North Korean Hackers Stole 7000 Crypto Wallet Records

9 min read
0 views
Sep 18, 2026

Japan just tied a global malware campaign to more than 7,000 stolen crypto wallet records. The twist is not only the theft. It is how the attackers walked in through job interviews.

Financial market analysis from 18/09/2026. Market conditions may have changed since publication.

Seven thousand wallet records. That number landed this week and it still feels too neat, too round, too easy to scroll past. I sat with it for a minute because wallet records are not just files. They are seeds, keys, browser leftovers, screenshots, clipboard scraps. They are the kind of material that turns a quiet compromise into a transfer you only notice when the balance is already gone.

Japan’s investigators, working with partners in the United States, Australia and Germany, say a North Korea linked cluster known as WaterPlum infected more than 30,000 devices across over 100 countries and regions. The window they described runs from around December 2025 through July 2026. Web designers, engineers, and people working in crypto, blockchain and Web3 sat in the middle of the target list. I’ve found that this mix is not an accident. Those jobs sit at the junction of money, code and remote work, which is exactly where a fake recruiter can look legitimate for just long enough.

What The WaterPlum Case Actually Reveals

Authorities assessed that WaterPlum, tied to activity often discussed as Contagious Interview, and some North Korean IT workers sit under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department. That institutional framing matters. This is not a lone operator selling stolen logins on a forum. It is a revenue and access machine dressed as hiring.

Wallets controlled by the group received at least 1.7 billion yen, about $10.7 million at the rate Japanese officials used. That figure is the visible haul, not the full cost. Stolen identity documents, stored passports, driver’s licenses, and shared folder contents do not show up as a ticker price. They show up later as account takeovers, fake profiles, and new applications that look almost real.

The interview is no longer a filter. In too many crypto teams, it has become the attack surface.

Perhaps the most interesting aspect is how ordinary the first contact sounded. Social media. Job boards. Gig platforms. Freelance marketplaces. Attractive roles at supposed AI, cryptocurrency and NFT firms. Then a coding test. Then a file that needed to be downloaded so a video call could work, or so an assignment could be graded. That last step is where curiosity beats caution, and I say that as someone who has watched smart people click because they did not want to lose a role.

How Fake Crypto Jobs Became The Delivery Channel

WaterPlum did not need a zero day story to make headlines. It needed a plausible hiring process. Candidates were steered toward collaborative development platforms and code repositories. Malicious packages were placed in that flow. Once a machine was compromised, operators could keep a foothold, move around the device, and pull credentials, keystrokes, screenshots and clipboard data.

Private keys and seed phrases sat near the top of the wish list. That should not surprise anyone who has spent time around self custody. A seed phrase on a notes app, a screenshot of a recovery screen, a browser extension left unlocked, a password manager session that never timed out. None of that is exotic. It is Tuesday afternoon sloppiness, and it scales.

Security researchers have been warning about this pattern for years. Developers inside DeFi projects have been approached through job posts, emails, professional networking messages, video calls and staged interviews. The WaterPlum disclosure does not invent that playbook. It puts official weight behind it and attaches a body count of devices and wallets.

  • First contact through social platforms, job sites and freelance markets
  • A company story built around AI, crypto or NFT work
  • A technical task that requires downloading code or a helper file
  • Persistent access after the first infection
  • Theft of wallet material, identity files and session data

In my experience, teams still treat recruitment as a people problem and security as a product problem. Those two rooms need to share a wall. If your hiring pipeline can place untrusted code on an engineer’s laptop, your treasury policy is already leaking.

Thirty Thousand Devices And A Map That Keeps Growing

More than 30,000 computers. More than 100 countries and regions. Japan included. Those numbers are large enough to sound abstract, so it helps to think in roles rather than flags. A designer with client wallets in a browser. An engineer with staging keys in a local env file. A community lead who keeps a hot wallet for giveaways. A founder who photographs a hardware device “just this once.”

The campaign did not need every victim to be rich. It needed volume, then sorting. Information stealing tools are good at that sorting. They collect first and let operators decide later which machines are worth a second pass. That is why a modest laptop in a small studio can matter as much as a well known protocol contributor.

I keep coming back to the time span. December 2025 to July 2026 is not a weekend smash and grab. It is a season. Long enough for victims to change jobs, wipe machines, or assume an odd interview file was harmless because nothing exploded on day one. Delayed discovery is a feature of this style of theft, not a bug.

The Japan Laptop Farm And Why Location Theater Works

Investigators say they dismantled the first known domestic laptop farm tied to North Korean IT workers in Japan. A local facilitator kept machines at home. Workers elsewhere drove those machines remotely. Identity documents belonging to people living in Japan were used so the workers could look local on paper. Payments sometimes landed in facilitator accounts and then moved on.

Some workers operated from North Korea. Others sat in China or Russia. Smaller numbers were placed in Africa and Southeast Asia. Laptop farms and virtual private servers helped hide the real desk. Crowdsourcing platforms, both domestic and overseas, supplied the contracts. The point was not elegance. The point was a paycheck that could be converted and sent out of the country.

Comparable cases in the United States ended in prison time for facilitators who helped remote workers sit on company laptops. Prosecutors described schemes touching nearly 70 companies and more than a million dollars in one cluster, with additional facilitators sentenced across a short stretch of months. Separate forfeiture actions targeted stablecoin rails used to pay workers. One September order covered roughly $212,700 in USDC and USDT tied to worker payment addresses, inside a broader effort measured in millions.

None of that is a side plot. Currency generation through remote tech work and currency generation through malware can share staff, infrastructure and political cover. Japanese and U.S. assessments put Bureau 313 in that shared center.

The bitFlyer Interview That Did Not End In A Hire

In May 2025, a suspected North Korean IT worker applied for an engineering seat at a major Japanese exchange using another person’s identity. The application arrived through the public recruitment form. Contact ran through a consumer mail account. Access came through proxy and VPN services. During the call, the applicant claimed to be Malaysian and living in Finland. The resume listed a thick stack of languages, blockchain work, cloud platforms, a European university and jobs across Europe and Asia.

Simple questions got answers. Detailed ones got fog. Investigators noted glances at a second screen, voices in the background, video dropouts. The candidate pushed back on relocating to Japan and wanted salary in cryptocurrency. The exchange did not hire. No loss was reported. A similar pattern had already been flagged at another large exchange, where the name on the call did not match the resume and live help seemed to sit just off camera.

Here is the part that should make hiring managers sit up. Investigators found matching infrastructure between WaterPlum operators, laptop farm traffic and that failed application. Same neighborhood of IP use. Same scaffolding. The malware crew and the employment crew were not two distant stories. They were rooms in one building.

If a candidate cannot tolerate a location check, a skills deep dive, or a fiat payroll, that is not a lifestyle preference. That is a signal.

Why Crypto Teams Keep Walking Into The Same Room

Remote first culture made this easier. So did the habit of treating a polished Git profile as identity. So did the rush to fill Solidity, Rust, DevRel and growth seats before a competitor does. I do not say that to scold founders who are short on time. I say it because speed without verification is now a documented loss channel.

Crypto also concentrates portable value on the same machines used for interviews. That is a design choice, even if nobody wrote it down. A designer edits a landing page on the laptop that also holds a browser wallet. An auditor clones a repo on the laptop that also stores client notes. Separation of duties sounds boring until a fake take home test arrives.

There is another human wrinkle. People want the job. They want to be helpful. They install the “fix” for the video tool. They run the “small diagnostic.” They tell themselves they will wipe the folder later. Later rarely comes. I’ve found that shame then keeps some victims quiet, which gives operators more time.

What Employers Were Told To Check Without Turning Hiring Into Theater

Official guidance from Japanese authorities was practical. Verify claimed location, qualifications and contact details. Pay extra attention when a candidate insists on fully remote work or crypto only pay. Test the skills that the resume shouts about. Compare the stated city with the network path used to submit the application. None of that requires a spy novel. It requires slowing the process by one extra day.

  1. Match identity documents to the person on the call using a live, unscripted check
  2. Ask for work that cannot be coached in real time from a second monitor
  3. Refuse candidate supplied “helper” files on personal or work devices
  4. Keep interview machines isolated from wallets, keys and production access
  5. Treat crypto only salary demands and relocation refusal as risk flags, not personality quirks

Is this fair to honest remote workers in another country? Fairness and safety are not opposites here. Plenty of strong engineers live far from headquarters. They can still prove who they are, where they sit, and what they can build without asking you to execute unknown packages.

Wallet Hygiene After A Campaign Like This

If you interviewed for a role in the last year and downloaded a take home archive, assume you should review that machine. Look at browser extensions added around that date. Rotate passwords that lived in the same profile as a wallet. Move funds off any hot wallet that shared a desktop with unknown code. That last step is not panic. It is basic containment.

Hardware devices help, but they are not magic if the seed was photographed, typed into a notes app, or pasted through a compromised clipboard. The record count in this case should be read as a reminder that “wallet records” include more than a keystore file. They include the messy human trail around the wallet.

Teams that hold treasury should also ask a blunt question. Who on staff can still approve a move from a laptop that has ever been used for a coding test? If the answer is “a few people, probably,” you already know the next internal task.

The Money Trail Is Smaller Than The Strategic One

$10.7 million is serious money and still small next to the largest exchange heists of the past few years. That comparison misses the point. WaterPlum looks built for persistence and dual use. Steal from wallets when the chance appears. Place workers inside companies when the interview goes well. Collect identity kits either way. Generate foreign currency under political direction.

Forfeiture cases against worker payment addresses show governments trying to pinch the employment rail at the same time they publish the malware rail. That two track pressure will continue. It will not, by itself, stop a candidate from joining your next video call with a second coach in the room.

So the practical burden sits with hiring desks, security leads and anyone who still runs unknown code because a stranger promised a salary. That is an unglamorous conclusion. It is also the one that matches the evidence.


A Few Uncomfortable Questions Worth Asking Out Loud

Would your team notice if a new contractor’s IP path never matched the city on the contract? Would a founder approve a merge from a machine that also holds a personal wallet? Would an applicant who freezes on follow up questions still get a second call because the resume was stacked with fashionable keywords?

I keep a short bias here. Crypto did not invent state backed theft. It did invent a workplace where value, identity and source code live on the same thin laptop. Until that habit changes, fake interviews will keep paying. The WaterPlum file is not a curiosity from one week in September. It is a checklist that arrived late, with 7,000 wallet records attached as the receipt.

If you take one thing from the disclosure, take this. Treat every unsolicited technical test as hostile until it is proven otherwise. Treat every remote hire as a verification problem, not a vibe problem. And if a number like 30,000 infected devices feels distant, remember that the next machine in that count can look exactly like the one on your desk.

I think the internet is going to be one of the major forces for reducing the role of government. The one thing that's missing but that will soon be developed is a reliable e-cash.
— Milton Friedman
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>