LinkedIn Crypto Recruiter Scams Steal $11.8M in Singapore
In brief
- LinkedIn scammers posed as crypto recruiters, moving victims to spoofed email domains
- Malicious coding assessments downloaded malware capturing session tokens from victims
- Stolen tokens bypassed MFA, exposing source code repos and internal servers
- Singapore Police and Cyber Security Agency warn of long-running Web3 developer targeting campaigns
The Attack Flow
A victim was approached on LinkedIn by someone posing as a recruiter for a crypto company. Communication quickly moved to email, where the sender used a spoofed domain closely resembling a real firm's. Several interviews followed on Google Meet with the interviewer keeping their camera off throughout.
The victim was then sent to a spoofed website to complete a technical coding assessment on a company-issued device. During this step, malicious software was downloaded without the victim realizing it.
How the Malware Worked
The malware captured a session token, the string a service issues to keep a user logged in. Because this token represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim's Bitbucket account, where the company stores and manages its source code.
From there the attackers altered the employer's software systems and reached its internal servers. They collected credentials that were then used to get around transaction limits and approval checks and move funds. The damage cascaded from a single compromised employee device to the entire corporate infrastructure.
Broader Threat Landscape
Researchers have tracked a long-running operation they call Contagious Interview, in which fake recruiters steer Web3 developers toward malicious code, including more than 300 booby-trapped packages uploaded to the npm registry.
This isn't isolated. A group known as TraderTraitor has used fake job offers to reach corporate cloud systems. Others have posed as recruiters from Coinbase and Uniswap to get targets running commands. Those campaigns are attributed to North Korean hackers.
The Russian-speaking crew Crazy Evil built an entire fake Web3 company, ChainSeeker.io, and advertised blockchain analyst roles to lure applicants into installing wallet-draining malware.
What to Watch For
Singapore agencies advise individuals to verify recruiters through official channels. Treat an interviewer who will not turn on their camera as a warning sign. Never run code from an unverified source.
For companies, the agencies recommend securing API keys and internal credentials and strengthening multi-factor authentication and watching for unfamiliar devices and unusual network activity.


