Invest2 distinct publishers3 min readUpdated
A joint police and cyber agency advisory puts fake-job crypto losses at S$15.1m. The more consequential detail is three exchange operations in four months, all running off the same tooling.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The Singapore Police Force and the Cyber Security Agency of Singapore have issued a joint advisory on crypto scams built on fake job offers and compromised software systems, putting losses at roughly $11.8 million, or S$15.1 million [1]. The figure is not the interesting part; the delivery mechanism behind the response is, because police have now run three joint operations with crypto exchanges inside about four months [16][9][10][11].
The advisory covers two quite different attacks. The retail version starts with a social media advertisement for an online job or an investment return, after which someone posing as a guide walks the victim through opening a crypto account and buying tokens; the payout never arrives, and some targets are talked into surrendering login details or a seed phrase [8]. The enterprise version, as described by Decrypt, is a supply-chain compromise wearing a recruiter's clothes: an approach on LinkedIn, a move to email from a spoofed domain, several Google Meet interviews with the interviewer's camera off [3], then a coding assessment on a spoofed site completed on a company-issued laptop, which installed malware [4]. The malware captured a session token, which represents an already-authenticated session and so walked past multi-factor authentication into the victim's Bitbucket account [5]. From there the attackers altered the employer's systems, reached internal servers and harvested credentials used to get around transaction limits and approval checks [6]. The agencies name no company, no destination for the funds, and no attacker [7].
The operational cadence is where this stops being a warning notice. From March 16 to April 15, police blocked about S$2.86 million with Coinbase and Upbit, interrupting more than 90 cases in which victims had already started sending funds [9]. A six-week follow-on from April 16 to May 31 stopped more than S$4.2 million with seven firms, including Coinbase, Coinhako, Gemini, Independent Reserve, OKX and StraitsX [10]. June added more than S$2.9 million and contact with over 130 people flagged by exchanges [11]. That is roughly S$9.96 million blocked across the three [1], about two-thirds the size of the single fake-job loss the advisory describes [2] and about 5 per cent of the S$182.2 million Singapore lost to crypto-linked scams in 2025 [3]. Chainalysis and TRM Labs supplied the tracing tools to the Anti-Scam Centre and Cyber Investigation Branch for all three [12], and in June the SPF passed blockchain intelligence to the FBI and the New South Wales Police cybercrime squad [13]. Same tooling, same partners, escalating scope: that is a standing process, not a task force.
The backdrop is a market where headline numbers are improving unevenly. Total scam and cybercrime cases fell 24.8 per cent to 41,974 in 2025 and losses fell to S$913.1 million from about S$1.1 billion [15], but crypto was still about a fifth of the total [14], and average loss per case rose roughly 10 per cent, to about S$21,800 [4]. Fewer victims, each worth more.
For operators, the corporate half of the advisory is the actionable half: secure API keys and internal credentials, harden MFA, watch for unfamiliar devices, and on suspected compromise isolate systems, revoke active sessions and reset credentials [18]. Two things to watch. Whether the seven-firm April operation becomes the floor for participation rather than a high-water mark, and whether any exchange that declines to share customer signals gets named. Note also that Cryptopolitan dates these operations to 2026 while the loss baseline is 2025 [16][14]; the year labelling in secondary coverage is worth checking against the SPF's own releases.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The Singapore Police Force and the Cyber Security Agency of Singapore issued a joint advisory on scams involving fake job offers and compromised software systems, putting losses at $11.8 million (S$15.1 million).
The agencies described a victim approached on LinkedIn by someone posing as a recruiter for a crypto company, moved to email from a spoofed domain closely resembling a real firm's, followed by several Google Meet interviews in which the interviewer kept their camera off.
The victim was sent to a spoofed website to complete a technical coding assessment and did so on a company-issued device, downloading malicious software without realising it.
The malware captured a session token, the string a service issues to keep a user logged in; because it represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim's Bitbucket account, where the company stores and manages source code.
From the compromised account the attackers altered the employer's software systems and reached internal servers, collecting credentials later used to get around transaction limits and approval checks and move funds.
The advisory does not name any company, say where the funds went, or attribute the attacks to anyone.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Official advisory, relayed secondhand and unattributed
The core facts originate in a named joint government advisory and are reported consistently by two independent outlets, with specific figures, dates and named institutions. Against that, neither outlet links or quotes a primary document - Decrypt cites Straits Times and Channel NewsAsia coverage of the statement - and the advisory withholds the victim company, the fund destination and any attribution, so the intrusion narrative cannot be independently checked.
Recurring public-private interdiction with named participants
Adoption of the exchange-police interdiction model is unusually well evidenced: three operations inside four months, seven named firms plus Upbit, two named analytics vendors embedded in Anti-Scam Centre and Cyber Investigation Branch workflow, quantified blocked amounts totalling roughly S$9.96 million, and outbound intelligence sharing with the FBI and NSW Police. What is not evidenced is corporate adoption of the advisory's hardening guidance, or interception coverage beyond about 5.5% of annual crypto-scam losses.
Headline figure prominent, institutional build-out understated
Claims are not inflated: figures come from an official advisory, are reported consistently, and are presented as prevented-loss and lost-value amounts rather than projections. The mild negative reflects understatement in the other direction - the recurring three-operation cadence with fixed vendor tooling and cross-border sharing is the more structural development, yet it appears as background detail in one outlet and not at all in the other, while both lead on a single dollar total whose composition (retail victims versus corporate compromise) is never reconciled.
Agency and vendor visibility incentives, trade-outlet distribution
Prevented-loss totals are self-reported by the agencies that ran the operations, and the named exchanges and two analytics vendors gain reputational visibility from disclosed participation, so those figures should be read as institutional communications. Both publishers are crypto trade outlets, and one carries a newsletter promotion and an investment disclaimer inline. Mitigating factors: Decrypt discloses that it sought comment from LinkedIn, and no source promotes a commercial product or price.
Consistent official numbers, thin independent verification
Confidence is moderate: two independent outlets agree on the headline figure and neither contradicts the other, and the operational figures are specific and internally consistent. It is held down by single-source dependence for each half of the story - only Cryptopolitan carries the operations and statistics, only Decrypt carries the intrusion chain - by the absence of a primary document, and by an unresolved ambiguity in what the $11.8m total covers.
invest
DOJ Flew a $165M Ponzi Case Home From Fiji, Which Resets the Affiliate Math1 distinct publisher
invest
Washington deputises private cyber firms, and hands their customers a liability question1 distinct publisher
product
Binance gives agents a trading seat, and gives users the permission slip1 distinct publisher
invest
Chainalysis sues over ICE's $94.7M award to TRM Labs, and the filing is sealed1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026
1 article · August 14, 2026