate systems.
WaterPlum also collected identity documents that could be reused by North Korean IT workers seeking contracts under false identities. Investigators tied the cyber campaign to a broader system of remote workers and “laptop farms” designed to disguise where operators were actually located.
The Record reports that Japanese authorities dismantled one such laptop farm and found evidence that several hundred million yen had been sent outside the country. It also notes that the attackers targeted web designers, engineers and crypto specialists—the exact people most likely to treat a coding exercise as a normal part of getting hired.
That is what makes the lure effective. A developer expects to clone a repository, install dependencies, open a project in Visual Studio Code or troubleshoot a conferencing tool.
WaterPlum turned those habits against the target.
The government advisory says malicious projects used blockchain themes as decoys and could trigger code through trusted Visual Studio Code configurations. It urges developers to open unknown projects in Restricted Mode, inspect task files, use a sandbox or virtual machine for untrusted code, and avoid running obfuscated commands they do not fully understand.
WaterPlum hit 30,000+ devices and 7,000+ crypto wallets via fake interviews, agencies say. Hardware wallets can't rescue stolen seed phrases or poisoned approvals. Treat hiring tests as hostile code: use a keyless sandbox. #Crypto #Cybersecurity #Malware #InfoSec #Web3 pic.twitter.com/rNLQqK16bx
— herald.eth (@herald_eth) September 18, 2026
If a device may already be compromised, investigators recommend disconnecting it from the internet, moving crypto assets to a newly created wallet on a separate clean device, storing the new seed phrase offline and considering a full operating-system reset. Companies are urged to limit credentials and source-code access, deploy endpoint monitoring and revoke sessions quickly when a contractor appears suspicious.
The practical lesson is blunt: a recruiting message can now carry the same risk as an unsolicited wallet link.
Crypto developers should verify the company and recruiter through an independent channel, inspect every repository before execution and keep hiring tests away from machines that hold wallet keys or production credentials. The interview may look routine. The code is not entitled to trust.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
