WaterPlum Phishing Campaign Stole $10.7 Million in Crypto

A joint report from Japan, the United States, Australia and Germany links North Korean hacker group WaterPlum, also known as Contagious Interview, to job-seeking phishing attacks and laptop farms. WaterPlum targets developers and engineers, especially those working in cryptocurrency and blockchain, by posing as recruiters or crypto companies. Victims are asked to download coding tests or project files that contain malware such as BeaverTail, InvisibleFerret, OtterCookie and StoatWaffle. Malicious VS Code settings and NPM packages can execute code and steal browser passwords, clipboard data, screenshots, private keys and wallet seed phrases. From December 2025 to July 2026, at least 30,000 computers in more than 100 countries were infected. Data from over 7,000 crypto wallets was stolen, while about JPY 1.7 billion, or roughly $10.7 million, flowed to WaterPlum-controlled wallets. Japanese police also dismantled a laptop farm allegedly used by North Korean IT workers operating remotely through local identities, VPNs and rented computers. The report connects the cyber operations and overseas employment schemes to North Korea’s General Bureau 313. It also describes a suspected North Korean applicant who sought an engineering role at Japanese exchange bitFlyer in 2025 but was rejected after inconsistencies emerged during interviews. Crypto users and developers should avoid running untrusted code, use virtual machines or VS Code Restricted Mode, disconnect compromised devices and move wallet assets to new wallets if private keys may have been exposed.
Neutral
The immediate market impact is likely neutral because the report concerns targeted cybercrime rather than a protocol failure, exchange insolvency or broad market liquidation. However, it is negative for crypto security sentiment. The reported theft of about $10.7 million and the compromise of more than 7,000 wallets could trigger short-term caution among traders, particularly users holding funds in software wallets or working with untrusted code. Security alerts of this kind have historically produced limited, temporary selling unless they involve a major exchange, bridge or widely used protocol. The bitFlyer case does not indicate that the exchange was breached, which reduces systemic risk. In the short term, traders may move assets to hardware or newly generated wallets, increase stablecoin balances and monitor suspicious addresses, potentially raising demand for wallet screening and blockchain intelligence services. In the long term, repeated North Korean campaigns could lead exchanges, crypto firms and regulators to strengthen recruitment checks, endpoint security, wallet controls and sanctions enforcement. Those measures may improve market resilience but also increase compliance costs and friction for freelancers and crypto businesses. Traders should watch for any confirmed compromise of a major platform, large transfers from identified WaterPlum wallets, or follow-up sanctions. Without such developments, the incident is best treated as a security warning rather than a broad bearish catalyst.