North Korea Ran a Fake Recruiting Operation and 30,000 Crypto Developers Had No Idea

North Korean cyber group WaterPlum built an entire fake recruiting pipeline, posed as hiring managers at crypto, AI, and NFT companies, and quietly infected at least 30,000 devices across more than 100 countries, walking away with $10.7 million in stolen crypto.

This was not a phishing email. This was a coordinated, months-long social engineering campaign designed to target the exact people building the future of Web3.

How It Worked

WaterPlum approached developers through legitimate-looking job postings and LinkedIn-style outreach. Targets were offered roles at credible-sounding crypto and NFT firms. Once a candidate engaged, they were walked through a fake interview or technical assessment process that required them to download files or run code on their machines.

That was the moment of infection.

The malware deployed gave attackers persistent access to developer environments, crypto wallets, and private keys. With that access, the group drained $10.7 million across the campaign.

Over 100 countries were affected, meaning this was not a targeted regional attack. WaterPlum was casting the widest net possible, prioritizing volume.

Why This Hits Different

Most crypto hacks exploit smart contract bugs or protocol vulnerabilities. This one exploited something harder to patch: human trust.

Developers are high-value targets. They often hold significant personal crypto holdings, have access to project treasuries, and work in environments where running unfamiliar code is completely normal. WaterPlum knew exactly who to target and exactly how to approach them without raising flags.

This is also not WaterPlum's first operation. North Korean state-sponsored hacking groups have stolen billions from the crypto industry over the past several years, with the Lazarus Group alone responsible for over $3 billion in theft since 2017 according to blockchain analytics firms. WaterPlum represents an escalation in recruitment-based attack vectors specifically.

What Crypto Holders and Developers Need to Do Right Now

If you are a developer who has applied to crypto, AI, or NFT jobs in recent months, treat any code you ran during an interview process as potentially compromised. Rotate your wallet keys, revoke permissions, and audit your development environment immediately.

For the broader market, this is a reminder that North Korean groups are not slowing down. They are getting more sophisticated, more patient, and more profitable. Any project that employs remote developers should be reviewing its onboarding security protocols today.

Watch for any anomalous wallet activity connected to developer addresses over the coming weeks. The full scope of this campaign may not yet be known, and follow-on drains from already-compromised devices remain a real risk.

The job offer looked real. The recruiter seemed legit. That was the whole point.