North Korean hackers no longer steal from exchanges; they’ve shifted to targeting developers who are "job hunting": among 30,000 devices, more than 7,000 encrypted wallets were wiped.
Seven agencies—including Germany’s Federal Intelligence Service (BND) and the Federal Office for the Protection of the Constitution (BfV)—issued a joint warning, calling out the organization WaterPlum, with the activity pointing back to North Korea. What makes this scheme so insidious is that it first masquerades as a legitimate recruiter, sends an attractive high-paying offer, then adds a "programming test" for you to run. Once the code is executed, your computer is remotely taken over and your wallet private keys and seed phrases are scooped up in one go. You think you’re going to an interview, but really you’re being used to send money.
The 30,000 devices and 7,000 wallets are only the portion that has been counted so far. Even more alarming is that it doesn’t rely on vulnerabilities—it relies on the fact that you "open it yourself." Developers looking for work, programmers trying to take on side gigs, and ordinary crypto traders are all becoming victims.
My take: the hackers have moved their targets from "big whales" down to "retail developers," and that’s the most dangerous change. In the past, you might think, "My wallet is small and no one would bother." Now it’s precisely those people who are easiest to trick. During the job-hunting season or for side-gig season—if anything asks you to "run some code first," stop and think.
Who do you think will be targeted next? Chat in the comments. Click the profile to watch the live stream. Every day, I’ll take you through crypto security hotspots—not just what’s happening in the news, but also help you understand the logic and opportunities behind it 👀🚀
💬 你的答案是什么?进群聊
Seven agencies—including Germany’s Federal Intelligence Service (BND) and the Federal Office for the Protection of the Constitution (BfV)—issued a joint warning, calling out the organization WaterPlum, with the activity pointing back to North Korea. What makes this scheme so insidious is that it first masquerades as a legitimate recruiter, sends an attractive high-paying offer, then adds a "programming test" for you to run. Once the code is executed, your computer is remotely taken over and your wallet private keys and seed phrases are scooped up in one go. You think you’re going to an interview, but really you’re being used to send money.
The 30,000 devices and 7,000 wallets are only the portion that has been counted so far. Even more alarming is that it doesn’t rely on vulnerabilities—it relies on the fact that you "open it yourself." Developers looking for work, programmers trying to take on side gigs, and ordinary crypto traders are all becoming victims.
My take: the hackers have moved their targets from "big whales" down to "retail developers," and that’s the most dangerous change. In the past, you might think, "My wallet is small and no one would bother." Now it’s precisely those people who are easiest to trick. During the job-hunting season or for side-gig season—if anything asks you to "run some code first," stop and think.
Who do you think will be targeted next? Chat in the comments. Click the profile to watch the live stream. Every day, I’ll take you through crypto security hotspots—not just what’s happening in the news, but also help you understand the logic and opportunities behind it 👀🚀
💬 你的答案是什么?进群聊
