🔍 Interview questions ask you to run some code. After you finish, your wallet is empty.
On September 18, Japan’s National Police Agency, the FBI, the U.S. Department of Defense Cyber Crime Center, along with intelligence agencies from Australia and Germany, and other parties issued a joint advisory. The organization is called WaterPlum, and the more familiar name in the industry is Contagious Interview. A contagious interview.
The numbers are not small. At least 30,000 devices were infected across more than 100 countries, from December 2025 to July 2026. Funds or account credentials from more than 7,000 encrypted wallets were stolen. Crypto assets worth 1.7 billion yen (about $10.71 million) were sent back to North Korea.
The method is straightforward. Impersonating recruiters from AI, crypto, and NFT companies, they look for people on social platforms, job sites, and freelancer markets. The targets are Web3 and blockchain developers. It’s roughly one technical interview, and then they have the candidate download a file—supposedly to complete a coding assignment, or to “just quickly fix” the error shown in a video.
That file contains five malicious malware families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. StoatWaffle hides in blockchain-themed code repositories.
One steals browser credentials. One installs a persistent backdoor. One installs remote-control software and then strikes once the victim opens the wallet.
The real losses are more than just the wallet. The advisory says infecting a developer machine is equivalent to getting an entry point into the employer’s internal network; after that come source code theft and lateral movement. Stolen passport-style photos can also be used by North Korea’s IT workers to impersonate people and win more outsourcing jobs.
The interviewer side might also be fake. Members use AI face-swap software to join video interviews, then turn off the camera under the pretext of bad network conditions—so the candidate follows suit. They use a text-to-speech tool to practice Japanese pronunciation. These are key identifiers: refusing face-to-face chat, requiring payment in cryptocurrency for wages, and repeatedly glancing at a second monitor during the interview. In May 2025, a Japanese exchange rejected an applicant because the skills on their resume were “too broad,” and their English proficiency didn’t match what their CV implied.
The scale is huge. CertiK attributes the $2.1 billion in 2025 crypto theft losses—plus 60% of the year’s share—to North Korea-related groups. The first half of 2026 is $643 million. Of the $285 million that Drift Protocol lost in April, the attackers had first posed as a quantitative trading company for six months.
My view: this “competition” isn’t happening on-chain. Hardware wallets, multisig, and cold storage do nothing along this path. Nobody cracks private keys. Instead, the person holding the private keys runs the code themselves—inside the “interview.”
Three action items. Have interviewers run code in a clean virtual machine or a cloud host—don’t use your everyday machine. Keep your work email and development environment separate from your wallet. Treat any executable files, scripts, and npm/pip dependencies in the interview assignment as malware first.
When I wrote this, the four BTC quote sources were between 84,435 and 84,455, down 2.1% over 24 hours. ETH at 2,685, down 2.7%. SOL down 3%, XRP down 4.7%, DOGE down 7.8%. Higher-beta coins fell even harder, unrelated to this advisory.
Watch two things. The “laptop farm” that Japan took down was the first case—how many are there after that? The next entry point for large-scale theft: will it be via contracts or via interviews.
$BTC $ETH
#中本聪国际社区Baoluo币商资本 #Bitcoin #加密安全
On September 18, Japan’s National Police Agency, the FBI, the U.S. Department of Defense Cyber Crime Center, along with intelligence agencies from Australia and Germany, and other parties issued a joint advisory. The organization is called WaterPlum, and the more familiar name in the industry is Contagious Interview. A contagious interview.
The numbers are not small. At least 30,000 devices were infected across more than 100 countries, from December 2025 to July 2026. Funds or account credentials from more than 7,000 encrypted wallets were stolen. Crypto assets worth 1.7 billion yen (about $10.71 million) were sent back to North Korea.
The method is straightforward. Impersonating recruiters from AI, crypto, and NFT companies, they look for people on social platforms, job sites, and freelancer markets. The targets are Web3 and blockchain developers. It’s roughly one technical interview, and then they have the candidate download a file—supposedly to complete a coding assignment, or to “just quickly fix” the error shown in a video.
That file contains five malicious malware families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. StoatWaffle hides in blockchain-themed code repositories.
One steals browser credentials. One installs a persistent backdoor. One installs remote-control software and then strikes once the victim opens the wallet.
The real losses are more than just the wallet. The advisory says infecting a developer machine is equivalent to getting an entry point into the employer’s internal network; after that come source code theft and lateral movement. Stolen passport-style photos can also be used by North Korea’s IT workers to impersonate people and win more outsourcing jobs.
The interviewer side might also be fake. Members use AI face-swap software to join video interviews, then turn off the camera under the pretext of bad network conditions—so the candidate follows suit. They use a text-to-speech tool to practice Japanese pronunciation. These are key identifiers: refusing face-to-face chat, requiring payment in cryptocurrency for wages, and repeatedly glancing at a second monitor during the interview. In May 2025, a Japanese exchange rejected an applicant because the skills on their resume were “too broad,” and their English proficiency didn’t match what their CV implied.
The scale is huge. CertiK attributes the $2.1 billion in 2025 crypto theft losses—plus 60% of the year’s share—to North Korea-related groups. The first half of 2026 is $643 million. Of the $285 million that Drift Protocol lost in April, the attackers had first posed as a quantitative trading company for six months.
My view: this “competition” isn’t happening on-chain. Hardware wallets, multisig, and cold storage do nothing along this path. Nobody cracks private keys. Instead, the person holding the private keys runs the code themselves—inside the “interview.”
Three action items. Have interviewers run code in a clean virtual machine or a cloud host—don’t use your everyday machine. Keep your work email and development environment separate from your wallet. Treat any executable files, scripts, and npm/pip dependencies in the interview assignment as malware first.
When I wrote this, the four BTC quote sources were between 84,435 and 84,455, down 2.1% over 24 hours. ETH at 2,685, down 2.7%. SOL down 3%, XRP down 4.7%, DOGE down 7.8%. Higher-beta coins fell even harder, unrelated to this advisory.
Watch two things. The “laptop farm” that Japan took down was the first case—how many are there after that? The next entry point for large-scale theft: will it be via contracts or via interviews.
$BTC $ETH
#中本聪国际社区Baoluo币商资本 #Bitcoin #加密安全
