Blockwind News

Choose your region & language
🇸🇬
Singapore新加坡
🇭🇰
Hong Kong香港
🇨🇳
China中国大陆
Choose your region & language
Asia Pacific
🇸🇬
Singapore新加坡
🇭🇰
Hong Kong香港
China
🇨🇳
China中国大陆
Select your regional site

$15 Million Cryptocurrency Scam Exploits Fake Job Offer and Company Software Systems

Nicole
Nicole

18th August 2026

By Shubhii Verma

A sophisticated cryptocurrency scam involving a fake job recruitment process and malicious software has resulted in losses of approximately US$11.8 million (S$15.1 million), according to Singapore authorities.

The Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) issued a joint advisory on August 14, warning the public about the increasingly sophisticated tactics used by scammers to gain access to corporate systems and cryptocurrency accounts.

How the $15 Million Cryptocurrency Scam Began

The victim was initially approached on LinkedIn by an individual posing as a recruiter from a cryptocurrency-related company. The scammer continued the recruitment process through email, using a fraudulent domain designed to resemble a legitimate corporate website.

The victim subsequently participated in several video interviews through Google Meet. During the calls, the interviewer’s video was disabled, making it difficult for the victim to verify the recruiter’s identity.

Malicious Software Gave Attackers Access to Company Systems

The scam became more sophisticated when the victim was asked to complete what appeared to be a legitimate technical coding assessment. The victim was directed to a fake website and instructed to download software onto a company-issued computer as part of the assessment.

Unknown to the victim, the software contained malicious code that gave the attackers access to the victim’s systems.

The attackers subsequently gained control of the victim’s Bitbucket account, a platform commonly used by software developers to store and manage source code. Because the account was connected to the company’s code repositories, the attackers were able to use the compromised credentials to gain deeper access to the company’s internal infrastructure.

How Scammers Bypassed Crypto Transaction Safeguards

This access ultimately allowed the scammers to infiltrate internal servers and bypass existing transaction limits and approval mechanisms. They then carried out unauthorised cryptocurrency transfers, resulting in losses running into millions of dollars.

The incident highlights how cryptocurrency-related scams are increasingly moving beyond traditional phishing attempts. Rather than directly targeting crypto wallets or exchanges, criminals are exploiting employment processes, developer tools and corporate IT infrastructure to gain access to valuable digital assets.

The case also demonstrates the risks associated with remote recruitment and technical assessments. Job seekers may be more willing to download unfamiliar software or visit external websites when they believe they are participating in a genuine hiring process.

Singapore Authorities Warn About Crypto Job Scams

Singapore authorities urged individuals and businesses to exercise caution when dealing with unsolicited job offers, particularly those involving cryptocurrency, blockchain or technology companies. Job applicants should independently verify recruiters and companies, carefully examine email domains and avoid downloading software from unverified websites.

Companies, meanwhile, are encouraged to strengthen access controls, implement multi-factor authentication, regularly review user permissions and maintain additional approval safeguards for high-value cryptocurrency transactions.

The incident serves as a reminder that corporate cybersecurity and cryptocurrency security are increasingly interconnected. A compromised employee account can potentially provide attackers with access not only to sensitive company information but also to digital assets worth millions of dollars.

Quick Link

Share This Article