
Attackers posed as recruiters for crypto firms on LinkedIn, used coding tests to steal session tokens and drain corporate wallets, Singapore authorities said.
Singapore authorities said attackers posing as recruiters for cryptocurrency companies stole roughly $11.8 million by exploiting a vector most employees don't question: a job offer on LinkedIn.
A joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore details how the operation worked. The attackers targeted employees at crypto firms, not individual retail holders. Over S$15.1 million in reported losses reflects the efficiency of that approach.
Fake recruiters reached out to targets on LinkedIn. The victims were invited to video interviews. The interviewer never turned on their camera. The calls happened over Google Meet, and communication flowed through spoofed email domains.
Then came the technical assessment. Candidates were directed to what appeared to be a standard coding challenge platform. It was a spoofed site. The moment a victim downloaded the assessment files, malware quietly installed itself on their machine.
The malware harvested session tokens – the temporary credentials that prove to a system you are already logged in. By stealing those tokens, the attackers bypassed multi-factor authentication entirely. MFA became a speed bump, not a wall.
With valid session tokens, the attackers accessed Bitbucket accounts, a widely used code repository platform. Once inside the codebase, they modified the actual software running at these crypto firms, altering transaction limits and security checks to enable unauthorized transfers.
The advisory urges individuals to verify job offers through official company channels before engaging with any recruiter. It also warns against downloading files from unknown sources, even when presented as part of a legitimate-seeming hiring process.
Session management policies need scrutiny, the agencies said. Token lifetimes should be short. Access to production code should require more than a single authenticated session. Hiring processes themselves need security protocols to ensure that people conducting interviews are who they claim to be.
The $11.8 million in reported losses likely understates the full scope. Singapore's willingness to issue a public advisory suggests authorities believe the campaign is ongoing and that more firms may be at risk.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.