Singapore authorities have warned of a cryptocurrency-related scam that used fake job offers and malicious software to infiltrate corporate systems and facilitate unauthorized cryptocurrency transfers, resulting in $11.8 million in losses.
In an official advisory released on August 14. Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) said that the scheme particularly targeted technology and cryptocurrency professionals. Scammers posed as legitimate recruiters and used fake technical assessments to gain access to company systems.
How the scheme worked
The advisory detailed a case where the victim was approached on LinkedIn by a scammer posing as a recruiter for a cryptocurrency company. The scammer used an email address linked to a spoofed domain that resembled the legitimate firm’s website and arranged several interviews via Google Meet. The interviewer’s camera remained off during the calls, according to the authorities.
The victim was later directed to a fake website to complete a coding assessment using a company-issued device. The assessment contained malicious software that secretly harvested the victim’s session token. The stolen token was then used to bypass multi-factor authentication and access the victim’s Bitbucket account. The compromised Bitbucket account was connected to the company’s code repository, giving the scammer a route deeper into its systems.
After gaining access, the scammer altered automated software deployment instructions and remotely accessed internal company servers. They also harvested credentials that enabled them to bypass transaction limits and approval checks.
Those credentials were ultimately used to conduct cryptocurrency transfers, resulting in losses of $11.8 million. The incident highlights how a seemingly routine recruitment process can become an entry point into a company’s software infrastructure and, eventually, its digital-asset holdings.
Why the scheme matters
The case has highlighted the limitations of relying solely on multi-factor authentication (MFA). SPF and CSA warned that “session token harvesting can bypass MFA,” making additional security controls important for companies handling cryptocurrency.
The agencies recommended measures including device binding, anomalous login detection and shorter session-token expiry periods. They also urged companies to tightly control API keys and internal credentials, use transaction-level safeguards, and separate development environments from production systems where possible.
For developers, the agencies issued a simple warning: “Do not execute code or download files from unknown or unverified sources.”
That risk is particularly relevant during technical hiring assessments, where candidates may be more willing to run unfamiliar code or software supplied by a supposed employer.
Firms urged to tighten security
SPF and CSA advised businesses to verify recruiters and companies through official channels and to be cautious when interviewers refuse to appear on video or direct candidates to unfamiliar websites. Companies have also been advised to strengthen controls around code repositories and automated deployment systems, with sensitive changes subject to additional review and approval.
The authorities highlighted that if a compromise is suspected, companies should isolate affected devices, log out active sessions and reset passwords. They should also check system logs for any suspicious changes.
The warning shows that crypto companies can be targeted through employees. Attackers may gain access to digital assets by first breaking into company systems. Singapore authorities advised affected organizations to contact their cybersecurity teams or service providers immediately. The advisory did not provide details about the companies affected or where the stolen crypto went.
Also Read: South Korea Sentences Delio CEO to 15 Years for Crypto Fraud
