Cyber Security

How a fake coding test drained $11.8 million from a crypto company

Singapore authorities reveal how a fake LinkedIn job offer and a malicious coding test led to an $11.8 million crypto loss via session token theft.
How a fake coding test drained $11.8 million from a crypto company

I received a message on Signal last month from a developer who almost fell for a similar trap. The recruiter had a polished profile, a history of endorsements from recognizable names in the Web3 space, and a job description that offered a 40% pay bump. The developer only backed out because the 'coding assessment' required him to download a custom environment instead of using a standard browser-based IDE. That intuition saved his company. Others were not so lucky. The Singapore Police Force and the Cyber Security Agency of Singapore recently detailed a breach where a single employee’s desire for a better career path resulted in a US$11.8 million loss.

This incident is a textbook example of how modern threat actors bypass sophisticated defenses by targeting the human element at the edge of the network. The attackers did not look for a zero-day in a firewall or a flaw in a cryptographic protocol. They looked for a person who was willing to prove their technical worth on a company-issued device. By the time the security operations center noticed the unusual activity, the attackers had already moved from a LinkedIn inbox to the heart of the company's financial infrastructure.

The psychological hook of a dream job

Social engineering succeeds because it exploits professional ambition. The campaign began on LinkedIn, where a scammer posing as a recruiter for a cryptocurrency firm approached the victim. This phase was about building rapport and legitimacy. The attacker moved the conversation to email, using a spoofed domain that mirrored a real company’s address. To an employee skimming their inbox, a one-letter difference in a domain name is almost invisible.

The interview process further solidified the deception. The victim attended several rounds on Google Meet. The person on the other end kept their camera off, citing technical issues or privacy, a common tactic used to hide the identity of threat actors operating from jurisdictions like North Korea. This stage is the digital Trojan horse. The goal is to make the victim feel like they are in a high-stakes professional evaluation, which lowers their guard when the 'technical assessment' arrives.

When the coding assessment becomes a weapon

In the final stage of the recruitment process, the victim received a link to a spoofed website. They were told to complete a coding task on their company-issued laptop. This request is standard in the software industry, which makes it an ideal delivery mechanism for malicious payloads. As the victim ran the provided code or installed the suggested software environment, malware executed in the background.

This specific malware was designed to harvest session tokens. From a risk perspective, this is a nightmare scenario for any IT department. Session tokens are the digital equivalent of a VIP club bouncer recognizing your face after you have already shown your ID. Because the token proves the user has already authenticated, the attacker does not need to know the password or have access to the victim’s physical MFA device. They simply inject the stolen token into their own browser and inherit the victim’s active session.

Poisoning the software deployment pipeline

Once the attackers had the session token, they accessed the victim’s Bitbucket account. Bitbucket is the dark matter of a development environment; it is often invisible to general staff but contains the core logic of the company’s business. Accessing a repository is a systemic failure because it allows attackers to see how the company builds and deploys software.

Behind the scenes, the intruders modified the automated software deployment instructions. By changing the code in the repository or the scripts that tell the servers how to run that code, the attackers gained a foothold in the internal infrastructure. This lateral movement allowed them to jump from a single compromised laptop to the production servers that handle actual money. In the event of a breach like this, the trust model of the entire development lifecycle is broken. The attackers were no longer just guests on a laptop; they were effectively administrators of the company’s code.

Bypassing the final line of financial defense

The most damaging part of the intrusion occurred when the attackers reached the systems used to process cryptocurrency transfers. Most firms use transaction limits and multi-person approval checks as a countermeasure against internal fraud or single-point failures. However, the attackers used the credentials they collected during their movement through the network to modify these controls.

By rewriting the rules that governed how much money could leave the company and who needed to approve it, the attackers cleared the way for massive transfers. The resulting transactions totaled US$11.8 million. This highlights an architectural paradox: even if your network perimeter is resilient, your internal logic remains exploitable if an attacker can impersonate a high-privilege user at the root level. The attackers did not break the encryption of the blockchain; they broke the human process that managed the keys.

The shadow of state-sponsored activity

While Singaporean authorities did not officially attribute this specific attack to a specific group, the tactics are remarkably similar to campaigns run by North Korean threat actors. Groups like UNC4899, also known as TraderTraitor, have focused heavily on cryptocurrency and blockchain companies since at least 2020. They are known for approaching developers through LinkedIn and Telegram and persuading them to run malicious Docker containers or install 'community plugins' for apps like Obsidian.

In previous incidents, these groups have used AI-generated personas to impersonate trusted contacts. These campaigns place developer environments at the point of compromise, seeking GitHub tokens, SSH keys, and cloud credentials. Proactively speaking, these are not random acts of cybercrime but targeted operations designed to fund national interests. The precision required to modify deployment pipelines and bypass transaction checks suggests a deep familiarity with the internal workflows of cryptocurrency firms.

Hardening the human and technical firewall

To prevent a repeat of this $11.8 million disaster, businesses must move beyond basic security awareness training. Relying on an employee to spot a spoofed domain is a reactive strategy that will eventually fail. A more granular approach involves securing the infrastructure so that a single compromised device cannot bring down the entire firm.

First, companies must enforce hardware-based multi-factor authentication, such as FIDO2 security keys. Stolen session tokens are much harder to use when the system requires a physical touch on a dedicated device for sensitive actions like accessing code repositories. Second, access to Bitbucket and other mission-critical tools should be managed through Just-in-Time (JIT) provisioning. No developer should have permanent, standing access to production deployment pipelines.

Finally, any job-related technical assessment should happen in a sandboxed environment that is completely isolated from the corporate network. If a recruiter asks a candidate to run code on a company laptop, that should trigger an immediate alert in the security operations center. Assessing the attack surface means recognizing that a developer’s laptop is often the most valuable target in the building.

Practical takeaways for technical teams

  1. Use dedicated, non-corporate hardware for all recruitment-related tasks, including coding tests and interviews.
  2. Implement strict application-level plugin policies for productivity tools to prevent the execution of unauthorized code.
  3. Audit your Bitbucket and GitHub access logs for session hijacking signs, such as logins from unexpected IP addresses using valid tokens.
  4. Revoke active sessions immediately if an employee reports suspicious behavior during an external interaction.
  5. Strengthen internal transaction controls by requiring approvals from devices that are physically separated from the development network.

Sources: Singapore Police Force (SPF), Cyber Security Agency of Singapore (CSA), Google Cloud Mandiant (UNC4899 Report), MITRE ATT&CK Framework.

Disclaimer: This article is for informational and educational purposes only and does not replace a professional cybersecurity audit or incident response service.

bg
bg
bg

See you on the other side.

Our end-to-end encrypted email and cloud storage solution provides the most powerful means of secure data exchange, ensuring the safety and privacy of your data.

/ Create a free account