Singapore Warns of Crypto Job Scams After $11.8M Corporate Crypto Theft
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Singapore’s crypto job scam caused $11.8 million in losses through fake recruitment and malware.
- Attackers stole a Bitbucket session token and bypassed MFA to access company systems.
- Attackers altered deployment instructions, harvested credentials, and completed unauthorized cryptocurrency transfers.
Singapore authorities have linked $11.8 million in cryptocurrency losses to a scam built around fake recruitment activity. The Singapore Police Force and Cyber Security Agency of Singapore issued a joint advisory on August 14. The case targeted technology and cryptocurrency professionals through job approaches, staged interviews, and malicious coding assessments. Investigators said attackers used the process to reach corporate systems and trigger unauthorized cryptocurrency transfers.
Crypto Job Scams Target Tech Workers in Singapore
The Singapore crypto job scams began with a LinkedIn approach from someone posing as a recruiter. The scammer claimed to represent a cryptocurrency company and later moved communication to email. Moreover, the attacker used a spoofed domain that closely resembled the real company’s web address. The victim then joined Google Meet interviews, while the supposed interviewer kept the camera turned off.
After those calls, the recruiter directed the victim to a fake website for a technical assessment. The victim completed the coding task on a company-issued device. During that process, malicious software reached the device without the victim recognizing the threat. As a result, the malware captured a session token tied to the victim’s Bitbucket account.
The stolen token allowed the attacker to bypass multi-factor authentication. Since Bitbucket connected to the employer’s code repository, the breach opened a path into development systems. The attacker then changed automated software deployment instructions and reached internal servers. Additionally, the intruder collected credentials connected to transaction controls and approval processes.
JUST IN: Singapore police reveal a crypto-related fake recruitment scam exploiting LinkedIn, Google Meet, and MFA-bypassing malware, causing $11.8M in losses. $BTC / $ETH risk signals stay elevated as phishing and token theft linger; stay vigilant. pic.twitter.com/Alpa8U2lpj
— Bpay News (@bpaynews) August 14, 2026
Stolen Session Token Opens Corporate Systems
Authorities said the attackers used those credentials to bypass transaction limits and approval checks. They then carried out cryptocurrency transfers from the compromised environment. Notably, the attack did not rely on a single stolen password. Instead, it combined social engineering, malware, repository access, server intrusion, and control over deployment processes.
SPF and CSA highlighted session token theft as part of the intrusion. Multi-factor authentication can block many unauthorized logins, but stolen session tokens create another route. Therefore, the agencies urged companies to add device binding, anomalous login detection, and shorter session expiry periods. They also advised businesses to revoke suspicious sessions quickly.
The advisory also focused on protecting API keys and internal credentials. Companies should limit access, keep detailed logs, and use short-lived credentials when possible. Moreover, transaction limits and approval workflows should operate at the API level. Such controls can reduce the risk of attackers bypassing safeguards through direct API calls.
Agencies Urge Tighter Development Security Controls
SPF and CSA also recommended stricter checks around technical assessments and recruitment contacts. Workers should verify recruiters through official company channels before opening files or running code. Similarly, developers should scan software and dependency packages before using them. The agencies said untrusted content should run only in isolated environments, not on company systems.
Businesses also require stronger visibility and control over the code repositories and deployment pipelines. Multi-party reviews can be used to identify unanticipated changes prior to deployment. Meanwhile, access logs can provide details of unfamiliar machines, access privileges, or unusual account activity. Stronger network monitoring can also detect unauthorized outbound traffic from an internal server.
The advisory recommends that teams isolate suspected compromised systems immediately. Companies should revoke active sessions, reset credentials, and review access records. Moreover, they need to review for unauthorized changes made in repositories, internal servers, and approval workflows.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







