Tag: Consensys

  • North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    Key Highlights

    • North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters from legitimate crypto and AI companies to target software developers and IT professionals worldwide.
    • The campaign infected over 30,000 devices across more than 100 countries and extracted funds or credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
    • A joint advisory from Japan, Germany, Australia, and the United States links WaterPlum to North Korea’s Munitions Industry Department and its broader strategy of placing undercover IT workers inside foreign organizations.

    Global Advisory Exposes Sophisticated Recruitment Fraud

    A joint cybersecurity advisory issued by authorities in Japan, Germany, Australia, and the United States has detailed a sprawling operation by the North Korean hacking group WaterPlum, also tracked as Contagious Interview. The group masqueraded as recruiters for legitimate artificial intelligence, cryptocurrency, and non-fungible token (NFT) companies, leveraging social media platforms, online job boards, gig work sites, and freelance marketplaces to lure victims. According to the advisory, the primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The operation has resulted in the theft of at least $10.7 million, marking a significant escalation in North Korea’s use of social engineering to fund its weapons programs.

    Malware Deployment via Fake Coding Assignments

    The attack chain relied on tricking job seekers into downloading and executing malicious files disguised as coding assignments or fixes for video-conferencing errors. Once executed, the malware provided the threat actors with backdoor access to the victim’s computer. WaterPlum operators then deployed remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. The advisory notes that successful infections create downstream risks, enabling WaterPlum actors to infiltrate the organizations that employ the compromised developers, thereby extending the blast radius beyond individual freelancers to corporate networks.

    Connection to North Korean IT Worker Infiltration

    The advisory explicitly links WaterPlum’s activities to North Korea’s broader campaign of placing IT workers inside foreign companies under false pretenses. Japanese and U.S. authorities assess that WaterPlum actors and certain North Korean IT workers operate under the direction of the country’s Munitions Industry Department. This dual-track approach—stealing cryptocurrency directly while simultaneously building a workforce of impersonators—amplifies the regime’s revenue generation. Stolen identity documents allow North Korean operatives to impersonate legitimate developers, securing employment and income, while sensitive personal data harvested during intrusions creates opportunities for extortion.

    Recent Incidents Highlight Ongoing Threat

    The advisory cites concrete examples of the infiltration tactic. In one case, a suspected North Korean IT worker applied for an engineering role at a Japanese cryptocurrency exchange using a forged resume; the applicant was rejected after failing to demonstrate the claimed skills during the interview. More recently, in July, Cointelegraph reported that blockchain software company Consensys had unknowingly engaged a North Korea-linked developer as a consultant. Consensys confirmed it terminated the contractor’s access upon discovering the threat, stating an investigation found no theft of assets or data, no malicious code deployment, and no impact on user safety. These incidents underscore the persistent difficulty organizations face in vetting remote technical talent.

    Why This Matters

    The WaterPlum campaign represents the latest evolution in North Korea’s long-standing reliance on cryptocurrency theft to circumvent international sanctions and fund its nuclear and ballistic missile programs. The Federal Bureau of Investigation (FBI) previously attributed the $1.5 billion theft from the Bybit exchange in February 2025 to North Korean actors. U.S. authorities have issued warnings about the regime’s undercover IT worker scheme since at least 2018. The convergence of direct financial theft, supply chain compromise via compromised developers, and strategic workforce infiltration signals a mature, well-resourced threat ecosystem. For the cybersecurity industry and any organization hiring remote technical talent, the advisory serves as a critical reminder that identity verification and device trust cannot be assumed based solely on a resume or interview performance.

    Frequently Asked Questions

    What is WaterPlum and how does it operate?

    WaterPlum, also known as Contagious Interview, is a North Korean state-sponsored hacking group. It operates by posing as recruiters from legitimate AI, crypto, and NFT companies on job platforms. The group tricks software developers and IT professionals into downloading malware disguised as coding tests or software fixes, gaining backdoor access to steal cryptocurrency, credentials, and sensitive data.

    How can job seekers protect themselves from such recruitment scams?

    Job seekers should verify the legitimacy of recruiters and companies through independent channels before downloading any files. Be wary of unsolicited offers, requests to execute code as part of an interview process, or pressure to install specific video-conferencing software or “fixes.” Use endpoint detection and response (EDR) solutions and maintain strict separation between personal and work devices.

    What are the implications for companies hiring remote developers?

    Companies face the risk of inadvertently hiring North Korean operatives using stolen identities, which can lead to intellectual property theft, infrastructure compromise, and regulatory violations. The Consensys incident demonstrates that even sophisticated firms can be deceived. Organizations must implement rigorous identity verification, background checks, technical assessments that cannot be easily faked, and continuous monitoring of contractor activity.

  • Consensys and MetaMask to Separate Into Two Independent Companies by End of 2026

    Consensys and MetaMask to Separate Into Two Independent Companies by End of 2026

    Consensys has announced a strategic separation into two independent companies, marking the end of a single-company structure that has persisted for over a decade. The reorganization will create MetaMask, focused on consumer self-custodial finance, and a new Consensys entity dedicated to Ethereum protocols and institutional infrastructure. The split is expected to close by the end of 2026.

    MetaMask Pivots to Consumer Finance Platform

    The newly independent MetaMask will take ownership of the self-custodial wallet, which the company reports has surpassed 100 million downloads across approximately 190 countries and facilitated trillions of dollars in cumulative transaction volume. Joe Lubin, who co-founded Consensys, will step in full-time as Chairman and Chief Executive Officer of MetaMask while serving as Executive Chairman of the new Consensys.

    “MetaMask grew out of that work into the world’s most widely used self-custodial wallet, and today it’s becoming something larger: a platform where people don’t just hold their assets, but manage their money in its many diverse forms and aspects. Stepping into this role full-time is a recognition that consumer finance deserves the same focus and ambition that we’ve brought to building Ethereum itself,” Lubin noted.

    The independent company will remain Ethereum-first while expanding its Money Account offering—a self-custodial account designed to combine automated earning, instant spending, and one-click trading in a single balance. This push follows MetaMask’s launch of its own dollar stablecoin, mUSD, issued through Stripe-owned Bridge, as part of a broader move into everyday payments that includes a Mastercard-linked card. Lubin has also confirmed that MetaMask will issue its own token, with a DAO planned to fund the wallet’s growth.

    Consensys Retains Institutional Infrastructure Stack

    The newly focused Consensys will retain the Protocols Group, including the Linea Layer-2 network, the Besu execution client, and Teku, alongside its tokenization and stablecoin work for banks and asset managers. Mike Kriak will run Consensys as Chief Executive Officer, with David Cunningham serving as President.

    Consensys will concentrate on the infrastructure that banks and market operators use to move tokenized assets on-chain. Its Besu client already underpins permissioned EVM networks in traditional finance, and the firm established the Swiss-based Linea Association to decentralize the Linea zkEVM network, which launched the LINEA token for governance.

    “Financial institutions and market infrastructure are moving to always-on operations with tokenization at the core,” said David Cunningham, President of Consensys. “Consensys Software Inc. has built the open-source technology that is the foundation of this transition.”

    Citi’s June 2026 “Tokenization 2030” report, cited in the announcement, estimated that tokenized assets could reach $5.5 trillion to $8.2 trillion by 2030. Lubin said the two companies “will keep building the same ecosystem, just with the focus each market now demands.”

  • Consensys Spins Off MetaMask as Independent Firm, Stays Silent on IPO

    Consensys Spins Off MetaMask as Independent Firm, Stays Silent on IPO

    Ethereum development firm Consensys announced plans to split into two independently operated companies, separating its MetaMask wallet business from the Ethereum protocols and institutional blockchain infrastructure it has built over the past decade.

    New Corporate Structure

    The existing company, Consensys Software Inc., will rebrand as MetaMask under Ethereum co-founder Joe Lubin as chairman and CEO.

    Its protocols group and institutional infrastructure business, including the Linea blockchain, will move into a newly formed company retaining the Consensys name.

    Leadership Changes

    The separation, expected to be completed by the end of 2026, would see Mike Kriak lead the new Consensys as CEO. That firm would include David Cunningham as president and Lubin as executive chairman.

    The new Consensys entity will focus on developing Ethereum infrastructure and helping financial institutions deploy blockchain systems for tokenized assets, stablecoins, and settlement.

    IPO Plans Delayed

    The restructuring comes after Consensys pushed back a potential U.S. initial public offering (IPO) until this fall at the earliest, citing poor market conditions. The company had reportedly engaged JPMorgan and Goldman Sachs to lead the process.