Singapore’s authorities are sounding the alarm on a scam operation that has siphoned roughly $11.8 million from cryptocurrency firms, and the attack vector is one most people wouldn’t think twice about: a LinkedIn job offer.

A joint alert from the Singapore Police Force and the Cyber Security Agency of Singapore details how attackers posing as recruiters for legitimate crypto companies lured victims through fake hiring processes, ultimately planting malware that gave them the keys to corporate code repositories. From there, they rewrote the rules, literally, modifying software to bypass transaction limits and funnel crypto out the door.

The anatomy of a very polished con

Fake recruiters reach out to targets on LinkedIn, typically employees at crypto-related firms. Eventually, the victim is invited to a video interview. The interviewer never turns on their camera. The call happens over Google Meet, communication flows through spoofed email domains.

Then comes the technical assessment. Candidates are directed to what appears to be a standard coding challenge platform. It’s not. The site is spoofed, and the moment a victim downloads the assessment files, malware quietly installs itself on their machine.