XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Regulation
● Regulation

Singapore Authorities Warn of $11.8 Million LinkedIn Crypto Job Scam Ring

Sophisticated social engineering campaigns targeting cryptocurrency developers have cost victims $11.8 million through fake recruitment offers and malicious code deployment, according to Singapore's law enforcement and cyber security agencies.

JM
by Jacob Marquez · Regulation Desk
Published August 14, 2026 · 2 min read

The Attack Chain

According to the Singapore Police Force and Cyber Security Agency of Singapore, scammers posing as recruiters for cryptocurrency firms have orchestrated a coordinated campaign to compromise both individual victims and their employers. The attack begins on LinkedIn, where fake recruiters contact job seekers, then transition conversations to spoofed email domains that closely mimic legitimate companies. After conducting multiple interviews via Google Meet—with the interviewer’s camera remaining off throughout—targets are directed to fraudulent websites hosting technical coding assessments.

The critical compromise occurs when victims download and run code on company-issued devices, unknowingly installing malware. This malicious software captures session tokens, which represent authenticated user sessions. Because these tokens bypass the need for password re-entry, they circumvent multi-factor authentication entirely, granting attackers immediate access to the victim’s corporate accounts, including code repositories like Bitbucket where companies store source code.

From Code Access to Financial Loss

Once inside, attackers alter the employer’s software systems and penetrate internal servers. They harvest additional credentials that allow them to circumvent transaction approval processes and spending limits, enabling them to siphon funds. The advisory from Singapore’s authorities does not identify the targeted companies or specify where stolen funds are directed, but the pattern reveals attackers’ focus on accessing environments where significant capital resides—corporate systems rather than individual wallets.

Part of a Larger Pattern

Security researchers have documented similar operations for some time. A campaign tracked as Contagious Interview has targeted Web3 developers specifically, funneling them toward malicious code packages, including over 300 booby-trapped submissions to the npm registry. A group called TraderTraitor has adopted comparable tactics to reach corporate infrastructure. Researchers have attributed some of these campaigns to North Korean threat actors, though similar playbooks have emerged from Russian-speaking groups, including one that created an entire fake Web3 company called ChainSeeker.io to distribute wallet-draining malware under the guise of blockchain analyst recruitment.

As cryptocurrency adoption accelerates and Web3 development becomes increasingly valuable, these supply chain attacks targeting developers pose a meaningful threat to projects and platforms seeking engineering talent in a competitive market.

Source: Singapore Police Force and Cyber Security Agency of Singapore, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Regulation Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.