North Korean Hackers Stole $10.71 Million in Crypto

A multinational advisory revealed a hacking group targeted over 7,000 wallets using AI and sophisticated malware.

Updated on Oct. 3, 2026 in Cybersecurity

Bold flat-color editorial illustration of a jagged crystalline pillar, evoking the cold and systematic nature of international digital asset theft.
North Korean hackers stole over $10.71 million from cryptocurrency wallets between December 2025 and July 2026 using sophisticated AI malware. AI Illustration. Upload story photo >

Live Poll

Do you still trust the legitimacy of remote technical job interviews you encounter online?

Between December 2025 and July 2026, the North Korean hacking group WaterPlum infected more than 30,000 devices across over 100 countries. The group successfully stole approximately $10.71 million from more than 7,000 cryptocurrency wallets.

Why it matters

The hackers specifically target professionals in the crypto, AI, and NFT sectors to infiltrate devices and drain assets. By using AI face-swapping software during fake job interviews, the group maintains a sophisticated front to deploy malware.

WaterPlum infected 30,000 devices using malware families including BeaverTail, InvisibleFerret, and OtterCookie. The hackers leverage AI face-swapping technology during live video calls to pose as recruiters.

The players

WaterPlum

This is a North Korean hacking group that previously operated under the name Contagious Interview.

The details

Operators impersonate recruiters on professional platforms to trick candidates into downloading malicious files under the guise of an interview process. This group, formerly known as Contagious Interview, shares personnel and tactics with broader North Korean remote-IT-worker fraud schemes.

Timeline

  1. The group WaterPlum began operating in 2023.

  2. Malware infections and crypto theft occurred from December 2025 through July 2026.

  3. A joint advisory from five nations was published on September 18, 2026.

The Tech Race

This activity marks an evolution of North Korea's remote-IT-worker fraud scheme by integrating AI-driven deceptive techniques. The group has moved beyond traditional social engineering to adopt advanced face-swapping software, signaling a shift in how threat actors exploit remote work infrastructure.

Users in the tech, crypto, and AI industries should exercise extreme caution during remote job interviews with unknown recruiters. Always verify the identity of interviewers and avoid downloading unsolicited software or files during the hiring process.

The takeaway

The sophisticated nature of these attacks highlights how professional platforms can be manipulated for large-scale financial theft. Individuals should remain vigilant by confirming recruitment offers through official company channels and keeping security software updated.

Further reading

For more on the current threat landscape, visit the Cybersecurity section.

Source note: This article includes information reported by Startup Fortune.

Live Poll

Do you still trust the legitimacy of remote technical job interviews you encounter online?