Japan police attribute 10.71 million cryptocurrency theft to North Korean hackers WaterPlum

BlockchainCrypto Coin Show News Team·September 18, 2026·3 min read

Japan’s police agency has publicly identified a North Korean hacking group that stole $10.71 million in cryptocurrency by impersonating tech recruiters and infecting developer devices with malware. The joint attribution with the US, Australia and Germany signals a coordinated escalation in exposing state-sponsored cyber theft targeting the crypto sector.

  • North Korean group WaterPlum stole 1.7 billion yen ($10.71 million) by posing as AI and crypto company recruiters
  • Malware infected over 30,000 devices across 100+ countries from December 2025 to July 2026, compromising 7,000 crypto accounts
  • Japan authorities dismantled a laptop farm used to launder stolen funds back to North Korea, a first in the country
  • $10.71 million in cryptocurrency diverted to North Korea via the WaterPlum operation
  • 30,000+ devices infected with malware across more than 100 countries in eight months
  • 420% spike in blockchain malware since 2016, with significant portion from North Korea

Japan’s National Police Agency, working with the FBI and security agencies in Australia and Germany, has publicly attributed a major cryptocurrency theft operation to North Korean state actors. The group, known as WaterPlum and using the alias “Contagious Interview,” targeted software developers globally by posing as hiring managers at AI firms, crypto startups, and NFT companies. The seven-agency advisory, released Friday (September 18), first reported by Cryptopolitan, describes how the hackers installed malware through fake technical interviews and coding assignments, ultimately stealing $10.71 million and compromising thousands of crypto wallets.

WaterPlum’s fake recruitment scheme infected 30,000 devices in eight months

The operation began with a social engineering vector: attackers posed as recruiters from legitimate technology firms and offered positions to software developers in exchange for completing technical assessments.

Applicants were instructed to download and execute files purportedly needed for the evaluation, but the packages contained multiple strains of malware including BeaverTail, InvisibleFerret, OtterCandy, OtterCookie, and StoatWaffle.

Once installed, the malware created a remote-access backdoor that harvested browser passwords, keystrokes, screenshots, and critically, the private keys and seed phrases required to access cryptocurrency wallets.

Between December 2025 and July 2026, the operation compromised more than 30,000 devices across more than 100 countries and extracted sensitive data from approximately 7,000 cryptocurrency accounts, according to the advisory.

Japan’s first disruption of a North Korean laptop farm breaks the supply chain

A parallel scheme involved North Korean IT workers, some based in China and Russia, obtaining remote development and web programming contracts under false identities. They routed their salaries back to Pyongyang, with hundreds of millions of yen laundered over time through local enablers who operated laptop farms and virtual private servers on North Korean hackers’ behalf.

Japanese authorities disrupted this physical infrastructure for the first time, identifying and shutting down a laptop farm operated by a local collaborator.

The NPA and FBI assessed that the operation falls under the command of the 313 General Bureau of the Munitions Industry Department, a unit of the Central Committee of the Workers’ Party of Korea, meaning the stolen funds directly supported North Korea’s weapons program.

Public attribution follows $6.75 billion in documented North Korean crypto theft since 2016

The joint advisory marks a “public attribution” designed to deter future attacks by naming the state and group responsible.

The WaterPlum operation reflects a broader pattern of North Korean cyber activity targeting digital assets. Since 2016, actors with North Korean links have stolen approximately $6.75 billion in cryptocurrency, a threat serious enough to warrant discussion at the G7 leaders meeting in June 2026.

Malware designed to target public blockchains has spiked 420% during this period, with a substantial portion originating from North Korea and Iran, according to analysis cited in the advisory. Fake job recruitment remains a signature tactic: Black Hat researcher Vangelis Stykas traced North Korean hackers into 1,640 companies across 57 countries using identical methods.

The CCS read. We read the infrastructure angle, not the attribution. The disruption of Japan’s first identified laptop farm suggests law enforcement is moving upstream, targeting the supply chains and money laundering nodes that enable theft, not just naming perpetrators. That operational edge matters more to wallet security than the public naming, however coordinated.

Watch for whether other countries report similar laptop farm discoveries in the coming months, and whether the US Treasury moves to level fresh sanctions on North Korean cyber units following the joint attribution.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe