North Korea's WaterPlum crew just got exposed by a 4-country intel coalition (Japan, US, Australia, Germany) — and the numbers are brutal.
30,000+ machines compromised across 100+ countries since Dec 2024. 7,000+ crypto wallets drained. At least $10.71M funneled into DPRK-controlled addresses.
Their playbook? Fake job interviews. They social-engineer devs into running malicious code during "technical assessments," then siphon wallet seeds, session tokens, and network access in one move.
Japan just seized its first Laptop Farm tied to this op — basically a remote workforce shell game run by NK operatives.
If you're:
• Freelancing or interviewing remotely → never run unknown code on a machine with hot wallets or prod access
• Hiring devs → red flags include crypto-only payment, no video calls, overly generic resumes, refusal to meet IRL
This isn't FUD. This is state-level social engineering targeting the exact people building and holding crypto infra.
Stay paranoid.
30,000+ machines compromised across 100+ countries since Dec 2024. 7,000+ crypto wallets drained. At least $10.71M funneled into DPRK-controlled addresses.
Their playbook? Fake job interviews. They social-engineer devs into running malicious code during "technical assessments," then siphon wallet seeds, session tokens, and network access in one move.
Japan just seized its first Laptop Farm tied to this op — basically a remote workforce shell game run by NK operatives.
If you're:
• Freelancing or interviewing remotely → never run unknown code on a machine with hot wallets or prod access
• Hiring devs → red flags include crypto-only payment, no video calls, overly generic resumes, refusal to meet IRL
This isn't FUD. This is state-level social engineering targeting the exact people building and holding crypto infra.
Stay paranoid.


