North Korea's Fake Recruiters Stole $10.7M and Hit 30,000 Devices: Your Job Offer Could Be the Exploit
WaterPlum impersonated hiring managers at crypto, AI and NFT companies, planting malware on 30,000 devices across more than 100 countries and draining $10.7 million. The real lesson isn't about code, it's about the humans running it.
Can you spot a fake recruiter? Most crypto developers think they can. North Korea's WaterPlum just proved otherwise.
The crew built fake job listings at crypto, AI and NFT companies. They posed as hiring managers. They sent coding challenges and interview prep files. Developers opened them. Then 30,000 devices across more than 100 countries got infected. The haul was $10.7 million in crypto.
That's the story in three sentences. The rest is detail, and the detail is what should worry you.
The Raw Numbers
Let's count what we know. Thirty thousand infected machines. Over one hundred countries. And a dollar figure with $10.7 million attached to it.
Break that down. Thirty thousand devices is more machines than the combined full-time engineering staff at every major L1. Some of those laptops belonged to people working inside exchanges, bridges and DeFi protocols. That isn't a guess.
That's the whole point of the attack. You don't go after the vault. You go after the person holding the keys to it.
The $10.7 million is the number that deserves scrutiny. It's what's been traced and confirmed. Malware that sits on a machine for weeks does more than drain one wallet. It logs keystrokes. It grabs seed phrases. It screenshots password managers and pivots into internal Slack threads. Real damage rarely shows up in one transaction.
So what's the actual cost? Probably several multiples of that figure. Nobody wants to publish the real one.
This Isn't New, It's Scaling
Historically speaking, North Korean crews have run this playbook since at least 2017. Lazarus. AppleJeus. The fake crypto trading firm that lured hundreds of engineers with promises of remote work and paid interviews.
What's changed is volume. Thirty thousand devices isn't a targeted operation. That's an assembly line.
And here's the uncomfortable part. Crypto built an entire security stack around smart contracts. Audits. Bug bounties. Formal verification. Multisig treasuries. We hardened the code. We left the humans wide open.
Look at the track record. The biggest losses of the last two years didn't come from a broken curve or a reentrancy bug. They came from someone clicking a link, signing a request, or running a test task from a recruiter promising a $180,000 salary and equity.
So the question isn't whether your code is safe. It's whether the person maintaining it's.
That's a hard thing to hear if you're a solo dev building in a basement. It's harder to hear if you're a CTO at a bridge with $400 million locked in a contract.
What Security Researchers Are Watching
According to incident reporting floating around threat intel circles, the WaterPlum loader is modular. That matters. The same infection can be repurposed. A keylogger today. A clipboard hijacker tomorrow. A poisoned package in a dependency manager next month.
Analysts tracking the flow say the laundering pattern is familiar. Funds move through mixers, then bridges, then OTC desks that don't ask many questions. The $10.7 million isn't parked in one address waiting to be frozen. It's already moving.
Chainalysis and similar firms will trace what they can. But tracing isn't recovery. Once a seed phrase leaves a laptop, the money is gone. The invalidation point sits at the moment of infection, not the moment of withdrawal. That's the brutal math on this class of crime.
And the industry keeps treating it as a footnote. Read any post-mortem after a major exploit. The human element gets one paragraph. The code review gets ten. That's backwards, and attackers know it.
Here's a second hot take. Most crypto teams still don't run endpoint detection on developer machines. They'll spend $50,000 on an audit and zero on the laptop the audited code was written on. That's not security. That's theater.
What's Next
Watch the hiring pipeline. If a recruiter you've never met sends an executable, a zipped project, or a private repo link that needs a login to preview, treat it as hostile until proven otherwise. That isn't paranoia. That's the current threat model.
Watch the identity layer. Zero-trust tooling, hardware keys, isolated build environments, hardware wallets that never touch a general-purpose machine. Demand for that stuff is going to spike. Some of it shows up in token prices for security-focused protocols. Some of it shows up in exchange budget lines after boards finally accept that employees are the perimeter.
Watch the regulatory side too. Expect more scrutiny on job platforms, more KYC pressure on OTC desks, and more coordinated seizures from agencies working alongside blockchain forensics firms. These pushes always arrive in waves after a freshened headline. This one qualifies.
And watch the count. Thirty thousand devices today. The same crew with the same tooling could reach 300,000 without much added effort. Cost scales slower than revenue in this business. That's the economics of it. North Korea found a model with better margins than most legitimate crypto startups.
The chart is the chart for price. This is a different chart, and it's pointed up and to the right for the wrong people.
Your move is simple. Verify the recruiter. Sandbox the file. Keep the seed phrase offline. Do the boring thing. The boring thing keeps you solvent.
Explore More
Key Terms Explained
A distributed database where transactions are grouped into blocks and linked together cryptographically.
A protocol that lets you move tokens between different blockchains.
Ownership stake in a company, represented as shares of stock.
A marketplace where cryptocurrencies are bought and sold.