North Korean gang WaterPlum fraudulent recruitment steals millions of dollars in currency.

CN
1 hour ago

During the period from December 2025 to July 2026, a hacker group named WaterPlum (also known as Contagious Interview) quietly began its operations. It wasn't until mid-2026 that multiple international agencies, including the Federal Bureau of Investigation (FBI) and the National Police Agency (NPA) of Japan, jointly issued warnings, revealing to the outside world that this organization, described in official materials as linked to North Korea, had breached over 30,000 devices in just about 8 months. Official reports indicated that they did not seek to exploit contracts or find loopholes in agreements, but instead masqueraded as companies in AI, cryptocurrency, or NFTs, publishing "job opportunities." Some media reports stated that the attacks primarily targeted global IT developers, gradually approaching job seekers through social media and recruitment platforms. As more endpoints were controlled, over 7,000 cryptocurrency wallets were hacked, with approximately $10.7 million in crypto assets transferred out, finally piecing together a complete picture of the attack on the blockchain. The joint warnings from multiple countries ultimately characterized this wave of actions as "fake recruitment" social engineering attacks, sounding the alarm for the cryptocurrency industry: technical vulnerabilities are no longer the only entry point for hackers; developers who hold private keys and code, as well as seemingly normal job application processes, are rapidly evolving into new security breaches.

Fake Recruitment Script: How High-Paying Offers Become Traps

In this round of operations, WaterPlum did not present itself as a "hacker organization" but rather deliberately donned the guise of popular sector companies. Reports indicate that they self-identified as being engaged in AI, cryptocurrency, or NFT-related businesses in their external communications, with job descriptions filled with keywords like "cutting-edge technology," "remote collaboration," and "generous benefits," making the overall packaging indistinguishable from real Web3 companies. Job seekers were presented with what appeared to be a normal tech team, an opportunity to engage with blockchain projects, coupled with meticulously designed company introductions and project stories, creating a familiar and safe atmosphere that made it difficult to connect it with an attack at first glance.

According to some media reports, this script primarily targeted IT developers globally, proactively reaching out via social media and various recruitment platforms, starting from a private message or a job recommendation, transforming the standard job application process into an attack chain. Initial communication, resume screening, and online interactions followed industry practices until subsequent phases gradually extended to operations related to the developers' personal terminals and cryptocurrency wallets, quietly completing a transition from the "recruitment scenario" to the "invasion scenario." The natural trust in "company branding" and "job opportunities" from job seekers became WaterPlum's critical breakthrough: the traditional technical defenses against unfamiliar emails and suspicious links remained, but when attacks disguised themselves as familiar career opportunities, the psychological boundaries of people's nearly unquestioned trust in these routine processes were genuinely circumvented.

Thirty Thousand Developer Machines Compromised: Personal Terminals Become New Backdoors in the Crypto World

The official warnings revealed numbers that escalated this operation from an "incident" to the magnitude of a "systemic attack": over 30,000 devices were controlled, involving more than 7,000 cryptocurrency wallets, with stolen assets amounting to approximately $10.7 million. These were not one-off exploits, but outcomes that accumulated slowly over about eight months of sustained operations from December 2025 to July 2026. The targeted terminals were mostly the work machines of IT developers, which are inherently integrated with multiple key permissions: on one hand, access to code repositories, development environments, and project backends; on the other hand, the personal and project-related cryptocurrency wallets and relevant keys. Once attackers secured this single entry point, they effectively opened dual backdoors to both the "code world" and the "asset world."

Therefore, the impact of WaterPlum successfully controlling personal terminals extends beyond simply emptying the assets in wallets. During the time the devices were under control, project codes, scripts, and packaging toolchains operated by developers could potentially be silently monitored or even have malicious changes passively implanted. This risk may not immediately present itself in the form of large-scale attacks, but objectively transforms isolated individuals into potential supply chain vulnerabilities: a single compromised development machine could be the starting point for the $10.7 million in stolen assets and could also expose more downstream users and projects to unseen attack surfaces.

FBI and NPA Voice Together: National-Level Attack and Defense Going Public

When the official statistics indicated that WaterPlum had breached over 30,000 devices, compromised more than 7,000 cryptocurrency wallets, and caused losses amounting to approximately $10.7 million between December 2025 and July 2026, this "incident" scattered across individual developer terminals was elevated to the level of a multinational security event. The Federal Bureau of Investigation (FBI), Japan's National Police Agency (NPA), and other international institutions unusually spoke out in a joint warning, not just to simply alert job seekers to fake recruitment, but using law enforcement language to inform the industry: these types of attacks have surpassed the capacity of any single jurisdiction to handle independently; there is a need to view stolen assets on the blockchain, cross-border victims, and the organizations behind them on the same battlefield map.

Moreover, the warning explicitly described WaterPlum / Contagious Interview as a hacker organization linked to North Korea, clearly categorizing this wave of attacks within the existing narrative of "state-level forces targeting cryptocurrency assets." Multiple countries publicly named and disclosed the attack time frame, the number of compromised devices, and the scale of losses, which will in turn compel exchanges, project teams, and practitioners to elevate standards of security and compliance: on one hand, developers' terminals, recruitment processes, and social engineering must be included in regular security assessments, considered a key attack surface capable of shaking the security of on-chain assets; on the other hand, there must also be pre-set scenarios for responding to state-level hackers in terms of compliance, risk control, incident response, and external information disclosure, acknowledging that they are already involved in a publicly visible national-level attack and defense confrontation.

Reshaping the Security Landscape: No Longer Just Contracts and Bridges Being Compromised

In recent years, the industry has equated "security incidents" almost exclusively with contract logic being breached or cross-chain bridges being compromised, with discussions on risk remaining at the protocol level and on-chain code itself. However, WaterPlum's recent actions deliberately bypassed contracts and protocols; both official warnings and media categorized it as "fake recruitment" social engineering attacks: first disguising as AI, cryptocurrency, or NFT companies, locking onto candidates on recruitment platforms and social media, then taking control of personal devices through malicious files and remote operations. Behind the compromised terminals lies a global community of IT developers naturally associated with project development and operations. Once computers and development environments are controlled, the linked cryptocurrency wallets become the most direct entry point, ultimately resulting in approximately $10.7 million in substantial losses spread over more than 7,000 wallets.

In this joint warning, the agencies specifically highlighted "fake recruitment," reflecting the reconfiguration of the security landscape: as remote work and global recruitment have become the default configuration today, the challenges of identity verification, terminal management, and vendor screening have significantly increased; any resume submission, outsourcing collaboration, or tool installation process could become an entry point for attacks. After the WaterPlum incident, the focus of Web3 security is expanding from "protection of single protocols" to a three-dimensional defense around people, terminals, and supply chains. Those who can incorporate all three layers into regular risk control will be the ones who truly qualify to claim their on-chain assets are within a controllable security range.

What to Do Next: A Self-Protection Checklist for Developers and Projects

For individual developers, the first step is to incorporate "job hunting" itself into the security domain: proactively verify the background of the recruiting company before submitting applications, achieving at least a threefold cross-check of the official website, business registration information, and past projects; if the other party rushes to skip formal processes, directly sends installation packages, or asks you to run unknown scripts on your machine, regard it as a high-risk signal. Next, ensure a physical and logical separation between wallets and work environments, placing wallets containing high-value assets on devices or secure environments completely isolated from daily development. Do not log into high-privilege addresses on the interview computer, and absolutely do not input mnemonic phrases or signatures in files, IDE plugins, or remote collaboration tools from unknown sources. Furthermore, given that WaterPlum has already stolen around $10.7 million in assets from more than 7,000 cryptocurrency wallets and that the attack time window extends until July 2026, any developer who has interacted with suspicious recruitment should thoroughly check their terminal and browser extensions according to the intent of the official joint warning, rotate keys, migrate assets, and eliminate potential risks. For projects and companies, recruitment and remote collaboration must be incorporated into security strategies: HR and security teams should jointly establish a "whitelist of legitimate interview tools," prohibiting the installation of unaudited software on core development machines; create multiple layers of isolation and operational audits for code repositories, deployment permissions, and signing devices, ensuring that a single compromised terminal cannot directly reach key addresses on the blockchain. WaterPlum is just one sample among many fake recruitment attacks, and these social engineering tactics may evolve into new disguising methods in the future. Only by having the entire community share intelligence over the long term and repeatedly emphasizing the awareness of "job hunting as an attack surface" in onboarding training and daily communication can we reduce the potential for endpoints to be compromised and wallets to be stolen during the next similar incident.

Join our community to discuss and get stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink