How did North Korea’s WaterPlum steal crypto worth $10.7M with fake job interviews?
North Korea remains one of the biggest risk factor to the crypto industry.
North Korea’s threat to the crypto industry is getting bigger by the day. According to a report by Japan’s National Police Agency (NPA) and the U.S Federal Bureau of Investigation (FBI), North Korean state-backed group WaterPlum stole $10.7M through fake headhunting.
WaterPlum reportedly posed as hiring managers for crypto firms, NFT businesses, and artificial intelligence companies and reached out to IT and software developers.
However, through a fake skill test, the victims were duped into downloading malicious programs that drained their wallets. Separately, the group also posed as employees and bagged lucrative offers with crypto firms only to gain access to their systems and compromise them.
According to the report, the group infiltrated 30K devices across over 100 countries, affecting over 7000 crypto wallets. And, it did this over an eight-month period from December 2025 to July 2026.
North Korea’s evolving crypto heist strategy
For perspective, WaterPlum is just one of the threat actors backed by North Korea, tracked by most security firms. And, it appears WaterPlum is purely designed for wide-scale fake recruitment schemes to deliver malware and steal victims’ crypto assets.
However, some of the recent high-value exploits have also been done by state-backed actors from North Korea. For example, TRM Labs linked the $285M Drift protocol hack to AppleJesus, also known as Citrine Sleet or UNC4736. This involved a daring 6-month face-to-face social engineering plan and $1M of their committed capital to compromise the core protocol’s contributors.
Perhaps one of the most lethal and high-value operators is the Lazarus Group, which is also backed by the state. It was behind the historic $1.5B Bybit exchange heist and KelpDAO’s $292M exploit.
Overall, these threat actors seem to be so sophisticated and organized, with each group with different targets and ways of compromising them. Interestingly, all the stolen crypto funds have become a crucial state revenue stream for North Korea, according to Certik.
In 2025, North Korean threat actors accounted for 60% or $2B of the $3.4B annual crypto losses, as per Certik. In fact, another security research firm, TRM Labs, estimated that the country drove 64% of overall crypto exploits last year.

As of H2 2026, North Korea-based hackers have accounted for 76% of total crypto losses, worth over $600M. They’ve marked a steady dominance and been a risk to the industry since 2020.
Final Summary
- Japan, the United States, and other countries reported that over $10M have been lost to fake job interviews by WaterPlum.
- North Korea now accounts for over 75% of stolen crypto funds in 2026.