
A coalition of seven intelligence and cybersecurity agencies has linked a North Korean hacking crew, known as WaterPlum, to a sophisticated social‑engineering operation that masqueraded as remote IT job interviews. The scheme, detailed in a recent Decrypt investigation, harvested roughly $11 million from more than 7,000 cryptocurrency wallets between 2022 and 2024.
What sets this campaign apart from classic phishing is the heavy reliance on AI‑driven conversational agents. Victims were invited to video calls that appeared to be legitimate recruitment screenings. Behind the scenes, large‑language‑model chatbots generated interview questions, evaluated answers, and, crucially, coaxed candidates into sharing private wallet addresses and seed phrases. The bots were fine‑tuned to mimic human recruiters, complete with regional accents and industry‑specific jargon, making detection extremely difficult for the average user.
The WaterPlum crew leveraged open‑source AI frameworks, deploying them on inexpensive cloud instances to scale the operation. By automating the interview flow, the actors could conduct thousands of sessions in parallel, dramatically increasing the attack surface. Once a victim disclosed their private key, the bots instantly routed the funds through a chain of mixers and low‑volume DeFi bridges, obscuring the trail before the assets settled in wallets controlled by the North Korean regime.
For the broader AI ecosystem, this incident is a stark reminder that the same language models powering productivity tools can be weaponized for large‑scale fraud. It underscores the urgent need for robust AI‑safety protocols, especially around identity verification and deep‑fake detection. Developers of conversational agents must embed provenance checks and watermarking to flag synthetic interactions that could be used maliciously.
From a crypto‑security perspective, the episode amplifies the risk profile of on‑chain assets. Even users who store funds in hardware wallets are vulnerable if they ever expose seed phrases during a compromised interview. The incident also highlights the importance of multi‑factor authentication and hardware‑based key management solutions that never reveal private keys to any external party.
While the report offers a rare glimpse into state‑backed cyber‑crime leveraging AI, it also serves as a cautionary tale for the industry: innovation without guardrails invites exploitation. Regulators, platform providers, and AI developers must collaborate to build detection mechanisms that can spot AI‑generated social engineering in real time, protecting both users and the integrity of decentralized finance.
The WaterPlum operation is still under investigation, but its use of AI chatbots marks a new frontier in crypto‑theft, one that blends traditional espionage with cutting‑edge machine learning. As the line between legitimate automation and malicious deception blurs, the crypto community must stay vigilant and demand stronger safeguards against AI‑enabled scams.
Photo: Priscilla Du Preez 🇨🇦 / Unsplash (https://unsplash.com/@priscilladupreez)
Coinbase adds on‑chain, fixed‑rate USDC loans backed by Bitcoin, using AI‑driven automation to price risk and manage liquidity.

The recent failure of the Clarity Act in the Senate has created a vacuum, potentially benefiting offshore crypto hubs and traditional banks while leaving stablecoin innovation in regulatory limbo.

Analysts see AI‑driven brokers like Coinbase, Robinhood and Circle as early beneficiaries of the SEC’s tokenized‑stock push, unlocking new on‑chain automation.

Comments