
Claimed WaterPlum Crypto Theft Campaign Lacks Public Verification

Claimed WaterPlum Crypto Theft Campaign Lacks Public Verification
WEEX View
- The main issue to watch is verification. The reported scale, attribution, and loss figures have not been matched by publicly identifiable security research, law enforcement disclosures, or blockchain-tracing records in the available material.
- The reported attack path matters for exchanges, wallets, and market infrastructure providers because the campaign allegedly targeted developers and IT staff through fake hiring tasks and meeting-related file fixes rather than a direct protocol exploit.
- Further disclosures on malware type, compromised platforms, and how stolen credentials were used would shape the operational impact for wallet security, employee access controls, and custodian-side defenses.
A report claims the North Korean hacker group WaterPlum posed as a recruitment agency targeting cryptocurrency, AI, and NFT firms, infecting 30,000 devices and stealing at least $10.7 million from more than 7,000 crypto wallets between December 2025 and July 2026.
According to the claim, WaterPlum used fake recruiting approaches to reach software developers and IT professionals, presenting malicious files as programming assignments or repairs needed for video conference software. The campaign was said to focus on workers connected to crypto, AI, and NFT companies.
The report described a broad cross-border operation, saying at least 30,000 devices in more than 100 countries were infected. It also said funds or account credentials were extracted from over 7,000 cryptocurrency wallets during the period from December 2025 to July 2026, with total losses of at least $10.7 million.
However, publicly verifiable support for those claims remains limited. Available follow-up checks did not identify a matching public report, law enforcement notice, or mainstream blockchain-analysis record that independently confirms the WaterPlum name, the reported victim scale, or the stated losses.
Separate reporting on other North Korean-linked hacking groups has shown similar social-engineering tactics aimed at crypto industry workers, including fake job offers, technical tests, and fraudulent video meeting prompts used to deliver malware. That background supports the broader threat pattern, but it does not independently confirm the specific WaterPlum claims or establish that the same actors were involved.
Why It Matters
Even without full public verification, the report underscores a persistent risk for the crypto sector: attackers do not need to breach a blockchain network directly if they can compromise the people building, maintaining, or accessing wallets and internal systems. Social-engineering campaigns aimed at developers and technical staff can expose private keys, browser credentials, and privileged corporate access.
The case also highlights a recurring security challenge for the industry’s institutional layer. As crypto firms expand hiring, remote collaboration, and contractor workflows, fake recruitment and meeting-based malware campaigns could become a more effective route into trading, custody, and treasury environments than direct on-chain attacks.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreBasedApp Data Breach Exposes KYC Data and Wallet Links
BasedApp data breach reports point to exposed KYC records tied to wallet addresses, while key details on user count, backend access, asset impact, and remediation remain unresolved.
JPYC Explains Stablecoin Payment Competition to Japan's Fair Trade Commission
JPYC reportedly briefed Japan
Core Lightning v26.06.9 Fixes Payment and Throttling Bugs
Core Lightning v26.06.9 was released on 2026-10-07 with fixes for a 26.06.8 throttling regression, a payment shutdown edge case, and added configuration and authorization hardening.
DWF Maas BitGo London Claim Centers on $141 Million Dispute
DWF Maas is reported to have sued BitGo in London for $141 million over alleged early token sales, but no matching public court record, case number, or BitGo response has been identified.



