North Korean Hackers Steal $10.7M in Crypto via Fake Job Listings, Infect 30,000+ Devices
A North Korean state-sponsored cyber group infiltrated developer networks across more than 100 countries by impersonating job recruiters, compromising at least 30,000 devices and draining $10.7 million from roughly 7,000 cryptocurrency wallets.
North Korean Hackers Steal $10.7M in Crypto via Fake Job Listings, Infect 30,000+ Devices
A North Korean state-sponsored cyber group infiltrated developer networks across more than 100 countries by impersonating job recruiters, compromising at least 30,000 devices and draining $10.7 million from roughly 7,000 cryptocurrency wallets.
The group, identified as WaterPlum, ran fraudulent recruitment campaigns targeting developers employed at crypto, AI, and NFT companies. Victims were approached with convincing fake job offers. Once engaged, the attackers delivered malware through the recruitment process itself, likely via infected code repositories, technical assessments, or onboarding documents. This delivery method has become a signature tactic of North Korean cyber units in recent years.
Thirty thousand infected devices across more than 100 countries represents a broad operational footprint, suggesting WaterPlum ran the campaign over an extended period rather than in a single burst. The $10.7 million total across approximately 7,000 wallets works out to roughly $1,528 per compromised wallet on average. That figure is low relative to the infection count, pointing to two possibilities: either many victims held limited crypto balances at the time of extraction, or the attackers were selective, draining only wallets where withdrawal would avoid triggering exchange-level fraud detection.
Developer targeting is deliberate. Crypto and AI companies hire quickly, often onboarding contractors and remote engineers with minimal vetting. Developers routinely run unfamiliar code as part of technical interviews or trial projects, which gives attackers a natural delivery vector for malware. Once a developer's machine is compromised, attackers gain access not just to personal wallets but potentially to private keys, seed phrases, and internal tooling with broader organizational access. A single infected developer at a DeFi protocol or custodial exchange could expose far more than their own holdings.
North Korean hacking operations have escalated steadily in sophistication and yield. The 2022 Ronin Network breach, attributed to the Lazarus Group, netted approximately $625 million in ETH and USDC, the largest single crypto theft on record. The WaterPlum campaign is smaller in dollar terms but broader in geographic reach and infection count, reflecting a shift toward volume-based social engineering rather than targeted platform exploits. The United Nations has previously estimated that North Korea has stolen more than $3 billion in cryptocurrency since 2017, with proceeds funding the country's weapons programs.
North Korean cyber group WaterPlum targeted developers with fake jobs at crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries.
For developers and security teams, the immediate implication is clear: any unsolicited recruitment contact that involves running code, downloading files, or completing a technical task on a personal or work machine should be treated as a potential threat vector. Crypto security firms have previously recommended that developers use isolated virtual machines for any code execution tied to job applications.
The broader market impact of this specific theft is limited. $10.7 million is a rounding error against total crypto market capitalization. But the campaign's reach across more than 100 countries, more than 30,000 devices, and deliberate targeting of builders inside the industry signals that North Korean groups are investing in social engineering infrastructure at scale. Exchanges and protocols that employ remote developers should treat this as a prompt to audit device security policies and review what level of wallet or key access individual contributors hold.



