
Singapore agencies warn of fake crypto recruiter scams bypassing MFA to breach corporate systems and steal millions.
Scammers posing as crypto recruiters stole $11.8 million using fake job offers and technical assessments that installed malware on targets' devices, bypassing multi-factor authentication to drain corporate funds, Singapore authorities warn.
AI-generated summary
Scammers use fake recruiter profiles and technical tests to deploy malware and breach corporate systems.
Scammers posing as recruiters for cryptocurrency companies have taken $11.8 million (S$15.1 million), using fake job offers to compromise their targets' employers, according to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore.
Setting out how the scam works in a statement on Friday, reported by The Straits Times and Channel NewsAsia, the agencies said a victim was approached on LinkedIn by someone posing as a recruiter for a crypto company, then moved to email, where the sender used a spoofed domain closely resembling a real firm's. Several interviews followed on Google Meet. The interviewer kept their camera off throughout.
The victim was then sent to a spoofed website to complete a technical coding assessment, and did so on a company-issued device, downloading malicious software in the process without realizing it.
The malware captured a session token, the string a service issues to keep a user logged in. Because the token represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim's Bitbucket account, where the company stores and manages its source code.
From there the attackers altered the employer's software systems and reached its internal servers, the agencies said, collecting credentials that were then used to get around transaction limits and approval checks and move funds. The advisory does not name any company, say where the funds went, or attribute the attacks to anyone. Decrypt has approached LinkedIn for comment and will update this article should they respond.
That pattern is well documented, with researchers tracking a long-running operation they call Contagious Interview, in which fake recruiters steer Web3 developers toward malicious code, including more than 300 booby-trapped packages uploaded to the npm registry. A group known as TraderTraitor has used fake job offers to reach corporate cloud systems rather than individual wallets, which one researcher put down to that being where the money sits. Others have posed as recruiters from Coinbase and Uniswap to get targets running commands.
Those campaigns are attributed to North Korean hackers, but the playbook is not uniquely theirs. The Russian-speaking crew Crazy Evil built an entire fake Web3 company, ChainSeeker.io, and advertised blockchain analyst roles to lure applicants into installing wallet-draining malware.
Singapore agencies’ advice to individuals is to verify recruiters through official channels, treat an interviewer who will not turn on their camera as a warning sign, and never run code from an unverified source. For companies, the agencies recommend securing API keys and internal credentials, strengthening multi-factor authentication and watching for unfamiliar devices and unusual network activity. Where a compromise is suspected, they advise isolating affected systems, revoking active sessions, resetting credentials and reviewing access logs.
AI outlook — possibilities, not facts
Decrypt will update the article if LinkedIn responds to requests for comment.
Possible · Within days

The US Treasury’s proposed GENIUS Act rules aim to restrict the distribution of stablecoins on American exchanges. By July 2028, platforms must ensure issuers meet specific regulatory standards, potentially limiting access to offshore tokens like USDT while exempting self-custody.

Bitcoin surpassed $79,000 this Friday, fueled by institutional ETF inflows, a favorable regulatory environment in Washington, and over $4 billion in short liquidations. Analysts cite a convergence of macro-economic shifts and increased spot demand.

MANTRA Chain halted its mainnet on Aug. 21 after an attacker exploited an upstream dependency. Transactions, staking, and transfers are currently suspended while the team tests a security patch on the DuKong testnet before a coordinated restart.

Justin Sun has accused World Liberty Financial of deceptive practices, alleging that its USD1 stablecoin's live code contains hidden administrative functions allowing the issuer to move funds from frozen accounts, a feature not reflected in the project's public GitHub.

Bitcoin and gold prices surged to multi-month highs, with BTC consolidating above $77,000. Analysts attribute the rally to US government deficit spending and Treasury debt buyback policies, while Polymarket data shows a 48% probability of BTC hitting $90,000 by 2027.

Solana has successfully reduced its slot time to 350 milliseconds, down from 400ms, as part of a multi-stage plan to improve network latency. The update, approved via SIMD-0525, aims for further reductions toward a 200ms target.