What happened

Cointelegraph reported that the North Korean group WaterPlum used fake recruiter offers to target developers at crypto, AI and NFT companies. The operation reportedly infected 30,000 devices across more than 100 countries and stole $10.7M in crypto.

Why it matters

The report puts developer-facing hiring activity at the center of a large claimed crypto-theft campaign. For organizations that receive inbound job offers or interview tooling, the account supports treating those interactions as a potential security exposure.

What to watch

The next useful receipt would be the underlying report and independent confirmation of the reported device count, geographic reach and crypto theft.

What to watch

Watch for the underlying report or independent confirmation of the campaign’s reported scale and losses.

Sources and limits

Upstream references and independent checks

Digest dated 2026-09-21 · upstream model sonnet. Direct links are matched to all 1 upstream source IDs.

  1. 1
    North Korean fake recruiters infect 30K devices, steal $10.7M in cryptoDirect upstream source · adff5036af0df9fe7ab717d2f0aa0aaffcff8682

This Research brief was generated by Terra from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: The claims rest on one approved reporting source’s account of an underlying report, which was not supplied.