Skip to content

Invest1 publisher3 min readPublished

Seven agencies price North Korea's fake-recruiter funnel at $1,530 a wallet

Japan, the US, Australia and Germany put eight months of North Korea's developer-targeting campaign at $10.71 million taken from more than 7,000 wallets. CertiK counted $2.06 billion of North Korea-linked crypto theft in 2025 alone.

The Investor · Invest desk

Illustration accompanying Seven agencies price North Korea's fake-recruiter funnel at $1,530 a wallet

What happened

  • Seven agencies in Japan, the United States, Australia and Germany signed a joint advisory published on September 18 on a North Korean crew that poses as recruiters to compromise developers.
  • The crew, called WaterPlum by Japan's National Police Agency and Contagious Interview by the security industry, infected at least 30,000 devices in more than 100 countries from roughly December 2025 to July 2026.
  • Japanese authorities dismantled a laptop farm run by a domestic enabler, the first such case in the country, and found evidence that several hundred million yen in crypto had moved abroad.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure At about $1,530 a wallet, the campaign pays for itself on volume, so the firms newly reachable are the ones whose contractors hold keys on machines the employer does not administer.
  • decision Recruiters and security teams are now screening for the same bureau: the shared IP addresses mean a rejected applicant and a malicious coding task can come from one payroll. Hiring falls under the same review as endpoints.
  • constraint With StoatWaffle hidden in blockchain-themed repositories, the standard interview step of cloning a repo to finish an assignment can no longer be run on a machine with production access.
  • contradiction The advisory's traced total is a fraction of one Drift-sized loss, so a firm that treats $10.71 million as its worst case is pricing the funnel and ignoring the single relationship that reaches a treasury.

Divide the traced money by the victims and the operation looks cheap. The $10.71 million moved to North Korea works out at roughly $1,530 for each of the more than 7,000 wallets the crew took funds or credentials from. Per machine it is about $357, across the at least 30,000 infected devices [4] [3] [1] [2]. Across the roughly eight months from December 2025 to July 2026, the run rate is about $1.34 million a month against some 3,750 new infections a month [4]. Under one machine in four produced a wallet worth draining [3].

Set that against the prior year. CertiK attributed 60% of all crypto theft losses in 2025, some $2.06 billion, to North Korea-linked groups [16]. The whole eight-month campaign the seven agencies documented comes to about half a percent of that [5]. April's $285 million Drift Protocol hack, which followed six months of attackers posing as a quantitative trading firm, was roughly 27 times the entire WaterPlum total [17] [6].

So the wallets are the small half of the take. The advisory counts credentials alongside funds [4]. The approach that harvests them is a job application: actors impersonate AI, crypto or NFT companies and reach developers through social media, job boards and freelance marketplaces, then set a technical interview or coding task requiring downloads from developer platforms [6]. Of the five malware families named, StoatWaffle hides in blockchain-themed repositories [7].

Japan's National Police Agency and the FBI assess that both WaterPlum and some of North Korea's remote IT workers report to the 313 General Bureau of the Munitions Industry Department. That bureau sits under the Workers' Party central committee [8]. The two used the same IP addresses to reach laptop farms, use crowdsourcing services and apply for jobs, which the agencies treat as evidence they are one operation [9]. The Defense Department's Cyber Crime Center said in a post on September 18 that the group is "compromising job seekers' computer networks, harvesting sensitive data, and stealing cryptocurrency - targeting IT professionals in Japan, U.S., Europe, and beyond" [18].

Japanese authorities dismantled a laptop farm run by a domestic enabler, the first such case in the country, and found evidence that several hundred million yen in crypto had moved abroad [12]. A laptop farm is usually an enabler's home, where work computers are run remotely by IT workers in North Korea, China or Russia [13]. A Japanese crypto exchange turned away an applicant in May 2025 whose resume claimed implausibly broad skills and whose English did not match the record [14].

The crew's own costs are thin. Members used AI face-swapping in interviews before cutting video and asking the candidate to do the same, blaming the connection [10]. They practised Japanese pronunciation with text-to-speech tools and worked consistently on free machine-translation and AI tiers. On North Korean holidays they played games and watched soccer videos instead of running operations [11].

In my view the figure a crypto-exposed firm should price is the $285 million one, since the route in was the same months-long impersonation [17]. What would make that wrong: $10.71 million being close to the true total, with most of the 30,000 machines freelancers' personal laptops that had no path to corporate keys [3]. In that case the campaign is a tax on individual developers, and the money spent hardening hiring pipelines is misallocated.

What to watch

  • Further laptop-farm enabler prosecutions in Japan, or a first case in Australia or Germany, both advisory signatories.
  • Whether developer platforms purge the blockchain-themed repositories carrying StoatWaffle that the advisory names.
  • Whether exchanges start disclosing rejected-applicant cases of the kind the Japanese exchange logged in May 2025.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories