WaterPlum Targets 30,000 Devices and Steals 7,000+ Crypto Wallet Records Worldwide
Key Takeaways: WaterPlum hacked over 30,000 devices in 100+ countries and accessed information from 7,000+ crypto wallets. Fake jobs, coding tests and malicious code targeted crypto, blockchain and Web3 developers. At le...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Key Takeaways:
- WaterPlum hacked over 30,000 devices in 100+ countries and accessed information from 7,000+ crypto wallets.
- Fake jobs, coding tests and malicious code targeted crypto, blockchain and Web3 developers.
- At least $1.8 million in tokens had been sent to WaterPlum’s wallets by Japanese authorities.
User Score
8.7
Follow us on Google NewsJapan’s National Police Agency (NPA) has exposed a large-scale cyber campaign targeting IT professionals, with cryptocurrency theft at the center of the operation. The investigation linked the WaterPlum group to activity associated with North Korean IT workers and uncovered infrastructure used to hide their identities and locations.
WaterPlum Turns Fake Jobs Into Crypto TheftThe NPA said the campaign would be initiated around December 2025 and end in July 2026. It was thought that more than 30,000 computers in over 100 countries and regions were infected.
The main targets included web developers and designers, as well as crypto and blockchain experts. WaterPlum allegedly reached out to victims through social media, recruitment sites, gigs and freelance marketplaces.
The attackers would frequently disguise themselves as trusted crypto, AI or NFT firms. Online Interviews were then followed, where candidates had to solve software problems and/or coding assignments.
Some applicants were given assignments to download files from development sites or code repos in lieu of a typical technical assignment. It is possible for those files to have malware that can compromise the victim’s machine.
Read More: Revolut Crypto Data Leak Exposes Bitcoin Records, Attackers Demand Payment to Stop More
Malware Went After Wallet CredentialsThe NPA found multiple malware families associated with the attack: OtterCandy, OtterCookie, InvisibleFerret, BeaverTail and StoatWaffle.
If a system gets infected with the malware, it can grant persistent access in the system, and extract sensitive information from it. The catcher could grab browser cookies, clipboards, keystrokes, screenshots and files saved on the computer.
The biggest threats faced by crypto users were wallet credentials. According to the NPA, over 7,000 cryptocurrency wallet records were stolen. Private keys and seed phrases were among the information sought by the attackers.
The investigation also uncovered a minimum of ¥1.7 billion ($10.71 million RTW) of cryptocurrency moved to wallets operated by WaterPlum. This is an estimate of funds that have been identified by investigators, not an estimate of all potential losses.
North Korean IT Workers Add a Second Crypto RiskThe investigation also found another way to make money with Tech jobs. Japanese officials discovered and blocked a new “laptop farm” where computers were stored by a facilitator, and controlled remotely by North Koreans. Such machines could then be employed by workers to accept jobs and appear to be coming from Japan.
A minority also used stolen or mis-used identity papers and the use of VPS to mask the actual identities of the workers. Crypto and other assets valued at over hundreds of millions of yen have been sent abroad in incidents linked to the investigation, investigators said.
The NPA and the FBI concluded that the activities of WaterPlum and some North Korean IT workers were being directed by the Munitions Industry Department’s Bureau 313 of the Workers’ Party of Korea.
Read More: BonkDAO Hit by $20M Treasury Hack After Malicious Governance Proposal Rocks BONK Holders
The post WaterPlum Targets 30,000 Devices and Steals 7,000+ Crypto Wallet Records Worldwide appeared first on CryptoNinjas.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoNinjasRelated market context
Samsung Wallet Brings USDC to 82M Galaxy Devices With Coinbase, Solana and Sui Support
Key Takeaways: Samsung Wallet will support 82 million U.S. Galaxy to add transfers on USDC. Coinbase will keep USDC in their Coinb...
AI Could Weaken Ethereum Security as Cryptographic Risks Grow, Vitalik Buterin Warns
Buterin urged developers to prepare for potential AI vulnerabilities in both conventional and quantum-resistant cryptography, whil...
Ledger investigates wallet tampering tied to tens of millions in crypto thefts
The investigation highlights the critical need for enhanced security measures and trust in crypto hardware supply chains to preven...
Stealing $1.5B in crypto is easy, cashing out is the trap
North Korean hackers stole around $1.5 billion from Bybit in February 2025. While the hack itself has been widely covered and anal...
Ledger Confirms Hidden Hardware Implant in Affected User’s Wallet
Ledger confirmed Saturday, Oct. 10, 2026, that a hardware wallet belonging to one affected customer contained an unauthorized impl...
Wallet Linked to CryptoBilis Thefts Routes 464 ETH to Tornado Cash
Ethereum records show the money passed through an intermediary and four deposit wallets, while the source address retained about 7...