North Korean state-backed group WaterPlum posed as recruiters for legitimate crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries and stealing $10.7 million in cryptocurrency between December 2025 and July 2026. The group targeted software developers and IT professionals with fake job offers on social media and freelance platforms, according to a joint advisory from Japan, Germany, Australia and the US. Victims were instructed to download malicious files disguised as coding assignments or video-conferencing fixes, giving the attackers backdoor access to over 7,000 cryptocurrency wallets. The advisory links WaterPlum to North Korea's Munitions Industry Department and notes the campaign extends beyond theft — stolen identity documents allow North Korean IT workers to impersonate victims and earn income, while sensitive information can be used for extortion.

This highlights the persistent vulnerability of individual wallet holders to targeted social engineering, particularly developers who hold crypto as part of their professional work. The scale — 30,000 devices across 100-plus countries — suggests a well-resourced campaign that exploited trust in legitimate recruiting processes and the rising demand for crypto and AI talent. The advisory described a case in which a suspected North Korean IT worker applied to a Japanese crypto exchange using a forged resume but was rejected after failing to explain listed skills during the interview. In July, Consensys engaged a North Korea-linked consultant and subsequently terminated access after discovery, with no theft or malicious code deployment confirmed. US authorities have warned about undercover IT workers since at least 2018.

For traders, this is a risk context update rather than a directional catalyst. The $10.7 million loss is distributed across thousands of wallets and does not represent forced selling by a single entity or institution. The theft occurred over eight months. The campaign targets individual developers, not exchange reserves or institutional custody, so systemic liquidity is unaffected. However, the scale and sophistication of the operation reinforce the case for institutional custody and hardware wallet discipline, particularly for developers holding meaningful crypto balances. Projects that rely on remote freelance talent should note the risk of North Korean IT infiltration — Consensys caught theirs, but the advisory confirms others have not.

The one thing to watch is whether any large exchange or protocol discloses a breach tied to WaterPlum or similar North Korean operations. A targeted attack on a centralised platform or DeFi treasury would create immediate downside and a flight to custody-secured assets. Until that happens, this is a reminder of persistent individual-level risk, not a systemic event that shifts market structure or liquidity. The advisory does not name any compromised exchanges or protocols beyond the rejected Japanese exchange applicant, and no major platform has reported unusual withdrawals or access patterns. The campaign's focus on individual wallets rather than institutional reserves keeps this outside the scope of a tradeable macro event.

Source: CoinTelegraph