North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests

2 hours ago 2



Seven agencies from four countries published a joint advisory on September 18, 2026, and it carries a finding that matters to anyone who holds their own keys: a North Korean threat group has used fake job offers to infect at least 30,000 machines in more than 100 countries, draining balances or credentials from over 7,000 crypto wallets. The signatories include Japan's National Police Agency and the FBI, alongside Germany's foreign intelligence service, the Bundesnachrichtendienst, and its domestic security agency, the Bundesamt für Verfassungsschutz. The short answer to what you should do about it fits in a single sentence: keep the machine on which you run other people's code strictly separate from the machine that holds your keys. The rest of this article explains why that particular separation works, which malware families the agencies name, and how to spot the bait before you open anything. What the joint advisory of September 18, 2026 establishes The agencies track the group under the name “WaterPlum”. In the security industry the same group usually goes by “Contagious Interview”, named after its method: the job interview that infects. This advisory carries more weight than a...

Read Entire Article