North Korean cyber operators are still using the job interview as an attack vector. A group tracked as WaterPlum ran fake recruiter campaigns aimed at developers working at crypto, AI, and NFT companies, infecting roughly 30,000 devices and stealing $10.7 million, according to a report published by Cointelegraph on September 21, 2026.
The mechanics are old, but the scale is what stands out. This is not a one-off phishing email. It is a repeatable pipeline that turns a routine hiring conversation into a device compromise, and it is aimed squarely at the people who hold the keys to crypto infrastructure.
The interview is the malware delivery
The pattern in these campaigns tends to follow the same script. A recruiter reaches out with an attractive role, moves the conversation to a chat app, and eventually asks the candidate to complete a technical assignment. That assignment, a "coding test" or a demo repository to run locally, carries the malicious payload. Once the developer runs it on a work machine, the attacker gains a foothold.
Developers are a high-value target for a reason. A single engineer at a crypto firm may have access to signing keys, deployment pipelines, internal admin tools, or the wallets that move customer funds. Compromise one laptop and you can potentially reach far more than $10.7 million in downstream value. The reported theft figure is the money that has already moved, not a ceiling on the exposure.
30,000 devices is an industrial number
The 30,000 device figure reframes this from a targeted heist into a wide net. Campaigns at that scale are not hand-crafted for each victim. They run on volume, blasting fake job offers across developer communities and job boards, then sorting the responses for the machines that turn out to matter.
That volume also means the blast radius extends past crypto. The report names AI and NFT companies as targets alongside crypto firms. Any organization where an engineer routinely clones and runs unfamiliar code as part of a hiring process sits in the same threat model.
State-backed theft is a funding line, not a hobby
North Korea-linked groups have spent years treating crypto theft as a revenue source rather than pure vandalism. The appeal is straightforward: crypto settles quickly, moves across borders without a bank in the loop, and can be laundered through mixers and thin-KYC venues. Stolen funds get converted, split, and moved before most victims finish writing the incident report.
For the broader ecosystem, this is part of a larger pattern. Onchain malware and wallet-targeting attacks have climbed sharply this year, and much of that growth traces back to state-backed operators rather than opportunistic scammers. The fake-recruiter playbook is one branch of that tree, sitting next to malicious browser extensions, fake trading tools, and mobile malware that harvests wallet logins.
The indirect risk to everyday crypto users
Most readers will never receive a WaterPlum job offer. The exposure is indirect but real: if the developers and companies you trust with custody get compromised, your funds can move without you clicking anything. That is the argument for holding a meaningful share of your balance in a wallet you control rather than leaving everything on a platform.
Cards that let you spend from your own wallet reduce the surface area an attacker can reach through a single corporate breach, because there is no central custodial pool holding your balance. That is not a cure for social engineering, which targets people rather than protocols, but it changes what a single compromised laptop can drain.
The practical defense against the campaign itself is boring and effective. Treat any unsolicited "run this project" step in an interview as untrusted code. Run unknown repositories in a disposable virtual machine or a sandboxed container, never on the machine that holds your keys or your production access. Verify recruiters through the company's official channels before installing anything. A legitimate employer will not lose the candidate over a request to run their test in isolation.
The takeaway
WaterPlum's $10.7 million haul is a reminder that the weakest link in crypto security is often a human being reading a friendly message, not a smart contract bug. The report cites a single group across roughly 30,000 devices, so treat the figure as one operator's tally in a much larger, ongoing campaign rather than the full scope of state-backed developer targeting.
Overview
- WaterPlum, a North Korea-linked group, ran fake recruiter campaigns against developers at crypto, AI, and NFT companies, per a Cointelegraph report dated September 21, 2026.
- Researchers attribute roughly 30,000 infected devices and $10.7 million in stolen crypto to the operation.
- The malware is delivered through fake "coding test" assignments during the hiring process, targeting the machines of engineers with privileged access.
- Users can limit indirect exposure by holding funds in wallets they control and by treating any interview code as untrusted until run in isolation.



