Global alert issued as North Korean hackers exploit coding tests in fake job offers to steal from thousands of crypto wallets.

Global Cyber Alert: North Korean Hackers Exploit Coding Tests to Target Crypto Wallets
In a stark warning issued on September 18, 2026, a coalition of seven international agencies, including the FBI and Japan's National Police Agency, revealed a sophisticated cyber campaign orchestrated by a North Korean threat group known as "WaterPlum" (also referred to as "Contagious Interview"). This operation, active between December 2025 and July 2026, has compromised at least 30,000 machines in over 100 countries, resulting in the theft of assets and credentials from more than 7,000 cryptocurrency wallets, amounting to an estimated $10.71 million USD.
The "Contagious Interview" Scheme: A Trojan Horse for Hackers
The modus operandi of WaterPlum is particularly insidious, preying on individuals seeking employment in the lucrative tech and cryptocurrency sectors. The hackers pose as recruiters from legitimate companies, initiating contact through social media, job boards, and freelance platforms. The bait? Attractive job offers in fields like AI, NFTs, and blockchain development.
The cybercriminals meticulously guide potential victims through a seemingly standard hiring process, often employing AI-assisted face-swapping for video calls to enhance their deception. The critical juncture arrives during the technical interview or coding test phase. Candidates are instructed to download and execute files, ostensibly for the assignment or to resolve supposed technical glitches in communication tools. However, these files are malicious, serving as the entry point for malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
The malware families are designed to grant attackers remote access, steal credentials stored in browsers, capture keystrokes and screenshots, and, most crucially for crypto holders, extract private keys and seed phrases from crypto wallets. The attack doesn't discriminate; it targets not just developers but also web designers and other freelance tech workers, recognizing that compromised service providers can lead to broader organizational breaches.
Securing Your Digital Assets: A Crucial Divide
The joint advisory emphasizes a straightforward yet critical defense strategy: maintaining a strict separation between the machine used for running untrusted code and the device that stores your cryptocurrency keys. "Keep the machine on which you run other people's code strictly separate from the machine that holds your keys," the agencies implore.
For developers, this means executing code assignments only within isolated environments like virtual machines or sandboxes. For crypto holders, the ultimate safeguard lies in hardware wallets, which ensure private keys never leave the device. The agencies also advise scrutinizing code for obfuscated or unreadable sections and being wary of specific command components like ".vscode/tasks.json" within project folders, especially if opened in editors like Visual Studio Code.
Beyond individual security, the advisory touches upon the concerning practice of "laptop farms"—locations where North Korean IT workers, often under false identities, operate compromised machines remotely. This highlights the broader implications for clients and companies, as engaging with or inadvertently supporting such operations can lead to breaches of national law and sanctions.
Stay Vigilant, Stay Safe
The relentless evolution of cyber threats means constant vigilance is key. While the WaterPlum campaign is a significant development, it's a reminder that attackers are always refining their tactics. By understanding their methods and implementing robust security practices, especially the separation of devices for coding and crypto management, we can collectively build a stronger defense against these digital incursions. So, keep those coding tests in their own little digital sandbox and your crypto keys locked down tight – happy coding and happy holding!