Interestana
Home/News/Singapore Crypto Job Scams Exploit Fake Coding Tests, Costing Victims $11.8 Million
Decrypt3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Singapore Crypto Job Scams Exploit Fake Coding Tests, Costing Victims $11.8 Million

Singapore Crypto Job Scams Exploit Fake Coding Tests, Costing Victims $11.8 Million

An alarming trend of fake cryptocurrency job scams has resulted in an estimated $11.8 million in losses for victims in Singapore, according to a joint report by the Singapore Police Force and the Monetary Authority of Singapore (MAS). These elaborate schemes prey on individuals seeking opportunities in the rapidly expanding digital asset sector, impersonating legitimate cryptocurrency firms to lure unsuspecting applicants.

The modus operandi typically begins with the dissemination of enticing job advertisements, often appearing on social media platforms and popular job boards. These postings promise high salaries, attractive benefits, and exciting roles within the cryptocurrency industry, a field known for its high demand and lucrative potential. Once an individual expresses interest, they are usually invited to participate in a "coding assessment" or "technical interview," presented as a standard part of the hiring process.

However, this assessment is a carefully orchestrated trap. Victims are instructed to download and execute a program, which, unbeknownst to them, is embedded with malicious software. This malware is specifically designed to harvest session tokens from the victim's web browser. A session token is a critical piece of data that websites and applications use to maintain a user's logged-in state, effectively bypassing the need for repeated authentication. By stealing these tokens, attackers can circumvent crucial security measures, including multi-factor authentication (MFA), which is designed to add an extra layer of protection even if a password is compromised.

With the compromised session tokens in hand, the perpetrators gain unauthorized access to the victim's sensitive online accounts, particularly code repositories like GitHub or GitLab. These platforms are frequently linked to cryptocurrency wallets and trading accounts, serving as central hubs for managing digital assets. Once inside these repositories, the scammers can manipulate code, initiate fraudulent transfers of digital assets, or even introduce backdoors for future malicious activities. The Monetary Authority of Singapore, the nation's central bank and financial regulator, has issued advisories to the public, emphasizing the importance of vigilance and the need to rigorously verify the legitimacy of job offers, especially those in high-growth sectors like cryptocurrency. This includes cross-referencing information with official company websites and consulting with regulatory bodies. The substantial financial losses reported highlight the significant threat posed by these targeted cybercrimes to individuals and the broader digital asset ecosystem within Singapore.

Original source — read the full reporting at the publisher:

Read on Decrypt

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next