Crypto

Singapore crypto job scam reportedly led to $11.8 million in losses

Reports say fake recruiter outreach led to corporate system breaches, though the cited Singapore advisory is not currently accessible.

Dev Ramirez

By Dev Ramirez · Crypto Correspondent

· 3 min read

Singapore crypto job scam reportedly led to $11.8 million in losses
Photo: Decrypt

A reported Singapore crypto job scam used a fake hiring process to gain access to company systems and enable cryptocurrency transfers worth $11.8 million, according to secondary reports citing Singapore authorities. The figure, also reported as S$15.1 million, has not been independently confirmed from the underlying advisory: the Singapore Police Force link cited by those reports currently returns a page-not-found notice.

Yahoo’s reproduction of a Decrypt report and separate reports from The Crypto Times and KuCoin say Singapore’s Police Force and Cyber Security Agency issued a joint warning on Aug. 14, 2026. The reports say the scheme targeted technology and cryptocurrency professionals, but do not identify an affected company, the destination of the funds or those responsible.

How did the Singapore crypto job scam reportedly work?

The reported attack began with a LinkedIn message from someone posing as a recruiter for a cryptocurrency company. Communications then moved to an email address using a lookalike domain, according to Yahoo’s report. The purported recruiter arranged several Google Meet interviews while keeping their camera off.

The target was then directed to a fraudulent website for a coding assessment and used a company-issued device to complete it. Secondary reports say the assessment caused malicious software to be downloaded onto that device.

That malware allegedly took a session token, a digital marker that keeps a user signed in to a service. Unlike a password, a stolen token can represent a session that has already cleared the login check. In the reported case, the attackers used it to get into the victim’s Bitbucket account, which was connected to the company’s source-code repository.

The reports say the intruders then altered automated deployment instructions, reached internal servers and obtained additional credentials. Those credentials were allegedly used to evade transaction limits and approval checks before cryptocurrency was transferred.

The sequence shows why multi-factor authentication, or MFA, may not stop every breach. MFA adds a second verification step during sign-in, but the reported attackers allegedly presented a token from an authenticated session rather than attempting a fresh login with a password.

What warning signs and safeguards were reported?

The reports say the agencies advised people to verify recruiters and companies through official channels, and to view an interviewer’s persistent refusal to appear on video as a warning sign. They also cautioned against running code or downloading files from unverified sources, particularly on a work device.

For organizations handling crypto assets, the reported guidance included protecting API keys and internal credentials, monitoring for unfamiliar devices or unusual network activity, and strengthening access controls. The Crypto Times also reported recommendations including device binding, alerts for unusual logins, shorter session-token lifetimes, transaction-level safeguards and separation of development from production systems where possible.

If a compromise is suspected, the agencies reportedly advised isolating affected systems, ending active sessions, resetting credentials and reviewing access logs. The reports link to a Singapore police advisory described as containing this guidance, but the supplied police page does not currently display the advisory.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto