Loading article…
Singapore police and CSA warn of a crypto scam that stole US$11.8 million through fake recruiter offers and malware‑infected coding tests.
US$11.8 million (S$15.1 million) was siphoned from a Singapore‑based firm after a scammer posed as a recruiter, stole API keys via a malicious coding test, and bypassed transaction limits to move crypto assets, authorities said on Aug 14 2024【1】.
| At a glance | |
|---|---|
| Loss | US$11.8 million (S$15.1 million) |
| Date of advisory | 14 Aug 2024 |
| Scam method | Fake LinkedIn recruiter → spoofed email domain → video interview with video off → malicious coding assessment |
| Access vector | Compromised Bitbucket account & internal servers |
The victim was first contacted on LinkedIn by an individual claiming to recruit for a cryptocurrency‑related firm. After a series of email exchanges using a domain that closely mimicked a legitimate company’s address, the victim joined several Google Meet interviews where the interviewer's video remained disabled. The scammer then directed the victim to a counterfeit website to complete a technical coding assessment on a company‑issued laptop. The download installed malware that harvested the victim’s session token, allowing the attacker to bypass multi‑factor authentication and seize control of the victim’s Bitbucket repository. Because the repository was linked to the company’s internal codebase, the attacker could modify server configurations, retrieve internal credentials, and override transaction limits to execute cryptocurrency transfers without detection【2】.
Singapore’s Police Force and the Cyber Security Agency issued a joint advisory urging developers and technical staff to verify recruiter identities through official channels, to insist on video‑enabled interviews, and to avoid executing code from unverified sources. They also recommended businesses protect API keys with temporary credentials, enforce strict transaction limits, and strengthen multi‑factor authentication with device‑binding controls. Organizations are advised to monitor for unfamiliar devices, unexpected account access, and to isolate compromised systems immediately, revoking active sessions and resetting credentials where a breach is suspected【1】.
The incident underscores how attackers can leverage compromised development tools to infiltrate corporate crypto wallets, bypassing traditional security layers. As more firms integrate blockchain operations into their software stacks, vigilance over code‑repository access and recruiter verification will be critical to prevent similar multi‑million‑dollar losses.
Coverage is mostly measured — 187 of 189 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Aug 16, 2026 · How we report
Cryptocurrency allows for rapid movement of funds, offers greater anonymity, and often lacks the fraud protections found in traditional banking or credit card transactions.
Warning signs include high-pressure demands for immediate payment, instructions to keep a transaction secret, and unsolicited requests to deposit cash into a cryptocurrency kiosk.
Experts recommend hanging up immediately, refusing to send funds, and independently verifying the caller's identity by contacting the organization directly through a verified phone number.