
Attackers used a spoofed coding assessment on a company device to steal session tokens and bypass transaction controls, the Singapore Police Force and CSA said.
Alpha Score of 74 reflects strong overall profile with strong momentum, moderate value, strong quality, strong sentiment.
A fake cryptocurrency job offer that infected a company-issued device with malware led to US$11.8 million in losses after attackers bypassed transaction controls, Singapore authorities said.
The Singapore Police Force and Cyber Security Agency of Singapore said on Aug. 14 that the victim was first contacted on LinkedIn by a scammer posing as a recruiter from a crypto-related company. Communication moved from LinkedIn to email, where the supposed recruiter used a spoofed domain that closely resembled the legitimate company’s address. The victim attended several interviews through Google Meet, though the person conducting them kept their camera off.
As the process advanced, the victim was sent to a spoofed website and asked to complete a technical coding assessment on a company-issued device. Malicious software was downloaded during the assessment without the victim realizing the device had been compromised.
Once installed, the malware harvested the victim’s session token, SPF and CSA said. Attackers used the stolen token to bypass multi-factor authentication and gain access to the victim’s Bitbucket account, which was connected to the employer’s code repository. From there, they modified the company’s automated software deployment instructions, then moved into internal infrastructure by remotely accessing its servers. Credentials collected during the compromise allowed the attackers to bypass transaction limits and approval checks used to control cryptocurrency transfers. The agencies said the attackers carried out crypto transactions that resulted in losses totaling US$11.8 million.
The use of a coding assessment as the malware delivery method resembles attacks previously documented across the cryptocurrency sector, where developers and other technical staff are approached with job offers before being asked to run code or install software.
In May, crypto.news reported on TrapDoor malware, which targeted cryptocurrency and AI developers through malicious software packages. Developer security platform Socket found at least 34 malicious packages and 384 connected versions across npm, PyPI and Rust ecosystems. According to Socket, the packages were designed to steal cryptocurrency wallet information alongside GitHub tokens, API keys, cloud credentials and SSH access.
Recruitment-themed attacks have also leaned on legitimate communication platforms to make initial contact appear credible. In April, an Obsidian malware campaign used LinkedIn and Telegram to approach cryptocurrency and finance professionals. Elastic Security Labs found that attackers convinced targets to install malicious community plugins for the legitimate Obsidian note-taking application. The malware, identified as PHANTOMPULSE, used three blockchain networks to receive commands.
Recruitment-based social engineering has previously been used by North Korean threat actors against cryptocurrency businesses. Google Cloud and Wiz reported in 2025 that UNC4899, also known as TraderTraitor, had approached employees at crypto companies through LinkedIn and Telegram while posing as recruiters. In incidents involving remote job offers, employees were persuaded to execute malicious Docker containers on their workstations. Google said one incident allowed UNC4899 to disable multi-factor authentication on a privileged Google Cloud account and access wallet-related services. SPF and CSA have not attributed the latest US$11.8 million loss to North Korea or any other hacking group.
Following the incident, the agencies advised businesses and individuals–particularly those in technology and cryptocurrency–to verify the identities of recruiters and the companies they claim to represent before interacting with job-related files, websites or software. Companies were advised to protect application programming interface keys and internal credentials while strengthening multi-factor authentication. Securing code repositories and software deployment pipelines was specifically recommended.
For businesses that suspect a breach, SPF and CSA advised isolating affected equipment immediately and revoking active sessions. Credentials should be reset. Access logs should be examined for signs that attackers entered other accounts or company infrastructure. Authorities also advised checking whether code repositories, internal servers, accounts or approval workflows had been changed during the compromise. Internal cybersecurity teams or external security providers should be contacted without delay.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.