BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Ledgers Academy Letter

The Daily Ledger: 20 September 2026

Seven agencies from Japan, the United States, Australia and Germany published the scale of North Korea's fake recruiter campaign: 30,000 devices, more than 7,000 crypto wallets and at least $10.71 million, all reached through a coding test. Plus a flat ETF week, Polygon's permissionless burn and Binance's first foreign exchange perpetual.

Subject: Seven agencies just put a number on the fake job interview
Preview: 30,000 machines, 7,000 wallets and $10.71 million, all from developers who were asked to run one file. The advisory is public and the fix is unglamorous.

THE DAILY LEDGER

20 September 2026
Seven agencies publish the scale of North Korea's fake recruiter campaign, bitcoin drifts below $81,000 on a quiet weekend, and Polygon prepares a burn anyone can trigger

Editor's note: prices, sentiment and market data were checked at 02:50 UTC on 20 September 2026 (04:50 Europe/Stockholm). Sunday is not a trading session, so the last completed week for fund flows ended Friday 18 September.

On 18 September the police and intelligence agencies of four countries put their names to one document about fake job interview crypto malware, and for once the numbers are precise. A North Korean group known as WaterPlum infected at least 30,000 devices in more than 100 countries and took funds or credentials from over 7,000 cryptocurrency wallets. Every one of those victims did the same thing: they ran a file a recruiter sent them.

1. The Day in Numbers

  • Bitcoin: $80,569 at 02:50 UTC, down 0.88 percent over the trailing 24 hours. That window rolls continuously and is not a completed daily change.
  • Ether: $2,593 at 02:50 UTC, down 1.05 percent over the trailing 24 hours.
  • Fear and Greed Index: 71, Greed, unchanged from Saturday and up from 56 on Friday.
  • Total crypto market value: $2.75 trillion, with bitcoin dominance back up to 58.9 percent from 58.3 percent a day earlier.
  • US spot bitcoin ETFs: net inflows of $6.2 million across the whole week to Friday 18 September, a flat week rescued by Friday's $433 million. Spot ether funds lost $140 million over the same week and ended a four week run of inflows.

2. How a fake job interview turns into a drained crypto wallet

The advisory carries seven signatures, from Japan, the United States, Australia and Germany, and covers December 2025 to July 2026.

Five step chain from a fake recruiter message to a drained wallet. Step one, contact: actors posing as recruiters for AI, crypto or NFT companies approach developers on social media, job boards and freelance marketplaces. Step two, pretext: the target is asked to complete a coding assignment or fix an error in the video call, which requires running a file. Step three, execution, marked as the one step the victim controls: a malicious Node Package Manager package, or a Visual Studio Code project that runs code as soon as the folder is opened and trusted. Step four, persistence: a remote access trojan keeps the connection open while an infostealer sends wallet credentials to a command and control address. Step five, outflow: funds and credentials leave for North Korea. A panel gives the reported scale from December 2025 to July 2026: over 30,000 devices, over 100 countries, over 7,000 crypto wallets and at least 1.7 billion yen, equal to 10.71 million US dollars.
The chain is automatic after step three. Source: joint advisory of 18 September 2026, ic3.gov.

The pretext is a technical interview or a coding test. The payload arrives as a Node Package Manager package, the standard way JavaScript developers install other people's code, or as a Visual Studio Code project. The agencies name five malware families, including BeaverTail and StoatWaffle. One of them exploits a detail worth knowing: opening a folder in VS Code and answering yes to "do you trust the authors" can run a configuration file automatically, before you have read a line of code.

After that it is out of your hands. A remote access trojan keeps the connection alive, an infostealer sends wallet credentials to an address the attackers control, and the assets move. The $10.71 million figure is a stated minimum, not a complete tally.

3. Today's Headlines

Polygon prepares a burn that anyone can set off

Polygon Foundation chief executive Sandeep Nailwal said on 18 September that a permissionless burn contract is live on testnet, waiting on Security Council signatures. The first call would destroy 100 million POL, about 83 percent of the 121 million in the network's fee collector and slightly under one percent of total supply, with quarterly burns open to anyone afterwards.

Binance opens a foreign exchange desk that never closes

Binance lists its first foreign exchange perpetual contract on Monday 21 September, US dollar against the Brazilian real, settled in tether at up to 100 times leverage. Currency markets shut at weekends, so the contract switches from a third party index to its own order book on Saturdays and Sundays. Bybit listed euro, sterling and yen versions less than two weeks earlier.

Hyperliquid turns collateral into a loan you ask for

Hyperliquid opened manual borrows on 18 September: supply HYPE or bitcoin, borrow dollar stablecoins against it at a 65 percent loan-to-value ratio for HYPE and 50 percent for bitcoin. Roughly $269 million was borrowed on the first day.

4. Security Note

Two rules come straight out of the advisory, and both are free. First, never open an unknown repository in an editor that can run code on launch. In Visual Studio Code, answer "No" to the trust prompt, which is Restricted Mode, then read .vscode/tasks.json before you change your mind. Code you did not write belongs in a virtual machine, not on the machine holding your keys.

Second, if a device is ever infected, treat the wallet as gone even if the balance is not. The rule: generate a new wallet on a different, clean device, move everything to it, keep the new seed phrase offline, then wipe the old machine. Removing malware does not un-send what it already took, and a seed phrase that touched a compromised computer is public information from then on. Our cold storage guide covers doing that properly.

5. From the Academy Library

The contracts behind Binance's currency listing are explained in our entry on funding rates and perpetual futures, and Custody Without Slogans takes on the awkward question of which device your keys should live on. New readers can start at Academy School.

Nothing in this campaign broke any cryptography. Seven thousand wallets opened because seven thousand people were polite to a recruiter.

Disclaimer: This publication is for education and information only. It is not financial, investment, legal, tax, or security advice.

Sources and further reading

Keep reading

Recent letters

The Quiet Ledger: Issue #8 | 2 October 2026

The Bitget forensic reports showed a breach that never touched a private key, and a day later the SEC proposed where investment advisers may hold client crypto. A quiet week for price in which custody was the only real subject.

Read letter →

The Daily Ledger: 1 October 2026

September was 2026's costliest month for crypto theft, at about $768.4 million on CertiK's count, and two incidents produced roughly 92 percent of it. Net of the 3,400 bitcoin an attacker returned, the month's unrecovered cost is closer to $497 million.

Read letter →

The Daily Ledger: 30 September 2026

August core PCE rose 0.2 percent on the month and 3.0 percent on the year, below expectations, trimming the case for an October rate rise. Bitcoin spiked to about $85,600 and gave the whole move back, closing its best quarter since early 2024 at roughly 42.7 percent.

Read letter →

The Daily Ledger: 29 September 2026

Bitget covered the loss, reopened bitcoin withdrawals, and about $463 million of net outflow followed in 24 hours, its largest single day on record. Nobody was left out of pocket, and customers left anyway, because a covered loss still proves the loss was possible.

Read letter →

The Letter

One clear letter, every week.

Plain analysis of crypto infrastructure, markets and security. No price calls, no referral links, no hype.

Unsubscribe at any time. Read the privacy notice.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →