
Claimed WaterPlum Crypto Theft Campaign Lacks Public Verification

Claimed WaterPlum Crypto Theft Campaign Lacks Public Verification
WEEX View
- The main issue to watch is verification. The reported scale, attribution, and loss figures have not been matched by publicly identifiable security research, law enforcement disclosures, or blockchain-tracing records in the available material.
- The reported attack path matters for exchanges, wallets, and market infrastructure providers because the campaign allegedly targeted developers and IT staff through fake hiring tasks and meeting-related file fixes rather than a direct protocol exploit.
- Further disclosures on malware type, compromised platforms, and how stolen credentials were used would shape the operational impact for wallet security, employee access controls, and custodian-side defenses.
A report claims the North Korean hacker group WaterPlum posed as a recruitment agency targeting cryptocurrency, AI, and NFT firms, infecting 30,000 devices and stealing at least $10.7 million from more than 7,000 crypto wallets between December 2025 and July 2026.
According to the claim, WaterPlum used fake recruiting approaches to reach software developers and IT professionals, presenting malicious files as programming assignments or repairs needed for video conference software. The campaign was said to focus on workers connected to crypto, AI, and NFT companies.
The report described a broad cross-border operation, saying at least 30,000 devices in more than 100 countries were infected. It also said funds or account credentials were extracted from over 7,000 cryptocurrency wallets during the period from December 2025 to July 2026, with total losses of at least $10.7 million.
However, publicly verifiable support for those claims remains limited. Available follow-up checks did not identify a matching public report, law enforcement notice, or mainstream blockchain-analysis record that independently confirms the WaterPlum name, the reported victim scale, or the stated losses.
Separate reporting on other North Korean-linked hacking groups has shown similar social-engineering tactics aimed at crypto industry workers, including fake job offers, technical tests, and fraudulent video meeting prompts used to deliver malware. That background supports the broader threat pattern, but it does not independently confirm the specific WaterPlum claims or establish that the same actors were involved.
Why It Matters
Even without full public verification, the report underscores a persistent risk for the crypto sector: attackers do not need to breach a blockchain network directly if they can compromise the people building, maintaining, or accessing wallets and internal systems. Social-engineering campaigns aimed at developers and technical staff can expose private keys, browser credentials, and privileged corporate access.
The case also highlights a recurring security challenge for the industry’s institutional layer. As crypto firms expand hiring, remote collaboration, and contractor workflows, fake recruitment and meeting-based malware campaigns could become a more effective route into trading, custody, and treasury environments than direct on-chain attacks.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreJapan 10-Year JGB Yield Jumps After BOJ Tightening Signal
Japan
Bank of Russia Mutual Fund Crypto Rules Expand Indirect Access
The Bank of Russia reportedly widened mutual fund access to crypto-related instruments, but the exact rule text, investor scope, and reported 10% and 20% limits remain unclear from available documentation.
Hut 8 Poolin Texas Sites Bid Awaits Court Approval
Hut 8 was reported as the winning bidder for Poolin’s Texas sites at $140 million, but Poolin’s Chapter 11 sale still faces a September 29 court hearing in New Jersey.
Kalshi Denies Formal CFTC Investigation Into Trading Activity
Kalshi says the CFTC has not contacted the company and it does not believe it faces a formal investigation, while no public CFTC filing currently confirms a September 24 enforcement case.



