More than 30,000 devices across over 100 countries and regions were infected by North Korea-linked WaterPlum between December 2025 and July 2026, Japan’s National Police Agency and the FBI said. The malware operation stole data from 7,000 crypto wallets.
Why it matters
The scale turns WaterPlum from a targeted incident into a broad cybersecurity threat for crypto users. Wallet data can expose access credentials and compromise assets, making device security a central part of crypto custody.
Market impact
The reported campaign does not identify a specific blockchain or token, but it raises security risks across the wider crypto ecosystem. Users should treat wallet-related data on infected devices as exposed and review their device and wallet security controls.
Source: [source](https://www.npa.go.jp/bureau/cyber/pdf/20260918_j.pdf)
Frequently asked questions
-
How many devices did WaterPlum infect?
Japan’s National Police Agency and the FBI reported that WaterPlum infected more than 30,000 devices.
-
How widespread was the WaterPlum campaign?
The campaign affected devices across more than 100 countries and regions between December 2025 and July 2026.
-
How many crypto wallets had data stolen?
The reported malware operation stole data from 7,000 crypto wallets.
-
Who is linked to the WaterPlum malware operation?
WaterPlum was linked to North Korea by Japan’s National Police Agency and the FBI.
-
What is the main crypto risk from the campaign?
The campaign creates a wallet-security risk because compromised devices can expose wallet-related data and put crypto holdings at risk.
WuBlockchain