BlocktoBlockto
North Korean Hackers Steal $10.7M by Posing as Crypto Recruiters
NEWS

Photo: Illustrative

North Korean Hackers Steal $10.7M by Posing as Crypto Recruiters

A North Korean hacking group known as WaterPlum has stolen at least $10.7 million by impersonating recruiters for legitimate crypto, AI, and NFT companies, according to a joint advisory from authorities in Japan, Germany, Australia, and the United States. The group, also referred to as Contagious Interview, primarily targeted software developers, engineers, and specialists working in blockchain and Web3 technologies.

Tristan R.
By Tristan R.

Senior Author · September 21, 2026

2 min
Key takeaways
A North Korean hacking group known as WaterPlum has stolen at least $10.7 million by impersonating recruiters for legitimate crypto, AI, and NFT companies, according to a joint advisory from authorities in Japan , Germany, Australia, and the United States.
The group, also referred to as Contagious Interview, primarily targeted software developers, engineers, and specialists working in blockchain and Web3 technologies.
How the Scheme Worked According to the advisory, fake recruiters lured victims through social media, job boards, and freelance platforms, eventually instructing them to download malicious files disguised as coding assignments or fixes for video conferencing issues.

A North Korean hacking group known as WaterPlum has stolen at least $10.7 million by impersonating recruiters for legitimate crypto, AI, and NFT companies, according to a joint advisory from authorities in Japan, Germany, Australia, and the United States. The group, also referred to as Contagious Interview, primarily targeted software developers, engineers, and specialists working in blockchain and Web3 technologies.

How the Scheme Worked

According to the advisory, fake recruiters lured victims through social media, job boards, and freelance platforms, eventually instructing them to download malicious files disguised as coding assignments or fixes for video conferencing issues. Once installed, the malware granted attackers backdoor access, allowing them to deploy remote-access tools and data-stealing programs to extract sensitive information and crypto.

Broader Ties to North Korean State Operations

Authorities linked WaterPlum to North Korea’s wider strategy of embedding IT workers inside foreign companies, with officials assessing that some operatives function under the country’s Munitions Industry Department. Beyond financial theft, compromised systems reportedly gave attackers pathways to infiltrate the organizations that employed affected developers.

Real-World Cases Highlight the Threat

The advisory cited an instance where a suspected North Korean operative applied for an engineering role at a Japanese crypto exchange using a falsified resume, but was rejected after failing to explain the technical skills listed. In a separate case reported earlier this year, a blockchain company unknowingly engaged a North Korea linked developer as a contractor before terminating access once the connection was discovered, with no reported theft or security impact.

This campaign adds to a long pattern of North Korea using cryptocurrency theft to generate revenue, following previous major incidents including a $1.5 billion exchange hack attributed to North Korean actors last year.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.