Fake recruitment fraud: Cryptocurrency company recruitment scam caused nearly US$12 million in losses
The Singapore Police Force and the Singapore Cyber Security Administration jointly issued a warning that fraudsters posing as recruiters of cryptocurrency companies had used fake job opportunities to trick victims into downloading malware and then hacked into their employer systems, causing a total of US$11.8 million (approximately S$15.1 million) in losses.
The two departments detailed the fraud method in a statement on Friday (date). A victim received a message on the LinkedIn platform claiming to be a recruiter of a cryptocurrency company. The two parties then communicated by email. The sender used a fake domain name that was very similar to the real company's domain name. Since then, the victim has conducted multiple rounds of interviews on Google Meet, but the interviewer did not turn on the camera throughout.
The victim is then directed to a fake website to complete a technical programming assessment. While operating on company-issued devices, victims inadvertently downloaded malware. The malware captures session tokens-strings that the service system uses to keep users logged in. Since the token represents an authenticated session, the attacker used it to bypass multi-factor authentication and directly open the victim company's Bitbucket account (used to store and manage source code).
According to Singapore authorities, the attacker used the account to tamper with the employer's software system and hacked into internal servers, stealing credentials, bypassing transaction limits and approval processes and ultimately transferring funds. The warning did not mention the name of the specific company or the whereabouts of the funds, nor did it blame any organization for the attack.
Fraud methods have a long history
Such fraud models have long been recorded. Researchers have discovered a long-active attack called "Contagious Interview" in which fake recruiters induce Web3 developers to run malicious code, including more than 300 trapped npm packages. An organization called TraderTraitor uses fake job opportunities to hack into corporate cloud systems rather than personal wallets-researchers point out that this is because of the large amount of money stored in corporate systems. In addition, there are scammers posing as recruiters for Coinbase and Uniswap to induce targets to perform specific orders.
These attacks are often attributed to North Korean hackers, but the method is not unique to them. The Russian-language hacker group "Crazy Evil" once created a complete fake Web3 company "ChainSeeker.io" and posted blockchain analyst job advertisements to induce job seekers to install malware that could empty wallets.
Singapore authorities recommend
For individuals, Singapore authorities recommend: verifying the identity of recruiters through official channels; being vigilant against interviewers who refuse to turn on the camera; and not running codes of unknown origin. For enterprises, authorities recommend: protecting API keys and internal credentials; strengthening multi-factor authentication; and monitoring abnormal devices and network activity. If you suspect a system has been compromised, you should immediately isolate the affected system, revoke active sessions, reset credentials, and review access logs.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following