Fake LinkedIn Crypto Job Scams Have Cost $11.8M: Singapore
Scammers using fake crypto job offers on LinkedIn have defrauded victims of $11.8 million (S$15.1 million) in Singapore, compromising employers through malware-laden coding assessments.
Intelligence analysis by Gemini 2.5 Flash

A joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore revealed that fraudsters are luring individuals with bogus cryptocurrency job opportunities on LinkedIn. These scams involve victims undergoing fake coding assessments on company laptops, which then install malware to steal session tokens, bypassing multi-factor authentication and accessing cor…
Imagine someone pretends to be a friendly grown-up offering you a cool job building digital money, like Bitcoin. They ask you to do a test on your school computer, but secretly, while you're doing the test, they sneak a tiny spy into your computer. This spy then steals your special 'key' that lets you into your online accounts, even if you have a secret password. Then, they use your key to get into your parents' work accounts and steal their money. In Singapore, people lost a lot of money, like $11.8 million, because of these sneaky tricks.
Analysis
Singapore
The city-state of Singapore has become a focal point for a sophisticated new wave of cryptocurrency-related job scams, with reported losses reaching a staggering S$15.1 million, equivalent to $11.8 million USD. This alarming figure was disclosed in a joint advisory issued by the Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA), underscoring the severity of the threat within the nation's digital landscape. The advisory serves as a critical warning to both individuals and businesses operating in the burgeoning crypto sector, emphasizing the need for heightened vigilance against deceptive employment schemes.
The involvement of national security agencies like the SPF and CSA indicates that these are not isolated incidents but rather a coordinated criminal effort impacting the country's economic and cyber security. The public disclosure aims to raise awareness and prevent further victimization, reflecting a proactive stance by Singaporean authorities to combat cybercrime. The specific mention of the financial toll highlights the tangible impact on victims and the broader economy, necessitating a robust response from both governmental bodies and private entities.
Bitbucket
The modus operandi of these scams involves a cunning blend of social engineering and technical exploitation, with a key vulnerability identified in platforms like Bitbucket. Scammers initiate contact through professional networking sites such as LinkedIn, posing as recruiters for legitimate-sounding cryptocurrency firms. Once a victim expresses interest, they are guided through a seemingly authentic hiring process, which includes a crucial step: a coding assessment conducted on their company-issued laptop.
During this assessment, malicious software is covertly installed, designed to harvest session tokens. These tokens are critical pieces of data that allow attackers to bypass multi-factor authentication (MFA), a common security layer, and gain unauthorized access to the victim's corporate accounts, including those on development platforms like Bitbucket. This method is particularly insidious because it leverages the trust associated with professional recruitment and exploits the technical environment of the victim's workplace, turning a job opportunity into a vector for corporate espionage and financial theft.
S$15.1 million
The reported loss of S$15.1 million underscores the significant financial damage inflicted by these crypto job scams. This substantial sum represents the cumulative impact on numerous victims and their employers, highlighting the effectiveness of the scammers' tactics. The financial implications extend beyond direct monetary loss, encompassing potential data breaches, intellectual property theft, and reputational damage for the compromised companies.
Such large-scale financial fraud can erode public trust in online recruitment platforms and the legitimacy of the cryptocurrency industry itself. For individuals, losing money or having their professional accounts compromised can have devastating personal and career consequences. The scale of the losses necessitates a multi-faceted approach to prevention, involving not only law enforcement but also cybersecurity education for employees and robust security protocols within organizations to safeguard against similar future attacks.
Key points
- Scammers are using fake crypto job offers on LinkedIn to defraud victims.
- The scams have resulted in $11.8 million (S$15.1 million) in losses in Singapore.
- Victims are lured into coding assessments on company laptops, which install malware.
- The malware harvests session tokens to bypass multi-factor authentication and access corporate accounts.
- The Singapore Police Force and Cyber Security Agency of Singapore issued a joint advisory on the threat.
The joint advisory from the Singapore Police Force and Cyber Security Agency of Singapore demonstrates a proactive effort to combat these sophisticated scams. This increased awareness and official guidance could lead to better security practices among individuals and companies, potentially reducing future losses and fostering a more secure environment for legitimate crypto-related employment opportunities.
Despite official warnings, the advanced nature of these scams, which exploit trusted platforms like LinkedIn and bypass multi-factor authentication, suggests that individuals and companies remain highly vulnerable. The ongoing sophistication of these tactics means that significant financial losses could continue as scammers adapt, eroding confidence in digital employment and the broader crypto industry.



