Skip to main content
North Korea-linked hackers target 7,000 crypto wallets
Image for illustrative purposes only. Not a real photo.

North Korea-linked hackers target 7,000 crypto wallets

Share
  • North Korea-linked WaterPlum has compromised more than 30,000 devices across over 100 countries and regions.
  • The campaign has stolen information from more than 7,000 cryptocurrency wallets, including private keys and seed phrases.
  • Japanese authorities have linked the activity to North Korean IT workers and Bureau 313.

North Korea-linked hacking group WaterPlum has compromised more than 30,000 devices and stolen information from over 7,000 cryptocurrency wallets.

The campaign operated from around December 2025 to July 2026, targeting developers and Web3 workers through fake recruitment campaigns across more than 100 countries and regions.

Japanese and US authorities have linked WaterPlum and some North Korean IT workers to Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department.

Attackers posed as cryptocurrency, artificial intelligence and NFT companies before sending malicious files disguised as coding tests, interviews or technical assignments.

The malware targeted browser credentials, keystrokes, screenshots and clipboard data, while private keys and seed phrases stored on affected devices were also targeted.

Wallets controlled by WaterPlum received at least 1.7 billion yen, worth roughly $10.7 million based on the exchange rate used by Japanese authorities, although the figure does not represent a direct valuation of the 7,000 compromised wallet records.

Japanese investigators have also dismantled a domestic laptop farm linked to North Korean IT workers, while a suspected North Korean applicant was identified before being hired by Japanese cryptocurrency exchange bitFlyer in 2025.


Frequently asked questions