Seven agencies from four countries published a joint advisory on September 18, 2026, and it carries a finding that matters to anyone who holds their own keys: a North Korean threat group has used fake job offers to infect at least 30,000 machines in more than 100 countries, draining balances or credentials from over 7,000 crypto wallets. The signatories include Japan's National Police Agency and the FBI, alongside Germany's foreign intelligence service, the Bundesnachrichtendienst, and its domestic security agency, the Bundesamt für Verfassungsschutz.
North Korea Hackers Drain 7,000 Crypto Wallets
Seven agencies from four countries published a joint advisory on September 18, 2026, and it carries a finding that matters to anyone who holds their own keys: a North Korean threat group has used fake job offers to infect at least…
CryptoTicker
Publisher
Sep 19, 2026 at 9:11 PM UTC · 12 Min. Lesezeit

Key Signal
30,000 PCs Compromised machines
Last Updated
vor 18 Stunden
The short answer to what you should do about it fits in a single sentence: keep the machine on which you run other people's code strictly separate from the machine that holds your keys. The rest of this article explains why that particular separation works, which malware families the agencies name, and how to spot the bait before you open anything.
What the joint advisory of September 18, 2026 establishes
The agencies track the group under the name “WaterPlum”. In the security industry the same group usually goes by “Contagious Interview”, named after its method: the job interview that infects. This advisory carries more weight than a single vendor's assessment, because it is a coordinated finding by seven state bodies.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
