Singapore crypto job scam

A fake job interview on LinkedIn ended up costing a company US$11.8 million after a supposed recruiter walked a Singapore-based employee straight into a malware trap. The Singapore crypto job scam unfolded in stages that felt routine at first — a LinkedIn message, a few video calls, a coding test — before spiraling into a full breach of corporate infrastructure and a cryptocurrency heist, according to the Singapore Police Force and the Cyber Security Agency of Singapore.

Key takeaways

  • A victim was approached on LinkedIn by a scammer posing as a recruiter for a crypto-related company, then guided through a fake interview process.

  • A spoofed domain and a rigged technical assessment installed malware on the victim’s company-issued device without their knowledge.

  • The malware harvested a session token, letting attackers bypass multi-factor authentication and break into the victim’s Bitbucket code repository account.

  • From Bitbucket, attackers altered deployment instructions, moved into the company’s internal servers, and bypassed transaction controls to steal US$11.8 million in cryptocurrency.

  • Singapore authorities have not linked the attack to North Korea or any other named hacking group.

Singapore Crypto Job Scam Leads to $11.8 Million Loss

The scam began with a message that looked like an ordinary recruitment pitch. SPF and CSA said the victim was first contacted on LinkedIn by someone claiming to recruit for a cryptocurrency-related company, kicking off an interview process that eventually gave outsiders access to the victim’s own employer.

A LinkedIn Interview That Wasn’t

Once the conversation moved off LinkedIn, the fake recruiter switched to email using a spoofed domain built to closely resemble the real company’s address. The victim then sat through several interviews on Google Meet — though notably, the person conducting them kept the camera off throughout. As the process progressed, the target was directed to a spoofed website and told to complete a technical coding assessment on a company-issued device. That assessment quietly delivered malicious software onto the machine, and the victim had no idea the device had been compromised.

Malware Bypasses MFA to Reach Bitbucket and Company Servers

Once installed, the malware harvested the victim’s session token — a piece of data that let attackers slip past multi-factor authentication entirely. That multi-factor authentication bypass opened the door to the victim’s Bitbucket account, which was tied directly to the employer’s code repository. Because Bitbucket is widely used by development teams to store, manage and collaborate on source code, a single compromised employee account with the right permissions can expose far more than one person’s device.

From there, the intrusion escalated fast. SPF and CSA said attackers modified the company’s automated software deployment instructions after breaking into the Bitbucket account, then used that foothold to remotely access the company’s internal servers — turning what started as a job-scam phishing attempt into a full-blown Bitbucket compromise attack against the company’s infrastructure.

The final blow came through the credentials collected along the way. Those stolen credentials let the attackers bypass the transaction limits and approval checks meant to control cryptocurrency transfers, and they used that access to move funds out of the company. The total damage: US$11.8 million in losses, authorities confirmed.

A Familiar Playbook Across the Crypto Industry

This is not an isolated technique. Recruitment-themed attacks have repeatedly leaned on trusted platforms — LinkedIn, Telegram, Google Meet, Slack — to make the initial contact feel legitimate before pushing targets toward malicious files or software. That’s precisely what makes this style of cryptocurrency recruitment scam so effective: it exploits professional trust rather than technical weakness at the entry point.

In April, an Obsidian malware campaign used LinkedIn and Telegram to approach crypto and finance professionals, convincing them to install malicious plugins for the legitimate Obsidian note-taking app. Elastic Security Labs identified the malware as PHANTOMPULSE, noting it used three blockchain networks to receive commands and maintain persistence. That During that same period, the wallet service Zerion disclosed a $100,000 security incident stemming from an extended campaign of social engineering attributed to North Korean attackers, with researchers at Security Alliance connecting the campaign to 164 malicious domains used to infiltrate crypto companies through Slack and LinkedIn. Zerion said the attackers had targeted the human side of its operations rather than breaking its wallet technology directly.

North Korea’s UNC4899 and Other Recruiter-Based Attacks

Singapore authorities have not attributed the US$11.8 million loss to North Korea or any other hacking group. But the tactics echo a pattern North Korean-linked actors have used before. Google Cloud and Wiz reported in 2025 that a group known as UNC4899, or TraderTraitor, approached crypto company employees through LinkedIn and Telegram while posing as recruiters, persuading some to run malicious Docker containers that deployed downloaders and backdoors. In at least one case, Google said the group disabled multi-factor authentication on a privileged Google Cloud account to reach wallet-related services. The group has reportedly been active since 2020, focusing heavily on crypto and blockchain firms.

Developer environments keep turning up as the weak point across these cases. A TrapDoor campaign discovered in May compromised GitHub tokens, SSH keys and cloud credentials in addition to cryptocurrency wallet data — enabling threat actors to obtain multiple forms of system access through a single compromised developer machine setup. A December 2024 fake interview campaign, meanwhile, approached Web3 professionals through LinkedIn, Telegram and freelance platforms, later steering them toward a video task where a supposed microphone or camera glitch tricked victims into running commands that opened their devices to attackers. On-chain investigator Taylor Monahan said at the time that running those commands could hand attackers general access to a device, creating openings to steal data, monitor activity, or compromise crypto wallets.

How Singapore Authorities Say Companies Should Respond

Following the incident, SPF and CSA urged businesses and individuals — especially those in tech and crypto — to verify the identity of recruiters and the companies they claim to represent before opening job-related files, websites or software. Companies were also told to protect API keys and internal credentials, strengthen multi-factor authentication, and secure code repositories and deployment pipelines specifically, since access to those systems can let a single compromised device reach into company-wide infrastructure.

Isolate, Revoke, Reset

For businesses that suspect a breach has already happened, the agencies advised isolating affected devices or systems immediately, revoking active sessions, and resetting credentials without delay. Access logs should be checked for signs attackers reached other accounts or infrastructure, and teams should verify whether repositories, servers, or approval workflows were altered during the compromise. Internal security teams or outside providers should be brought in right away to determine which accounts were exposed and whether unauthorized changes followed the initial intrusion.

For individuals, the advice is simpler but just as pointed: treat unsolicited recruitment offers with caution, verify both the recruiter and the company independently, and stay alert whenever an interview process asks candidates to download files, run unfamiliar code, or use websites from unverified sources.

FAQ

How did the attackers initially compromise the victim’s device?

Attackers posed as recruiters on LinkedIn and used spoofed domains and a fake interview website to deploy malware during a technical assessment on a company device.

What security feature did the attackers bypass to access the company’s Bitbucket account?

The attackers harvested session tokens via malware to bypass multi-factor authentication and access the Bitbucket repository.

What advice do Singapore authorities give to prevent similar recruitment scams?

Authorities advise verifying recruiter identities, securing API keys and code repositories, isolating compromised devices immediately, revoking sessions, and resetting credentials.

Is the attack attributed to any known hacking group?

Singapore authorities have not attributed this specific attack to North Korea or any other hacking group.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.