Fake LinkedIn Crypto Job Scams Cost Singapore Victims $11.8M via Malware in Hiring Tests
Scammers posing as crypto recruiters on LinkedIn have drained at least $11.8 million from Singapore-based victims by embedding malware inside bogus coding assessments, turning the hiring process into a credential theft operation.
Fake LinkedIn Crypto Job Scams Cost Singapore Victims $11.8M via Malware in Hiring Tests
Scammers posing as crypto recruiters on LinkedIn have drained at least $11.8 million from Singapore-based victims by embedding malware inside bogus coding assessments, turning a routine step in the technical hiring process into a credential theft operation.
The attack vector is precise and deliberate. A target receives what appears to be a legitimate job inquiry from a recruiter at a crypto firm. They advance through a screening process and are eventually sent a coding challenge. The moment they run that assessment, malware executes on their machine and harvests active session tokens. Those tokens grant access to authenticated browser sessions without requiring a password or a second factor.
That last detail is the critical escalation here. Multi-factor authentication (MFA), the standard defense against stolen credentials, becomes irrelevant once an attacker holds a valid session token. The token is proof that authentication already happened. Malware planted during a bogus coding assessment harvested a session token, bypassing multi-factor authentication to reach a code repository. Code repositories are exactly where private keys, API credentials, and deployment scripts tend to live, making them high-value targets far beyond the individual victim's personal wallet.
The $11.8 million figure is specific to Singapore, and it is worth framing correctly. Compared to nine-figure DeFi exploits or exchange hacks, the dollar amount is modest. But the damage metric understates the structural threat. This is not a protocol vulnerability or a smart contract bug. It is a social engineering campaign that turns the hiring funnel itself into an attack surface, one that scales with the number of people actively seeking jobs in crypto. Singapore's position as a regional hub for digital asset firms, home to licensed exchanges and a dense concentration of blockchain developers, makes its workforce a concentrated target.
The pattern is not new. Crypto firms have faced hiring-process attacks before, most notably the 2022 Axie Infinity breach where a Sky Mavis engineer opened a fraudulent job offer delivered as a PDF, ultimately enabling the $625 million Ronin bridge hack. What has changed is the technical sophistication. Earlier campaigns often relied on phishing links or malicious attachments that endpoint security tools could flag. Embedding the payload inside a functional coding challenge that a developer is expected to run locally is harder to detect and easier to rationalize as legitimate.
The scam highlights vulnerabilities in digital hiring processes, urging firms to enhance security measures and verify recruiter identities.
The defense posture this demands goes beyond individual skepticism. Firms need to treat inbound recruiter contact as an unverified channel by default, implement strict policies around running externally sourced code on machines with access to internal systems, and consider sandboxed environments for any technical assessment a candidate or employee completes during a hiring process. Browser session hardening, including short token expiry windows and device binding, can limit the window an attacker has after token theft. None of these are exotic controls; most are already standard in high-security engineering environments outside crypto.
For individuals, the calculus is simpler but demanding: never run code from an unsolicited or unverified source on a machine that has access to anything sensitive. Verify recruiter identities through official company channels before engaging. Treat any coding challenge delivered outside a known, established platform with the same suspicion you would apply to a cold-call asking for your seed phrase.
Singapore's $11.8 million loss is a documented number from a single jurisdiction over a bounded period. The actual exposure across the global crypto hiring market, where remote-first teams and pseudonymous contributors are the norm, is almost certainly larger. The hiring process was not designed with adversarial actors in mind. It is now one.





