Singapore skyline at dusk with the Merlion fountain and illuminated waterfront buildings along Marina Bay.
TECHNOLOGY

Singapore Crypto Job Scam Causes $11.8M in Losses

Image credit: Shutterstock

A fake cryptocurrency job offer led to US$11.8 million in losses after attackers compromised a company-issued device and gained access to internal systems used to authorize crypto transfers.

The Singapore Police Force and Cyber Security Agency of Singapore warned about the attack on August 14. Authorities said the victim was approached on LinkedIn by someone impersonating a recruiter from a cryptocurrency-related company.

Fake Recruiter Used Coding Assessment to Steal Session Token 

The scammer moved further communication to email using a spoofed domain that closely resembled the legitimate company’s address. Several Google Meet interviews followed, with the interviewer keeping their camera switched off.

The victim was then directed to a fake website to complete a technical coding assessment using a company-issued device. During the assessment, the victim unknowingly downloaded malicious software.

The malware harvested a session token that allowed the attackers to bypass multi-factor authentication and access the victim’s Bitbucket account, which was connected to the employer’s code repository.

Bitbucket Compromise Led to $11.8M in Crypto Transfers

After gaining access to Bitbucket, the attackers modified the company’s automated software deployment instructions and remotely accessed internal servers.

They then harvested credentials that allowed them to bypass transaction limits and approval checks before carrying out unauthorized cryptocurrency transfers. SPF and CSA put the losses at about US$11.8 million, or S$15.1 million.

Authorities did not disclose the affected company, the cryptocurrencies transferred or whether any of the funds have been recovered.

Singapore Urges Firms to Secure Code Repositories and Transfer Controls

SPF and CSA warned that fake recruiters may target developers and technical professionals with assignments designed to obtain credentials or install malicious code.

Authorities advised businesses to protect API keys and internal credentials, strengthen multi-factor authentication and secure code repositories and deployment pipelines. Companies should also isolate compromised systems, revoke active sessions, reset credentials and review access logs when suspicious activity is detected.

The agencies also advised businesses to implement transaction limits and other safeguards that cannot be bypassed. The August 14 advisory did not disclose whether the attackers have been identified or whether any of the US$11.8 million has been recovered.

More For You

Explore More News