【Beware! A $11.8 million crypto recruitment scam breaks out in Singapore】
On August 14, Singapore police and the Cyber Security Agency jointly disclosed a major cryptocurrency scam that has resulted in losses of $11.8 million. The scam’s tactics are highly deceptive and are worth every professional’s utmost vigilance.
Complete scam chain:
1️⃣ The scammers impersonate a crypto company on LinkedIn, contacting job seekers proactively
2️⃣ They use a spoof email address with a domain name highly similar to the real company’s to communicate
3️⃣ They arrange a Google Meet video interview, with the camera turned off throughout
4️⃣ They instruct victims to access a spoof website on company-provided devices to complete the “coding test”
5️⃣ The device is implanted with malware, and session tokens are stolen
6️⃣ The attackers use this to bypass MFA multi-factor authentication
7️⃣ They break into the company’s Bitbucket code repository and tamper with automated deployment instructions
8️⃣ They remotely control internal servers, steal credentials, and bypass transaction limits and approval workflows
9️⃣ Finally, they complete large cryptocurrency transfers
The key warning of this case is that the attack did not directly target wallets or exchanges. Instead, it compromised the company’s internal development and deployment pipeline through social engineering, then bypassed risk-control approvals from the source.
Official prevention recommendations:
✅ Rigorously verify recruiters and company identities, and be wary of spoof emails with similar domain names
✅ Protect API keys and internal credentials, and avoid entering them in untrusted environments
✅ Strengthen multi-factor authentication, prioritizing hardware keys or FIDO2 solutions
✅ Enhance security audits of code repositories and CI/CD deployment pipelines
✅ If a suspicious intrusion is discovered, immediately isolate the device, revoke active sessions, reset credentials, and review access logs
For those working in crypto, this case once again serves as a reminder: no matter how strict the technical risk controls are, they can’t withstand an employee who falls for social engineering. Security awareness is the cheapest—and most effective—line of defense in the crypto world.
#加密货币 #网络安全 #anti-fraud
On August 14, Singapore police and the Cyber Security Agency jointly disclosed a major cryptocurrency scam that has resulted in losses of $11.8 million. The scam’s tactics are highly deceptive and are worth every professional’s utmost vigilance.
Complete scam chain:
1️⃣ The scammers impersonate a crypto company on LinkedIn, contacting job seekers proactively
2️⃣ They use a spoof email address with a domain name highly similar to the real company’s to communicate
3️⃣ They arrange a Google Meet video interview, with the camera turned off throughout
4️⃣ They instruct victims to access a spoof website on company-provided devices to complete the “coding test”
5️⃣ The device is implanted with malware, and session tokens are stolen
6️⃣ The attackers use this to bypass MFA multi-factor authentication
7️⃣ They break into the company’s Bitbucket code repository and tamper with automated deployment instructions
8️⃣ They remotely control internal servers, steal credentials, and bypass transaction limits and approval workflows
9️⃣ Finally, they complete large cryptocurrency transfers
The key warning of this case is that the attack did not directly target wallets or exchanges. Instead, it compromised the company’s internal development and deployment pipeline through social engineering, then bypassed risk-control approvals from the source.
Official prevention recommendations:
✅ Rigorously verify recruiters and company identities, and be wary of spoof emails with similar domain names
✅ Protect API keys and internal credentials, and avoid entering them in untrusted environments
✅ Strengthen multi-factor authentication, prioritizing hardware keys or FIDO2 solutions
✅ Enhance security audits of code repositories and CI/CD deployment pipelines
✅ If a suspicious intrusion is discovered, immediately isolate the device, revoke active sessions, reset credentials, and review access logs
For those working in crypto, this case once again serves as a reminder: no matter how strict the technical risk controls are, they can’t withstand an employee who falls for social engineering. Security awareness is the cheapest—and most effective—line of defense in the crypto world.
#加密货币 #网络安全 #anti-fraud