How did North Korea’s Water Plum steal 암호화폐 worth $10. 7M with fake job interviews?
North Korea’s threat to the 암호화폐 industry is getting bigger by the day. According to a report by Japan’s National Police Agency (NPA) and the U. S Federal Bureau of Investigation (FBI), North Korean state-backed group Water Plum stole $10. 7M through fake headhunting.
Water Plum reportedly posed as hiring managers for 암호화폐 firms, NFT businesses, and artificial intelligence companies and reached out to IT and software developers.
However, through a fake skill test, the victims were duped into downloading malicious programs that drained their wallets. Separately, the group also posed as employees and bagged lucrative offers with 암호화폐 firms only to gain access to their systems and compromise them.
According to thereport, the group infiltrated 30K devices across over 100 countries, affecting over 7000 암호화폐 wallets. And, it did this over an eight-month period from December 2025 to July 2026.
For perspective, Water Plum is just one of the threat actors backed by North Korea, tracked by most security firms. And, it appears Water Plum is purely designed for wide-scale fake recruitment schemes to deliver malware and steal victims’ 암호화폐 assets.
However, some of the recent high-value exploits have also been done by state-backed actors from North Korea. For example, TRM Labs linked the $285M Drift protocol hack to Apple Jesus, also known as Citrine Sleet or UNC4736. This involved a daring 6-month face-to-face social engineering plan and $1M of their committed capital to compromise the core protocol’s contributors.
Perhaps one of the most lethal and high-value operators is the Lazarus Group, which is also backed by the state. It was behind the historic $1. 5B Bybit 거래소 heist and KelpDAO’s $292M exploit.
Overall, these threat actors seem to be so sophisticated and organized, with each group with different targets and ways of compromising them. Interestingly, all the stolen 암호화폐 funds have become a crucialstate revenue streamfor North Korea, according to Certik.
In 2025, North Korean threat actors accounted for 60% or $2B of the $3. 4B annual 암호화폐 losses, as per Certik. In fact, another security research firm, TRM Labs, estimated that the country drove 64% of overall 암호화폐 exploits last year.
As of H2 2026, North Korea-based hackers have accounted for 76% of total 암호화폐 losses, worth over $600M. They’ve marked a steady dominance and been a risk to the industry since 2020.
Benjamin Njiri is a 암호화폐 Analyst and Reporter at AMBCrypto, specializing in technical analysis and emerging market trends. With a background in Telecoms engineering and power systems, he applies data analysis to filter market noise and decode on-chain data. His work delivers clear, data-driven insights that help readers navigate 암호화폐 markets with confidence.
출처: AMBCrypto