
Japan, FBI Tie WaterPlum Campaign to Crypto Wallet Theft

Japan, FBI Tie WaterPlum Campaign to Crypto Wallet Theft
WEEX View
- The immediate market focus is whether law enforcement publishes wallet addresses, malware indicators, or exchange-facing alerts that can help platforms block related flows and identify compromised users.
- Exchanges and wallet providers may also need to watch for credential theft and device compromise among employees, contractors, and high-value users, especially where hiring workflows, code tests, or remote interview tools create entry points.
- The report’s reference to a dismantled “laptop farm” points to a broader operational risk: social-engineering campaigns tied to remote IT worker networks can reach both corporate systems and end-user wallets before any on-chain movement becomes visible.
A joint report issued by Japan’s National Cyber Coordination Center, the FBI, the U.S. Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, and Germany’s Federal Intelligence Service said the North Korean hacker group WaterPlum used fake recruitment approaches to infect more than 30,000 devices and steal information from over 7,000 cryptocurrency wallets.
According to the report, WaterPlum primarily targeted IT personnel and carried out attacks disguised as recruitment efforts. Authorities said the campaign sought to steal both confidential information and cryptocurrency assets. The activity covered the period from December 2025 to July 2026 and affected terminals in more than 100 countries and regions, including Japan.
The agencies said the campaign infected more than 30,000 terminals and stole information from more than 7,000 cryptocurrency wallets. They also said at least about 1.7 billion yen, or roughly $10.71 million, in crypto assets was transferred to wallets controlled by the attackers.
Japanese police said they seized and dismantled a “laptop farm” run by local supporters for North Korean IT workers to operate remotely. The Japanese police agency and the FBI assessed that WaterPlum and some North Korean IT workers were directed by the 313 Bureau of the Ministry of National Defense Industry of the Workers’ Party of Korea.
The report also said the group had previously posed as applicants for engineering roles at Japanese crypto exchange bitFlyer. Authorities said no actual employment took place in that case and bitFlyer did not incur losses. That separates the attempted infiltration from the confirmed wallet-related theft and device infections described in the broader campaign.
Fake recruitment and interview lures have become a recurring attack path in crypto-focused cybercrime. Recent security reporting has linked North Korea-related groups to campaigns targeting Web3 developers and crypto industry workers with malicious code, skills tests, and spoofed meeting links designed to compromise devices and harvest credentials or wallet access.
Why It Matters
This case brings together several risks that matter to the crypto industry at once: endpoint compromise, insider-style access attempts, and wallet theft tied to social engineering rather than a direct protocol exploit. That widens the threat model for exchanges, market makers, developers, and wallet users beyond smart-contract security alone.
It also reinforces how cross-border enforcement is increasingly central to crypto crime response when state-linked groups are involved. A coordinated assessment by police, intelligence, and cyber agencies can shape later compliance actions, wallet monitoring, and exchange controls even before a full public accounting of the laundering path emerges.
Milestones
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreVietnam Targets 2026 Crypto Licenses Under Pilot Framework
Vietnam said it expects to license its first crypto asset service providers in 2026 under a pilot framework, while officials discussed regulatory cooperation with Austria's FMA on investor protection, anti-money laundering, and market supervision.
SlowMist Warns FomoPeek iOS App Versions Carried Malicious Code
SlowMist said FomoPeek App versions 1.1 to 1.2 carried malicious code that could expose private keys and other sensitive data on affected iPhones, after users reported stolen assets linked to private key leaks.
Switchboard Says It Will Wind Down Oracle Operations
Switchboard said it is ceasing operations, with maintenance for its oracle implementations ending immediately and remaining support scheduled to end on September 25, prompting protocols to migrate to alternatives including Pyth and RedStone.
Bastion Seeks OCC Trust Charter as Stablecoin Regulation Tightens
Bastion is pursuing an OCC national trust bank charter after earlier reports framed the matter as conditional approval, highlighting growing efforts by crypto infrastructure firms to move stablecoin and custody businesses into a federal oversight framework.




