Singapore Authorities Warn of $11.8 Million LinkedIn Crypto Job Scam Ring
Sophisticated social engineering campaigns targeting cryptocurrency developers have cost victims $11.8 million through fake recruitment offers and malicious code deployment, according to Singapore's law enforcement and cyber security agencies.
The Attack Chain
According to the Singapore Police Force and Cyber Security Agency of Singapore, scammers posing as recruiters for cryptocurrency firms have orchestrated a coordinated campaign to compromise both individual victims and their employers. The attack begins on LinkedIn, where fake recruiters contact job seekers, then transition conversations to spoofed email domains that closely mimic legitimate companies. After conducting multiple interviews via Google Meet—with the interviewer’s camera remaining off throughout—targets are directed to fraudulent websites hosting technical coding assessments.
The critical compromise occurs when victims download and run code on company-issued devices, unknowingly installing malware. This malicious software captures session tokens, which represent authenticated user sessions. Because these tokens bypass the need for password re-entry, they circumvent multi-factor authentication entirely, granting attackers immediate access to the victim’s corporate accounts, including code repositories like Bitbucket where companies store source code.
From Code Access to Financial Loss
Once inside, attackers alter the employer’s software systems and penetrate internal servers. They harvest additional credentials that allow them to circumvent transaction approval processes and spending limits, enabling them to siphon funds. The advisory from Singapore’s authorities does not identify the targeted companies or specify where stolen funds are directed, but the pattern reveals attackers’ focus on accessing environments where significant capital resides—corporate systems rather than individual wallets.
Part of a Larger Pattern
Security researchers have documented similar operations for some time. A campaign tracked as Contagious Interview has targeted Web3 developers specifically, funneling them toward malicious code packages, including over 300 booby-trapped submissions to the npm registry. A group called TraderTraitor has adopted comparable tactics to reach corporate infrastructure. Researchers have attributed some of these campaigns to North Korean threat actors, though similar playbooks have emerged from Russian-speaking groups, including one that created an entire fake Web3 company called ChainSeeker.io to distribute wallet-draining malware under the guise of blockchain analyst recruitment.
As cryptocurrency adoption accelerates and Web3 development becomes increasingly valuable, these supply chain attacks targeting developers pose a meaningful threat to projects and platforms seeking engineering talent in a competitive market.
Source: Singapore Police Force and Cyber Security Agency of Singapore, via Decrypt. Not financial advice.