Singapore Warns Fake Crypto Job Scammers Stole $11.8M
Singapore authorities warn that scammers posing as crypto recruiters target developers via LinkedIn, using fake interviews and malicious coding tests to deploy malware. The campaign has stolen $11.8 million by compromising company systems, bypassing MFA, and moving funds, according to a joint police and cyber agency advisory.
Quick Take
Scammers pose as crypto recruiters on LinkedIn to target developers.
Malware from fake coding tests captures session tokens to bypass MFA.
Attackers used compromised Bitbucket access to move $11.8M in funds.
Authorities advise verifying recruiters and avoiding unverified code.
Market Impact Analysis
NeutralSecurity advisory on crypto job scams; no direct asset price impact, but reputational risk for crypto hiring.
Speculation Analysis
Key Takeaways
- Scammers pose as crypto recruiters on LinkedIn and move to spoofed email domains to target developers.
- Malware from fake coding assessments captures session tokens, allowing attackers to bypass multi-factor authentication.
- Attackers used compromised Bitbucket access to alter employer systems and move $11.8 million.
- Authorities advise verifying recruiters through official channels and avoiding unverified code on work devices.
What Happened
Singapore's police and cyber security agency have issued a joint advisory warning that scammers posing as cryptocurrency recruiters have stolen $11.8 million through fake job offers. The scheme targets developers on LinkedIn, where attackers pose as recruiters for crypto firms and move conversations to email using spoofed domains. Victims are invited to multiple interviews on Google Meet, often with the interviewer's camera off. They are then directed to a spoofed website to complete a technical coding assessment on a company-issued device. The assessment downloads malware that captures a session token from the victim's system. That token, representing an already-authenticated session, allows attackers to bypass multi-factor authentication and access the victim's Bitbucket account. From there, attackers alter employer software systems, reach internal servers, collect credentials, and move funds.
The Numbers
Singapore authorities put total losses at $11.8 million (S$15.1 million). The advisory describes one case involving a victim approached via LinkedIn, several interviews on Google Meet, and a spoofed coding assessment site. The malware captured a single session token, which bypassed multi-factor authentication and opened the victim's Bitbucket account. Researchers tracking the broader Contagious Interview campaign have identified more than 300 booby-trapped packages uploaded to the npm registry. The group TraderTraitor has used similar fake job offers to access corporate cloud systems, while Russian-speaking crew Crazy Evil built a fake Web3 company, ChainSeeker.io, to lure applicants into installing wallet-draining malware. The Singapore advisory does not name any company or attribute the attacks.
Why It Happened
Attackers exploit the hiring process by mimicking legitimate recruiters and using spoofed domains that closely resemble real companies. Developers are prime targets because they often complete technical coding tests on work devices and have access to source code repositories like Bitbucket. Malware captures session tokens, which are credentials that keep users logged in. Because tokens represent an already-authenticated session, presenting them bypasses multi-factor authentication entirely. This gives attackers direct access to corporate systems without needing passwords or additional verification. The crypto industry's concentration of funds and reliance on remote hiring make it an attractive target. Similar methods have been used by North Korean-linked groups and other cybercriminal crews.
Broader Impact
The advisory underscores a growing threat to remote hiring in crypto and tech. The use of fake coding assessments to deploy malware shows that even routine recruitment steps can compromise enterprise security. Companies should vet third-party recruiting contacts and restrict code execution on work devices. The pattern also signals that session token theft is an effective MFA bypass, pressuring organizations to adopt deeper monitoring and least-privilege access.
What to Watch Next
- Watch for more joint advisories or arrests related to fake crypto recruiter scams across Asia.
- Monitor companies' hiring processes for added verification steps, especially for technical roles involving code tests.
- Track security research on Contagious Interview and similar campaigns for new malicious packages or domains.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.