A fake recruitment scheme on LinkedIn let hackers breach a Singapore crypto firm's systems and bypass MFA, resulting in US$11.8 million in losses.

Fake Job Interview Nets Hackers US$11.8 Million in Singapore Crypto Firm Breach

The420 Web Correspondent
5 Min Read

Singapore authorities have disclosed details of an elaborate cryptocurrency job scam that resulted in losses of approximately US$11.8 million, after attackers posing as recruiters used a fake technical assessment to infiltrate a company’s internal systems and ultimately bypass its cryptocurrency transaction controls. The Singapore Police Force and the Cyber Security Agency of Singapore issued a joint advisory on the case, warning that the incident highlights a growing blind spot in how technology and cryptocurrency firms vet recruitment processes.

The scheme unfolded with unusual patience and technical sophistication, beginning not with a phishing link or a malicious attachment but with what appeared to be a routine job opportunity on LinkedIn. That entry point, authorities say, ultimately gave attackers a foothold deep enough to bypass multi-factor authentication and clear transaction approval checks meant to prevent exactly this kind of theft.

A Recruitment Process Built to Deceive

According to the joint statement, the victim was first approached on LinkedIn by someone posing as a recruiter representing a cryptocurrency-related company. Communication then shifted to email, using a spoofed domain closely mimicking that of a legitimate firm, a detail designed to survive casual scrutiny from a target who had no reason to doubt the opportunity’s authenticity.

The process proceeded through several video interviews conducted over Google Meet, during which the interviewer’s camera remained switched off throughout, a detail that in hindsight served to conceal the absence of any real interviewer. As part of the supposed hiring process, the victim was asked to complete a coding or technical assessment, a step that has become an increasingly common malware delivery vector across the cryptocurrency industry, where developers are routinely asked to run code or install software as part of legitimate recruitment.

Once the malicious code executed, attackers gained access to the victim’s company-issued device and, from there, to internal infrastructure including the firm’s code repository. Investigators found that the attackers used this access to harvest an active session token, a technique that allowed them to sidestep multi-factor authentication entirely rather than attempting to defeat it directly.

When MFA Is Not Enough

The case has drawn particular attention because it demonstrates a limitation increasingly familiar to security researchers but still underappreciated in corporate risk planning: multi-factor authentication protects against stolen passwords, but not against a stolen session that has already been authenticated. Once attackers held a valid session token, they were able to move through the company’s systems with the same access as a legitimate employee, eventually reaching credentials that let them bypass transaction limits and approval checks governing cryptocurrency transfers.

With those controls circumvented, the attackers executed transactions that collectively resulted in losses of US$11.8 million, funds that, as with most cryptocurrency theft, become significantly harder to trace or recover once moved across exchanges and mixing services. Authorities have not disclosed the identity of the affected company or confirmed whether any portion of the stolen funds has since been recovered.

Singapore’s Wider Scam Problem

The incident lands against the backdrop of a scam and cybercrime landscape that Singapore’s own police statistics show has grown substantially in recent years, with losses touching a record high of roughly 1.1 billion Singapore dollars in 2024 alone before beginning to moderate somewhat through 2025. Cryptocurrency-related fraud has remained a persistent contributor to that total, reflecting both the sector’s appeal to sophisticated attackers and the practical difficulty of reversing transactions once digital assets leave a victim’s control.

In response to this case specifically, the Singapore Police Force and Cyber Security Agency have recommended that companies handling cryptocurrency adopt device binding, anomalous login detection and shorter session-token expiry windows, alongside tighter controls over application programming interface keys and internal credentials. The agencies have also urged firms to treat recruitment-linked technical assessments with the same scrutiny typically reserved for unsolicited email attachments, given how effectively the format has been weaponised across the sector.

The case adds to a growing body of similar incidents in which cryptocurrency and technology firms have been targeted through recruitment-themed social engineering, a pattern security researchers say has become one of the most consistently effective ways to breach organisations that might otherwise maintain robust technical defences against conventional phishing.

Stay Connected