The interview went through several rounds of Google Meet calls, and the other side's camera was never turned on. That's one of the few details that left a trace in a scam case disclosed last Friday by the Singapore Police Force and the Cyber Security Agency of Singapore — and at the time, the victim didn't think much of it.
The joint announcement from both agencies states that this scheme, which impersonates crypto companies during recruitment, has caused total losses of $11.8 million (roughly S$15.1 million). According to the case description, the victim was first approached on LinkedIn by someone posing as a headhunter for a crypto firm, and the conversation then moved to email using a domain deliberately designed to mimic the real company's. This was followed by several rounds of Google Meet interviews, during which the interviewer's camera stayed off the entire time. Finally, the victim was directed to a fake website to complete a technical coding test — using a company-issued laptop — and it was during this process that malware was quietly installed.
The truly fatal step was what the malware was designed to target: session tokens, the authentication strings that services use to keep users logged in. Armed with these tokens, attackers didn't need passwords or verification codes — they could impersonate a legitimate user who had "already logged in," bypassing multi-factor authentication entirely to gain access to the victim's Bitbucket account, where the company stored and managed its source code. From there, the attackers modified the employer's software systems, worked their way into internal servers, harvested credentials, and ultimately used them to get around transaction limits and review mechanisms to transfer the funds out. The announcement did not name the victim company, nor did it disclose where the funds went or attribute blame to any specific party. Decrypt has reached out to LinkedIn for comment and will update this story if they respond.
Not an Isolated Case, But a Playbook
Researchers have long tracked a campaign codenamed "Contagious Interview" that follows an identical pattern: fake headhunters lure Web3 developers into installing malicious code, with over 300 compromised packages uploaded to the npm registry alone. Another group known as TraderTraitor typically uses fake job offers to break into corporate cloud systems rather than targeting individual wallets directly — some researchers interpret this as evidence that the bulk of the funds are usually stored there. Other attackers have impersonated recruiters from Coinbase and Uniswap to trick targets into running specific commands.
These campaigns are often attributed to North Korean hackers, but the playbook isn't exclusive to them. The Russian-speaking cybercrime group Crazy Evil went so far as to set up an entire fake company, ChainSeeker.io, publicly recruiting "blockchain analysts" as a way to trick applicants into installing wallet-draining malware.
The advice from Singapore's two agencies to individuals is straightforward: verify recruiters' identities through official channels, treat an interviewer's refusal to turn on their camera as a red flag, and never run code from unverified sources. For businesses, the recommendations include strengthening API key and internal credential management, tightening multi-factor authentication, and staying alert to unfamiliar devices and unusual network activity. If a breach is suspected, affected systems should be isolated immediately, existing login work sessions revoked, credentials reset, and access logs reviewed.






