Job offers in the Web3 industry have led to the loss of millions of dollars in digital assets. A North Korean hacking group known as WaterPlum siphoned funds and credentials from more than 7,000 crypto wallets between December 2025 and July 2026, stealing at least $10.7 million under the guise of fake job postings.
A joint advisory recently published by security authorities in the United States, Japan, Germany, and Australia revealed the cross-continental reach of the cyber infection. The intelligence report detailed that malware distributed by WaterPlum has compromised at least 30,000 computers belonging to workers across more than 100 countries.
Infiltrating via Coding Test Files
The threat group, also known among cybersecurity experts as Contagious Interview, specifically targets individual victims. They set their sights on software developers, web designers, and Web3 specialists actively looking for new gigs on freelance platforms and professional social networks.
The hackers routinely impersonate companies in the crypto, artificial intelligence, or NFT sectors to convince prospective victims. Once applicants respond to the job offer, the attackers move to the execution phase by sending files disguised as coding test assignments. In other scenarios, the perpetrators claim they need help resolving video conferencing software errors to trick targets into downloading malware payloads onto their devices.
Part of the Military Funding Machinery
Joint investigations by intelligence agencies concluded that the WaterPlum network operates strictly under the control of the Munitions Industry Department, an official agency of North Korea’s central government.
The military entity has long been under close scrutiny for its role in deploying and managing revenue generated by North Korean IT workers across overseas projects. This institutional link shows that looting Web3 freelancers’ crypto wallets serves as a key driver for a well-structured foreign revenue generation campaign.
For modern Web3 professionals, technical skills alone no longer guarantee wallet security. When a job interview leads to requests to download unfamiliar software, turning down the offer and severing communication is the safest move before your hard-earned assets vanish entirely.
Source: Cointelegraph.
Read also: Revolut Hacker Demands 6,000 Monero Ransom - 680 Victims Reportedly Picked via On-Chain Analysis
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




