A North Korean cyber operation that posed as recruiters has infected at least 30,000 devices and stolen at least $10.7 million in cryptocurrency, showing how hiring processes have become a direct security risk for digital asset companies.
Malware hidden inside the hiring process
A joint advisory from authorities in the United States, Japan, Germany and Australia says the North Korean group WaterPlum, also known as Contagious Interview, targeted technology workers across more than 100 countries. The campaign focused on software developers, web designers, engineers and other specialists whose access to code, company systems and digital wallets can make them valuable entry points.
The attackers approached candidates through social media, online job boards, gig work sites and freelance marketplaces. After establishing contact, they instructed victims to download files presented as coding assignments, software fixes or tools for resolving video conference problems. The files instead installed malware that created backdoor access to affected devices.
According to the advisory, the attackers could then deploy remote access trojans and information stealing software. That access allowed them to extract sensitive information, compromise cryptocurrency wallets and potentially move deeper into the networks of employers. Authorities said more than 7,000 wallets had funds or credentials extracted between December 2025 and July 2026. Identified cryptocurrency losses reached at least $10.7 million.
Cointelegraph reported the advisory’s findings on September 21, 2026. The figures likely represent only the losses authorities have been able to connect to the campaign, rather than a complete account of its financial impact.
The operation is significant because it turns a familiar business activity, the technical interview, into a delivery mechanism for malware. Traditional phishing defenses often focus on suspicious email links, fake payment requests or urgent messages from apparent executives. A malicious coding test can appear more credible because it is relevant to the candidate’s skills and arrives during a process the victim expects to involve unfamiliar files and software.
Why crypto companies are especially exposed
Cryptocurrency businesses have several characteristics that increase the potential damage from this type of intrusion. Exchanges, custodians and wallet providers may connect employees to systems holding digital assets, transaction credentials and customer information. Protocol developers can have access to source code, deployment keys and administrative accounts. Smaller startups may rely on a limited number of engineers who perform several functions, sometimes from personal devices and across multiple time zones.
A compromised developer does not need to steal funds immediately to create a serious risk. Attackers could study internal procedures, obtain credentials, identify wallet management practices or manipulate software before a release. They might also use the employee’s access to target other staff members or suppliers. In a sector where a single leaked private key can cause irreversible losses, the distinction between an employee device breach and a treasury incident is often narrow.
The campaign also reflects the increasingly global nature of crypto hiring. Companies frequently recruit pseudonymous or remote talent based on portfolios, open source contributions and online reputations. That model broadens access to technical expertise, but it can make identity verification and employment screening more difficult.
A case cited in the advisory involved a suspected North Korean operative who applied for an engineering role at a Japanese cryptocurrency exchange using a forged résumé. The applicant was rejected after failing to explain the skills listed in the application. The example illustrates that recruitment risk is not limited to malware downloads. False identities and fabricated professional histories can also be used to obtain legitimate access to corporate systems.
Verification without closing the door
The challenge for crypto companies is to strengthen recruitment controls without making remote work inaccessible to qualified candidates. Firms can begin by separating candidate evaluation from access to sensitive infrastructure. Coding assignments should run in isolated environments, use disposable credentials and avoid requiring applicants to install unknown software on personal computers.
Employers should also verify claims through structured technical interviews, reference checks and reviews of public code that can be tied to a consistent identity. A résumé alone should not determine access to repositories, production systems or financial operations. Companies can require identity checks before issuing equipment or granting access, while preserving privacy by limiting the information collected to what is necessary.
Internal controls matter after hiring as well. Developers should use hardware protected credentials, multifactor authentication and separate accounts for code development and financial operations. Wallet permissions should follow the principle of least privilege, with transaction approvals divided among more than one authorized person. Network monitoring and endpoint detection can help identify unusual downloads, remote access activity or attempts to export credentials.
For venture backed startups, these measures may seem costly compared with rapid recruitment. Yet the expense of a professional security process is small relative to the value of a treasury, customer database or unreleased protocol code. Investors and business partners may increasingly treat workforce security as part of operational due diligence.
A broader warning for the industry
WaterPlum is connected to North Korea’s wider effort to place information technology workers inside foreign companies. Authorities say stolen identities, forged résumés and remote employment can generate income, extract information or support cryptocurrency theft.
That strategy broadens the industry’s understanding of cyber risk. Security is no longer limited to smart contract audits, wallet design or exchange defenses. It also includes who is being hired, how candidates receive technical tasks, what devices they use and how access changes after employment begins.
For crypto companies, the lesson is practical. A legitimate recruitment process must be treated as part of the company’s security perimeter. Firms that combine careful verification with isolated testing and tightly controlled permissions can reduce the opportunity for attackers without abandoning global talent. As digital assets become more integrated into mainstream finance, the hiring desk may become as important to institutional security as the vault.
This article was written with the assistance of an AI system and published automatically.