How did North Korean WaterPlum hackers steal $10.7M from crypto developers?

The North Korean cyber group WaterPlum stole $10.7 million by infecting 30,000 devices through fake job offers at crypto and AI firms. This massive social engineering campaign targeted developers in over 100 countries, highlighting a major security risk for technical personnel in 2026.
How did North Korean WaterPlum hackers steal $10.7M from crypto developers?

The North Korean-linked cyber group WaterPlum successfully drained $10.7 million in digital assets by compromising over 30,000 devices through a sophisticated 'fake recruiter' scheme. By posing as talent acquisition specialists for prominent AI, NFT, and crypto startups, the group tricked developers into downloading malicious software disguised as coding tests or technical assessments. This breach spanned more than 100 countries, making it one of the largest and most geographically diverse developer-focused social engineering attacks recorded in 2026.

The WaterPlum campaign specifically targeted technical talent on professional networking platforms and specialized developer forums. The hackers initiated conversations about high-paying roles and eventually requested that candidates run scripts or download software to 'test their skills' for a specific project. Once executed, these files installed persistent backdoors that allowed the North Korean operatives to bypass two-factor authentication and gain direct access to private keys, hot wallets, and sensitive credentials stored on the developers' local machines.

For US-based developers and crypto firms, this incident underscores the persistent threat posed by state-sponsored actors seeking to bypass traditional network defenses by targeting individual employees. The US Treasury and the FBI have previously linked such activities to the funding of sanctioned weapons programs, and this latest $10.7 million haul suggests that North Korean tactics are evolving to exploit the overlap between crypto and the growing AI sector. This geopolitical risk remains a primary concern for institutional investors looking at the security of the broader crypto infrastructure.

As the industry reacts to the scale of the WaterPlum infection, developers are urged to move technical interviews to hardware-isolated environments or use sandboxed virtual machines for any third-party code execution. Market participants should watch for new advisories from the Cybersecurity and Infrastructure Security Agency (CISA) and potential updates to the OFAC sanctions list targeting the wallet addresses associated with this specific campaign. The ongoing vulnerability of technical personnel suggests that 2026 will see increased demand for decentralized identity and zero-trust security solutions for remote hiring.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.