Crypto Fraud Watch: Fake Recruiters Take $10.71 Million, Haruko Leaks 15 Funds' API Keys, and the CFTC Files Without Congress

Four governments named the same North Korean malware campaign, a London vendor disclosed a breach reaching fifteen hedge funds, and the CFTC filed market structure rules with the White House after the Senate declined to pass any. Here is what moved in the last forty-eight hours.

Seven Agencies, Four Countries, $10.71 Million in Fake Job Offers

On September 18, seven agencies, the FBI and Japan's National Police Agency among them, issued a joint advisory on a North Korean group called WaterPlum. From December 2025 through July 2026 it infected over 30,000 devices in 100-plus countries and drained credentials from more than 7,000 crypto wallets, sending at least $10.71 million to wallets it controls. The lure was a job interview: fake recruiters asked candidates to clone a repository or install something to join a video call.

The advisory ties WaterPlum to North Korea's 313 General Bureau, which puts the thefts inside the sanctions perimeter and makes civil recovery close to hopeless. It also flags North Koreans using stolen resumes and remote laptop farms to win contracts. Paying one is an OFAC exposure of your own. Hiring is now a compliance function.

Haruko's Breach and the Vendor Nobody Lists in the Risk Memo

The same day, Haruko, the London firm whose trade-data tools sit between hedge funds and their exchanges, disclosed a targeted cyberattack. The attacker exploited a flaw in one internal process, pulled a user access token from its memory, and read exchange API details and trading records for 15 clients. The affected firms were the ones that had not enabled inbound IP whitelisting. The keys were read-only, and read-only keys should not move money, so any real loss raises a question about what permissions were actually set. Managers should reread their vendor agreements for the liability cap and the notification clock.

The CFTC Files Market Structure Rules Without Congress

On Thursday, September 17, the CFTC sent a rulemaking titled "Regulation Crypto Asset Transactions and Regulation Crypto Asset Markets" to the Office of Information and Regulatory Affairs at OMB. It is docketed at RIN 3038-AF80 as a pre-rule, and it landed two days after the CLARITY Act failed a Senate procedural vote. Chair Michael Selig signaled in August that the agency would act on existing authorities if legislation stalled. The takeaway is a clock: OIRA typically clears a pre-rule in 10 working days, against 90 for proposed and final rules. Rules built on old statutes are easier to attack, so expect major-questions and APA challenges if the text overreaches.

A Privacy Coin ETF Splits Three Ways

Grayscale filed to split its Zcash ETF, ZCSH, three-for-one, under a month after it began trading August 25, with split-adjusted trading from September 30. The fund has pulled in over $233 million and held about $890 million in net assets on September 17. The wrapper is the point. A shielded-transaction asset now sits inside a registered product subject to sanctions screening, asking issuers to run an anti-money-laundering program that assumes traceability over an asset built to defeat it.

How to Protect Yourself

Two of today's stories start the same way: someone with credible credentials asked for a small technical favor. Treat any unsolicited recruiter who wants you to run code as hostile, and keep interview projects in a disposable virtual machine with no wallet and no browser profile you care about. If you use a third-party trading vendor, enable IP whitelisting, scope API keys narrowly, and rotate them on a schedule rather than after an incident.

If funds are gone, speed decides outcomes. Preserve wallet addresses, transaction hashes, the recruiter's messages and profile, and the repository before they vanish. Report promptly to the FBI's IC3 and to any exchange in the path, since exchanges can freeze deposits but usually need a law enforcement referral or a court order to do it. Emergency freezing relief and, in some jurisdictions, alternative service on an unidentified defendant are available.

At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.

Disclaimer

This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.

Next
Next

Crypto Law Brief: The SEC’s Five-Year Tokenized Stock Window, a CFTC Pass for Wallet Front-Ends, and Sanctions on Iran’s BitBank