Singaporean authorities have warned that a wave of fraudulent cryptocurrency job offers spread through LinkedIn has drained roughly $11.8 million from victims, with attackers using fake coding tests to plant malware and infiltrate corporate systems.
How the Scam Works
The scheme begins with what appears to be a legitimate recruitment pitch. Fraudsters posing as hiring managers approach targets on LinkedIn, dangling attractive roles at crypto and tech firms. Once a candidate is engaged, they are invited to complete a technical assessment — typically a coding exercise presented as a routine part of the interview process.
That test is the trap. When the victim downloads and runs the assessment files, hidden malware installs itself on the machine. In at least one case, the malicious software harvested a session token, allowing the attackers to slip past multi-factor authentication and gain access to a code repository without needing to steal a password directly.
A single stolen session token was enough to walk straight past multi-factor authentication.
Why It Matters
Session tokens are a prized target because they represent an already-authenticated login. By capturing one, criminals can effectively impersonate a legitimate user, sidestepping the security layers companies rely on to keep intruders out. The technique highlights a growing sophistication among scammers who blend social engineering with technical exploits.
The tactic bears the hallmarks of well-organized threat actors who have increasingly focused on the crypto industry, where valuable code, private keys, and digital assets can be exposed through a single compromised account.
- Scammers impersonate recruiters on LinkedIn to build trust.
- Fake coding assessments deliver malware to victims' devices.
- Stolen session tokens bypass multi-factor authentication entirely.
Staying Protected
Security experts advise job seekers to treat unsolicited technical tasks with caution, particularly any request to download and execute unfamiliar files. Verifying a recruiter's identity through official company channels and running suspicious files only in isolated environments can reduce exposure.
For companies, the incident underscores the importance of monitoring for anomalous access and shortening the lifespan of session tokens, so that even a compromised credential offers attackers only a narrow window. As crypto-related employment scams grow more elaborate, both individuals and firms face pressure to tighten defenses against threats disguised as opportunity.
