Multinational agencies warn North Korean hackers are using fake job offers to compromise devices

AI Market Summary
A multinational law-enforcement alert says North Korea-linked WaterPlum used fake AI/crypto/NFT job offers to distribute malware, infecting 30,000+ devices and compromising 7,000+ crypto wallets, with at least $10.71m traced to attacker-controlled addresses. The disclosure reinforces operational and counterparty risk across the crypto ecosystem, likely tightening security posture for developers, exchanges, and wallet providers and weighing on near-term risk sentiment.
Impact level
● Medium
Affected assets
BTC/USDT-1.11%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A joint international alert from agencies including the U.S. Federal Bureau of Investigation (FBI) and Japan's National Police Agency (NPA) warns that the North Korea-linked hacking group WaterPlum, also known as "Contagious Interview", targeted IT developers worldwide between December 2025 and July 2026. According to Forbes, the group impersonated companies in the AI, cryptocurrency, and NFT sectors and advertised bogus roles to lure candidates. Victims were approached through social media and recruitment platforms and were persuaded to download malware disguised as materials for technical interviews or coding tests. The advisory says more than 30,000 devices across over 100 countries and regions were infected. Data was stolen from over 7,000 cryptocurrency wallets, and at least $10.71 million flowed into wallets controlled by the attackers.