Search the site
Press ESC to close
LIVE
Loading...
Updating...

WaterPlum Hackers Infiltrate 30,000 Devices in Global Crypto Theft

Pieter van Meer
Fact-checked
2 min read
387 words
Share

A sophisticated cyber-espionage campaign linked to North Korea has resulted in the compromise of over 30,000 devices and the theft of funds from more than 7,000 cryptocurrency wallets. According to a joint early warning issued by international law enforcement agencies, including the US Federal Bureau of Investigation (FBI) and the Japanese National Police Agency (NPA), the hacker group known as WaterPlum—also identified by the alias Contagious Interview—targeted IT professionals globally. The operation, which spanned from December 2025 to July 2026, focused on stealing digital assets and sensitive data through deceptive recruitment practices.

Tactics of the Contagious Interview Campaign

The attackers utilized highly targeted social engineering techniques to reach job seekers on professional recruitment platforms and social media. By posing as legitimate firms within the Artificial Intelligence (AI), NFT, and cryptocurrency sectors, the hackers lured developers with lucrative job offers. The infection vector typically involved technical interviews or coding assessments where candidates were pressured to download software tools.

  • Targeted Sectors: AI, non-fungible tokens, and blockchain development.
  • Method of Entry: Malicious coding tests and technical interview software.
  • Geographic Reach: Victims identified in over 100 countries and regions.

These malicious files allowed the attackers to gain remote access to the victims' systems, providing a gateway to extract private keys and seed phrases from digital wallets.

Financial Impact and Scale of the Breach

The scale of the operation highlights the growing threat of state-sponsored actors in the decentralized finance space. Investigations reveal that the hackers successfully exfiltrated approximately 7.71 million USD in various cryptocurrencies. These assets were traced to multiple addresses controlled by the group. The breach is particularly notable for its efficiency, impacting developers who are traditionally considered more tech-savvy and aware of cybersecurity risks.

The attackers contacted job seekers on social media and recruitment platforms, using technical interviews or coding tests as pretexts to induce them to download malicious files.

This incident underscores the critical importance of verifying the authenticity of software used during recruitment processes. Security experts recommend that developers use isolated environments or virtual machines when performing coding tests for unknown entities. As the value of the cryptocurrency market remains a primary target for illicit actors, the collaboration between the FBI and NPA emphasizes the need for international vigilance and robust security protocols across the global tech workforce.

Frequently Asked Questions

Quick answers to the most common questions about this topic.