OpenAI Gave AI Agents Their Own Computers at DevDay 2026. Here's Everything It Announced
What is an IDO in Crypto? How Initial DEX Offerings Work…
Papertrade, A Perps Exchange That Rewards You For Losing, To Launch On October 10th: X ...
Morgan Stanley is moving deeper onchain, launching an internal lab to test stablecoin...
How to Create a Crypto Faucet: Setup, Revenue Model, and…
Bitwise Launches NEAR ETF With 5% Yield and an AI Bet
Coinbase Lists Concrete Token CT, Transfers Await Approval
MoonPay has launched a South Korean subsidiary, with plans to make it a hub for its
AAVE Price Jumps 16% to $169 as Rally Tests $175 Resistance
Binance Alpha Trading Competition: Trade Doppler Finance (XDP) and Share $200K Worth of Rewards (202...
Trump-related American Bitcoin has lost more than 90% of its value
Zcash Drops 11% to $1,356 as $28.7 Million of Longs Are…
U.S. HOUSE OVERSIGHT EXPANDS PREDICTION MARKET INSIDER TRADING PROBE TO HyperliquidX,...
Kalshi Eyes $1B Raise at $40B Valuation With Sequoia, Wellington
Cboe, S&P Dow Jones may explore tokenized options contracts under extended licensing deal
As $QNT has surged recently, whales that had been dormant for over 3 years are waking up and...
Bitcoin Is Up About 42% This Quarter With Two Days Left,…
Crypto ETFs Surge as Bitcoin Funds Add $2.95 Billion in 30 Days
SlowMist founder Cos stated that cross-chain liquidity protocol Chainflip is indeed making...
50,291,996 $XRP (75,959,870 USD) transferred from #BitGet to unknown wallet...
SEC Releases Crypto Asset FAQs, Federal Reserve Proposes Stablecoin Issuer Rules, CFTC Addresses Tokenized Investments and Mention Markets, Prediction Markets Litigation Advances
Zano Network Stabilizes After 30-Day Blockchain Rewind
Bitcoin Faces Risk as US Credit Card Stress Hits Multi-Year Highs
Aave Proposes Monad V4 Hub for Tokenized Equity Lending
@SECGov adds “no central party” condition to its token buyback...
Bitcoin Surges 35% Since August Low Amid Declining Open Interest
Tether claims $550 million in Iran freezes, but $35 million slipped past Senate
Odds That Variational Launches Its Anticipated TGE Above A $1B Valuation At 63%: Polymarket...
China's top spy agency says crypto anonymity is an "illusion," and users can be TRACED.It ...
Bill Pulte’s tweet cost FICO shareholders $4 billion
Bitcoin ETFs See Significant Inflows Amid Bullish Options Activity
Notice of Removal of Spot Trading Pairs - 2026-10-02Based on our most recent reviews, Binance will r...
FCA Secures £851,000 Recovery Orders For Victims Of £1.5M…
BBC Director-General Deems AI-Generated Doctor Who Episode 'Pretty Good'
Bitwise SPOT $NEAR ETF TRADING GOES LIVE ON NYSE ...
SharpLink Gaming(@Sharplink) staked another 42,074 $ETH($112.8M) today.SharpLink now holds 892,127...
French Firm Capital B Boosts $294M Bitcoin Treasury via Share Offering
Michael Saylor Explains Strategy’s Bitcoin, Debt and Preferred Stock Structure
MistTrack: Bitget Exploiter Attempted to Route Stolen Funds via Chainflip but Broker...
Chainlink LINK Price Rises 14.5% in 7 Days as Traders Watch $18 Resistance
Bitcoin holders are cashing in.Profit-taking hit a 2026 high as Bitcoin rallied to $87.4K. The bull...
$QNT listed on Lighter futures (core)・
Avalanche Achieves $266 Million Growth in Real-World Asset Market Cap
2,433 $BTC (204,200,567 USD) transferred from unknown wallet to unknown wallet...
Anthropic lost $42 billion, warned AI could resist shutdowns, but traders still price it at $2 trillion
US SEC Chair: Financial system is moving toward the crypto era, hopes to put the stock market on-chain
Goldman Sachs Brings Its $100B Treasury Fund to Crypto Without a Token
TRUMP DENIES OFFERING IRAN SANCTIONS RELIEF OR FROZEN FUNDSSAYS AXIOS...
U.S. House Expands Insider Trading Probe to Hyperliquid and Crypto.com
Is the Red September Curse Over? Bitcoin Set for Best September on Record
BUIDL Leads US Treasury Debt RWA Returns With 371.98%
₹146 Crore Hashpe Crypto Scam: Cruise Parties, Bollywood Events And Luxury Cars
AI Agents Can Use Crypto Wallets, but Their Startups Still Need Business Accounts
Fed Governor Barr: Further rate hikes may be needed
Chainlink Unveils CCIP 2.0 at Sibos 2026 to Enhance Institutional Blockchain Adoption
Coinbase Gets CFTC Approval For Its Own Derivatives Clearing House: Blog ...
Jensen Huang, Lisa Su and others appointed to Tsinghua SEM Advisory Board
Bittensor Unveils Roadmap for Decentralized AI Network
NEAR Intents’ SHIELD Blocks Over $50 Million in Stolen Funds from Bitget Breach
BNB Standard Corporation Rebrands Following Community Vote
Prediction Markets Shatter Records With $20 Billion Week
OKX Options Markets Become Available Through Talos Trading…
Top Trending Coins (Today) 1. QNT 2. HBAR 3. FIRO 4. TRUMP 5. NEAR 6. XLM 7. LINK 8. BUN 9. PENGU...
Trump ally Hassett slams Biden: US economy still paying the price for "massive money printing"
Hong Kong SAR Government Issues HK$20 Billion Equivalent Digital Green Bonds Introducing Tokenized HKD Deposits
Analysis: Tokenomics innovation is making a comeback as the crypto industry tries to give tokens "real value"
Ari Paul says Coinbase lost his $25M, covered up $1B in hacks
Coinbase Completes Its Derivatives Stack With CFTC Clearing Approval
Bitcoin Test of $82,500 and Oil’s Impact: Wintermute Issues a Forecast for Bitcoin
North Korean Hackers Targeted IT Professionals with Fake Job Listings and Stole Data from 7,000 Crypto Wallets
- North Korean hackers used fake job postings to steal cryptocurrency.
- They infected 30,000 devices and stole data from 7,000 crypto wallets.
- Specialists from more than 100 countries were among the victims.
Japan’s National Police Agency (NPA), together with the U.S. FBI, as well as Australian and German law enforcement agencies, uncovered the activities of the North Korea-linked cyber group WaterPlum. According to the agencies, from December 2025 to July 2026, the group infected more than 30,000 devices across more than 100 countries and regions with malware and stole data from more than 7,000 cryptocurrency wallets.
Crypto assets worth at least 1.7 billion Japanese yen, or about $10.8 million, were transferred to wallets controlled by WaterPlum.
WaterPlum Disguised Attacks as Job Postings
The group’s primary targets were IT professionals, including web developers, engineers, and specialists in cryptocurrency, blockchain, and Web3. WaterPlum posed as legitimate AI, crypto, and NFT companies or recruiting services and offered candidates attractive job openings.
During interviews or while completing test assignments, victims were asked to download malicious programs from collaboration platforms or code repositories. To distribute malware, the group used, among other things, NPM packages into which it embedded the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle families.
After infection, the attackers installed a backdoor, maintained remote access, and stole sensitive data. The targeted information included:
- Browser credentials
- Keystroke logs, clipboard contents, and screenshots
- Cryptocurrency wallet data, including private keys and seed phrases
- Documents and images of identity documents
According to the NPA and the FBI, WaterPlum and some North Korean IT workers operate under the direction of the 313th General Bureau of the Munitions Industry Department of the Central Committee of the Workers’ Party of Korea.
North Korean IT Workers Used “Laptop Farms”
Law enforcement also, for the first time in Japan, uncovered and dismantled a so-called laptop farm — computers set up in the home of a local intermediary and remotely controlled by North Korean IT workers. According to the NPA, cryptoassets and other funds worth several hundred million yen were transferred abroad through such schemes.
In May 2025, one of the suspects linked to the North Korean IT network also applied for an engineering role at the Japanese crypto exchange bitFlyer. The candidate used a VPN, submitted a resume under another person’s name, and insisted on the option to work remotely and be paid in cryptocurrency. The company spotted suspicious signs during the interview and did not hire him.
Law enforcement notes that the activities of North Korean IT workers may not be limited to earning foreign currency. They may also use access to corporate systems to steal confidential information, source code, and other data.
The NPA recommends that companies minimize contractors’ access to internal systems, verify candidates’ identities and qualifications, and use sandboxes or a restricted mode when working with unverified code. If a device is infected, the agency advises immediately isolating it from the network, and for cryptoassets — creating a new wallet from another device and transferring the funds there.
As a reminder, it recently became known that DPRK-linked groups infiltrated 1,640 companies in 57 countries and hunted for crypto keys.
Сообщение North Korean Hackers Targeted IT Professionals with Fake Job Listings and Stole Data from 7,000 Crypto Wallets появились сначала на INCRYPTED.
Source: Incrypted
