📰
Top StoriesNeutral
57

Singapore Warns Fake Crypto Job Scammers Stole $11.8M

Singapore authorities warn that scammers posing as crypto recruiters target developers via LinkedIn, using fake interviews and malicious coding tests to deploy malware. The campaign has stolen $11.8 million by compromising company systems, bypassing MFA, and moving funds, according to a joint police and cyber agency advisory.

DecryptDecrypt Agent

Quick Take

1

Scammers pose as crypto recruiters on LinkedIn to target developers.

2

Malware from fake coding tests captures session tokens to bypass MFA.

3

Attackers used compromised Bitbucket access to move $11.8M in funds.

4

Authorities advise verifying recruiters and avoiding unverified code.

Market Impact Analysis

Neutral

Security advisory on crypto job scams; no direct asset price impact, but reputational risk for crypto hiring.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger20/100
MinimalExtreme FOMO

Key Takeaways

  • Scammers pose as crypto recruiters on LinkedIn and move to spoofed email domains to target developers.
  • Malware from fake coding assessments captures session tokens, allowing attackers to bypass multi-factor authentication.
  • Attackers used compromised Bitbucket access to alter employer systems and move $11.8 million.
  • Authorities advise verifying recruiters through official channels and avoiding unverified code on work devices.
Total Losses$11.8Mreported by Singapore authorities
EquivalentS$15.1MSingapore dollar figure
Malicious npm packages300+linked to Contagious Interview

What Happened

Singapore's police and cyber security agency have issued a joint advisory warning that scammers posing as cryptocurrency recruiters have stolen $11.8 million through fake job offers. The scheme targets developers on LinkedIn, where attackers pose as recruiters for crypto firms and move conversations to email using spoofed domains. Victims are invited to multiple interviews on Google Meet, often with the interviewer's camera off. They are then directed to a spoofed website to complete a technical coding assessment on a company-issued device. The assessment downloads malware that captures a session token from the victim's system. That token, representing an already-authenticated session, allows attackers to bypass multi-factor authentication and access the victim's Bitbucket account. From there, attackers alter employer software systems, reach internal servers, collect credentials, and move funds.

The Numbers

Singapore authorities put total losses at $11.8 million (S$15.1 million). The advisory describes one case involving a victim approached via LinkedIn, several interviews on Google Meet, and a spoofed coding assessment site. The malware captured a single session token, which bypassed multi-factor authentication and opened the victim's Bitbucket account. Researchers tracking the broader Contagious Interview campaign have identified more than 300 booby-trapped packages uploaded to the npm registry. The group TraderTraitor has used similar fake job offers to access corporate cloud systems, while Russian-speaking crew Crazy Evil built a fake Web3 company, ChainSeeker.io, to lure applicants into installing wallet-draining malware. The Singapore advisory does not name any company or attribute the attacks.

Why It Happened

Attackers exploit the hiring process by mimicking legitimate recruiters and using spoofed domains that closely resemble real companies. Developers are prime targets because they often complete technical coding tests on work devices and have access to source code repositories like Bitbucket. Malware captures session tokens, which are credentials that keep users logged in. Because tokens represent an already-authenticated session, presenting them bypasses multi-factor authentication entirely. This gives attackers direct access to corporate systems without needing passwords or additional verification. The crypto industry's concentration of funds and reliance on remote hiring make it an attractive target. Similar methods have been used by North Korean-linked groups and other cybercriminal crews.

Broader Impact

The advisory underscores a growing threat to remote hiring in crypto and tech. The use of fake coding assessments to deploy malware shows that even routine recruitment steps can compromise enterprise security. Companies should vet third-party recruiting contacts and restrict code execution on work devices. The pattern also signals that session token theft is an effective MFA bypass, pressuring organizations to adopt deeper monitoring and least-privilege access.

What to Watch Next

  • Watch for more joint advisories or arrests related to fake crypto recruiter scams across Asia.
  • Monitor companies' hiring processes for added verification steps, especially for technical roles involving code tests.
  • Track security research on Contagious Interview and similar campaigns for new malicious packages or domains.
Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

🏛️
Institutional & Investment NewsBullish
70

Israel's largest bank taps Galaxy to offer Bitcoin, Ether, Solana trading

Bank Leumi, Israel's largest bank, has partnered with Galaxy Digital to enable Bitcoin, Ether, and Solana trading through its Leumi Trade app, with launch expected in early 2027. The move makes Leumi the first Israeli bank to offer digital asset trading services.

BTCETHSOL
85% confidence
Aug 14, 2026, 3:41 PM UTC · Cointelegraph
Singapore Warns Fake Crypto Job Scams Stole $11.8M | Bytewit