North Korea's WaterPlum Hackers Steal $10.71 Million from Developers
North Korea's WaterPlum hackers have been linked to a massive cryptocurrency heist that saw them steal $10.71 million from at least 30,000 devices in over 100 countries.
The group, which is tied to North Korea's 313 General Bureau, used fake job postings and coding tests on social media and online platforms to lure developers into running malicious code.
According to a joint advisory from several agencies, including the FBI and Japan's National Police Agency, WaterPlum used malware such as BeaverTail, InvisibleFerret, OtterCookie, and StoatWaffle to steal sensitive data, including wallet private keys and seed phrases.
The group moved at least $10.71 million in cryptocurrency assets to North Korea between December 2025 and July 2026, with over 7,000 crypto wallets compromised.
Experts warn that developers should be cautious when running code from unfamiliar repositories or installing fixes sent mid-call, as this can compromise sensitive data.