FBI and Japan NPA Warn of North Korean Crypto Wallet Attacks

2 hour ago 5 sources negative

Key takeaways:

  • North Korea's developer-focused social engineering shifts attacks from exchanges to individual wallet compromise.
  • Over $10.71M stolen may weigh on retail confidence in self-custody despite crypto's decentralization ethos.
  • Bitcoin's irreversible settlement makes pre-attack wallet security a non-negotiable priority for BTC holders.

The U.S. Federal Bureau of Investigation and Japan’s National Police Agency have issued a joint warning about a North Korea-linked campaign targeting cryptocurrency wallets. The alert urges individual holders and crypto-sector organizations to treat unsolicited communications and unverified software as high-risk vectors for asset theft.

Japanese authorities identified the cluster as WaterPlum, also known as Contagious Interview. Between December 2025 and July 2026, the campaign infected more than 30,000 devices and stole wallet-related data from over 7,000 crypto wallets across more than 100 countries. Wallets controlled by the attackers received at least $10.71 million in cryptocurrency, roughly ¥1.7 billion.

The operation primarily targeted IT professionals, developers, blockchain workers, Web3 engineers, and Web designers through fake job offers on social media, job boards, freelance platforms, and gig-work sites. Attackers impersonated cryptocurrency, AI, and NFT companies and recruitment agencies. Victims were asked to complete coding tasks or technical interviews, which led to malware downloads from development platforms and code repositories. The malware families included BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle, capable of stealing passwords, screenshots, keystrokes, clipboard data, private keys, and seed phrases.

The investigation uncovered “laptop farms” operated by North Korean IT workers and local supporters, allowing operatives to hide their identities. The NPA also described a suspicious application to Japanese exchange bitFlyer in May 2025 using stolen identity information and VPN services. Authorities said matching IP addresses link WaterPlum and North Korean IT activity, and both are believed to be connected to Bureau 313, part of North Korea’s Workers’ Party Central Committee.

Law enforcement advised verifying software updates, using hardware wallets, enforcing least-privilege access for signing keys, and conducting high-risk work in virtual machines or isolated environments. Because Bitcoin transactions settle irreversibly, agencies stressed that wallet defenses must be in place before an attack rather than after funds are stolen.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.