
Claimed WaterPlum Crypto Theft Campaign Lacks Public Verification

Claimed WaterPlum Crypto Theft Campaign Lacks Public Verification
WEEX View
- The main issue to watch is verification. The reported scale, attribution, and loss figures have not been matched by publicly identifiable security research, law enforcement disclosures, or blockchain-tracing records in the available material.
- The reported attack path matters for exchanges, wallets, and market infrastructure providers because the campaign allegedly targeted developers and IT staff through fake hiring tasks and meeting-related file fixes rather than a direct protocol exploit.
- Further disclosures on malware type, compromised platforms, and how stolen credentials were used would shape the operational impact for wallet security, employee access controls, and custodian-side defenses.
A report claims the North Korean hacker group WaterPlum posed as a recruitment agency targeting cryptocurrency, AI, and NFT firms, infecting 30,000 devices and stealing at least $10.7 million from more than 7,000 crypto wallets between December 2025 and July 2026.
According to the claim, WaterPlum used fake recruiting approaches to reach software developers and IT professionals, presenting malicious files as programming assignments or repairs needed for video conference software. The campaign was said to focus on workers connected to crypto, AI, and NFT companies.
The report described a broad cross-border operation, saying at least 30,000 devices in more than 100 countries were infected. It also said funds or account credentials were extracted from over 7,000 cryptocurrency wallets during the period from December 2025 to July 2026, with total losses of at least $10.7 million.
However, publicly verifiable support for those claims remains limited. Available follow-up checks did not identify a matching public report, law enforcement notice, or mainstream blockchain-analysis record that independently confirms the WaterPlum name, the reported victim scale, or the stated losses.
Separate reporting on other North Korean-linked hacking groups has shown similar social-engineering tactics aimed at crypto industry workers, including fake job offers, technical tests, and fraudulent video meeting prompts used to deliver malware. That background supports the broader threat pattern, but it does not independently confirm the specific WaterPlum claims or establish that the same actors were involved.
Why It Matters
Even without full public verification, the report underscores a persistent risk for the crypto sector: attackers do not need to breach a blockchain network directly if they can compromise the people building, maintaining, or accessing wallets and internal systems. Social-engineering campaigns aimed at developers and technical staff can expose private keys, browser credentials, and privileged corporate access.
The case also highlights a recurring security challenge for the industry’s institutional layer. As crypto firms expand hiring, remote collaboration, and contractor workflows, fake recruitment and meeting-based malware campaigns could become a more effective route into trading, custody, and treasury environments than direct on-chain attacks.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreKalshiEX LLC v. Schuler Opinion Backs Ohio, Tennessee Enforcement
The Sixth Circuit published opinion 26a0272p.06 in Kalshi’s Ohio and Tennessee appeals, with secondary coverage saying the ruling lets both states keep enforcing gambling laws against the sports contracts at issue.
Trung Nguyen Van U.S. Crypto Money Laundering Case
Trung Nguyen Van has been tied in media reports to a U.S. crypto money laundering case linked to alleged pig-butchering fraud, with Western District of Missouri charges and a reported $16 million Triangle victim transfer.
KelpDAO LayerZero Lawsuit Targets rsETH Bridge Exploit
KelpDAO and Evercrest Technologies are reported to have sued LayerZero over the 116,500 rsETH bridge exploit, but no court filing or official party statement was retrieved, leaving the legal details unresolved.
U.S. Spot Bitcoin ETFs and Treasury Buybacks
U.S. spot Bitcoin ETF inflows are being tied to Treasury buybacks, but the confirmed policy was a narrow long-end liquidity tool and the reported ETF surge still lacks a dated, reproducible flow window.



