Subscribe Now
Trending News

Blog Post

NORTH KOREA’S FAKE JOB INTERVIEWS JUST DRAINED $11 MILLION FROM 7,000 CRYPTO WALLETS
News

NORTH KOREA’S FAKE JOB INTERVIEWS JUST DRAINED $11 MILLION FROM 7,000 CRYPTO WALLETS 

Quick Summary

  • Japan’s National Police Agency, the FBI, the U.S. DoD Cyber Crime Center, Australia’s ASD and Germany’s BND just signed a JOINT advisory (September 18) warning about a North Korean cyber group called WaterPlum — known to security researchers as "Contagious Interview".
  • The crew infected at least 30,000 devices in more than 100 countries between roughly December 2025 and July 2026, by posing as tech recruiters and running fake job interviews.
  • They drained an estimated $11 million from more than 7,000 crypto wallets.
  • Targets: web designers, engineers and crypto/blockchain/Web3 specialists actively looking for work.
  • This is not a one-off. CertiK attributes 60% of all 2025 crypto theft losses — about $2.06 billion — to North Korea-linked groups.

What Happened

North Korea runs one of the most efficient theft machines on Earth, and its latest trick is insultingly simple: fake a job interview, steal the wallet.

The group impersonates legitimate AI, crypto and NFT companies. They hunt developers on social media, job boards and freelance marketplaces. You get a "technical interview." You get a coding task. You get told to download a file — either to finish the assignment or to "fix a fault" in the video call.

That file is malware. And the machine you run it on is the same machine holding your keys, your browser sessions, your recovery phrases, your life savings in sats.

The advisory, co-signed by Japan’s National Police Agency and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, Australia’s ASD/ACSC, and Germany’s BND and BfV, says the operation is industrial: at least 30,000 devices infected in over 100 countries between December 2025 and July 2026, and more than 7,000 crypto wallets drained of roughly $11 million.

The actors used AI face-swapping during interviews, then cut video and blamed the connection — asking the candidate to do the same. They practiced Japanese pronunciation with text-to-speech tools. They ran "laptop farms" through domestic enablers, with hundreds of millions of yen in crypto moved abroad before Japan dismantled one — the first such case in the country.

Investigators also traced WaterPlum and North Korea’s remote IT workers to the same reporting chain: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party central committee. The fake-recruiter operation and the state’s IT army used the same infrastructure.

North Korea’s hackers have been expanding this playbook for years — they cashed out $30 million in stolen Bitcoin through Hyperliquid earlier this year, and the April 2026 $285 million Drift Protocol heist followed attackers posing as a quantitative trading firm for six months. The fake job interview is just the newest variation on the same theme: they get inside your head, then they get inside your machine.

Why This Matters for Bitcoin

Two $11 million reasons.

First, the victims are not idiots. They are developers, engineers, blockchain specialists — people who understand crypto better than 99% of the population. If a North Korean state cyber unit can drain the wallets of technical people through a job interview, nobody is safe through vigilance alone. Bitcoin doesn’t have a customer support line. There is no chargeback. When your keys are compromised, the coins are gone — permanently, irrevocably, and (in this case) straight into a state’s weapons budget.

Second, this is the exact moment the "Bitcoin is too complicated for normal people" crowd loves to quote. Every one of these thefts is ammunition for the argument that you need a bank, a custodian, a "trusted" middleman to hold your money for you. But look at the actual solution: the money was stolen because victims ran untrusted code on machines that held keys. The fix was never a bank — it’s learning how to hold your own keys safely. Self-custody didn’t fail here; bad custody hygiene failed.

And if you think your exchange "protects" you, remember what happens when the bad guys get the exchange itself — we’ve seen what an exchange cold-wallet crisis does to people who trusted the middleman.

The Love Is Bitcoin Takeaway

The scariest part of this story isn’t the $11 million. It’s that the attack works on technical people, and it will keep working on everyone else.

Bitcoin is the only money you can lose to a single bad download. That’s the cost of being your own bank — and it’s a real cost, not a slogan. The question is how you manage it:

  • Your keys should never live on the machine you use for browsing, email, job hunting or interviews. A hardware wallet or a properly air-gapped setup means a compromised laptop is an inconvenience, not a catastrophe.
  • Never run code or install files from strangers in a "recruitment" process — no matter how legit the company looks. A real employer will never need you to install a debugger for a video call.
  • Treat "opportunities" that feel too good as hostile. A recruiter reaching out of nowhere with a paid coding task, who refuses in-person meetings, asks to be paid in crypto, and keeps glancing at a second screen, is not a headhunter. It’s an adversary doing reconnaissance.

Bitcoin doesn’t protect you from stupidity — it punishes it, instantly and irreversibly. That’s why the education matters as much as the technology. Read our beginner guide to self-custody before you stack another sat, and treat every unsolicited "opportunity" like the attack vector it probably is.

What Beginners Should Do Next

  • Never store meaningful Bitcoin on an internet-connected device. Get a hardware wallet or a cold-storage setup and keep the recovery phrase physically offline.
  • If you’re job hunting in tech, assume every unsolicited recruiter is hostile until proven otherwise. Verify the company on its actual domain, call their listed office number, and never install software for an interview.
  • Keep your work machine and your money machine separate. One laptop for interviews and browsing, one (air-gapped or hardware-secured) for your stack.
  • Watch the red flags the advisory lists: refusing in-person meetings, implausibly broad skills on a candidate’s resume (for the exchange side), asking to be paid in crypto, and glancing at a second screen during calls.
  • Never share keys, seed phrases, or screenshots of your wallet to "verify" anything. No legitimate employer, exchange, or government will ever ask.

FAQ

Is Bitcoin being hacked, or are users being hacked?
Users. The network hasn’t been compromised — victims ran North Korean malware planted through fake interviews and lost their own keys. That’s the difference between Bitcoin failing and people failing.

How did the attackers steal from 7,000 wallets?
Via malware disguised as interview tasks. Once installed, it harvested browser sessions, wallet files and credentials from the victim’s machine.

Is my exchange account safe?
You’re only as safe as the entity holding your coins — and exchanges are the juiciest targets on Earth. Look at the Coinbase AWS outage and every other exchange horror story. Not your keys, not your coins.

Should I stop applying for remote tech jobs?
No — just treat your computer like the attack surface it is. Separate money machines from work machines, don’t run untrusted files, and verify everything.

How much has North Korea stolen in total?
CertiK attributes 60% of 2025’s crypto theft losses — around $2.06 billion — to North Korea-linked groups. This fake-interview operation is just the latest line item on a very long invoice.

Is this financial advice?
No. This article is for education only and is not financial advice.

Final Thoughts

A state with nuclear weapons is running fake job interviews to empty people’s wallets, and the Western response is a joint advisory. No arrests, no sanctions that matter, no relief for the 7,000 people who lost everything — just a PDF telling you to be careful.

Meanwhile the machines keep stacking, the exchanges keep holding, and the scammers keep interviewing.

So here’s the question, and I want you to answer it in the comments: if the FBI, the NPA and the BND can’t stop them, what makes you think your exchange can — and how many more wallets have to be drained before you move your stack to keys only you control?

⚡ Buy the tools to hold your own keys with the coupon code LOVEISBITCOIN at loveisbitcoin.com/bull

Source: Decrypt reporting on the joint advisory by Japan’s NPA, the FBI, the U.S. DoD Cyber Crime Center, ASD and German intelligence — read the full report here.

Previous

NORTH KOREA'S FAKE JOB INTERVIEWS JUST DRAINED $11 MILLION FROM 7,000 CRYPTO WALLETS

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal