North Korea's WaterPlum hacking crew drains $11 million from 7,000 wallets

Recent investigations by a coalition of seven agencies have revealed a troubling connection between North Korea's WaterPlum hacking group and its remote IT worker scheme. These findings indicate that the hacking crew has reportedly drained $11 million from approximately 7,000 cryptocurrency wallets, highlighting the ongoing cyber threats emanating from the regime. The advisory underscores how these fraudulent job interviews were part of a broader strategy to exploit the global cryptocurrency landscape.
In the context of North Korea's persistent efforts to circumvent international sanctions, the hacking operations have evolved in sophistication. The WaterPlum group has been linked to various cybercriminal activities, including phishing and ransomware attacks, aimed at generating revenue for the regime. The remote IT worker scheme, which ostensibly offers jobs to international candidates, serves as a front for gathering sensitive information and targeting crypto assets.
This news is significant for the cryptocurrency market as it raises concerns about security and the integrity of digital assets. The revelation that such a large sum was siphoned from wallets through deception could lead to increased scrutiny on exchanges and wallet providers. Investors may become more cautious, potentially impacting trading volumes and market stability. Additionally, the incident emphasizes the need for stronger security measures within the crypto ecosystem to protect against sophisticated cyber threats.
Industry experts have expressed alarm over the implications of these findings. Analysts suggest that the connection between the hacking group and the remote worker scheme could lead to more coordinated and aggressive attacks on the cryptocurrency sector. Some experts are advocating for enhanced collaboration between governments and private sector entities to improve cybersecurity protocols and track illicit activities more effectively.
Looking ahead, the focus will likely shift to how regulatory bodies respond to these revelations. There may be increased efforts to tighten regulations surrounding cryptocurrency exchanges and wallet security in light of the identified vulnerabilities. Moreover, continued investigations into North Korea's cyber activities could yield further insights into the methods used by state-sponsored hackers, prompting a reevaluation of current security practices across the industry.
CoinMagnetic Team
Crypto investors since 2017. We trade with our own money and test every exchange ourselves.
Updated: September 2026
From our insights:
Related news

Coinbase traced $1.1 million crypto trail behind AI phishing service EvilTokens

FomoPeek app exploits iOS vulnerabilities in $580K crypto theft, SlowMist reports

Coldcard exploit sees white hats secure 52 Bitcoin for victims' trust

Whitehats move 52 bitcoin from the Coldcard hack to a recovery trust

Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks
