Skip to content

Invest2 publishers3 min readPublished

Singapore's exchange raids stop looking like incident response

A joint police and cyber agency advisory puts fake-job crypto losses at S$15.1m. The more consequential detail is three exchange operations in four months, all running off the same tooling.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Singapore's exchange raids stop looking like incident response
Generated illustration

What happened

  • The Singapore Police Force and the Cyber Security Agency of Singapore issued a joint advisory on scams involving fake job offers and compromised software systems, putting losses at $11.8 million (S$15.1 million).
  • The agencies described a victim approached on LinkedIn by someone posing as a recruiter for a crypto company, moved to email from a spoofed domain closely resembling a real firm's, followed by several Google Meet interviews in which the interviewer kept their camera off.
  • The victim was sent to a spoofed website to complete a technical coding assessment and did so on a company-issued device, downloading malicious software without realising it.
  • The malware captured a session token, the string a service issues to keep a user logged in; because it represents an already-authenticated session, presenting it bypassed multi-factor authentication and opened the victim's Bitbucket account, where the company stores and manages source code.
  • From the compromised account the attackers altered the employer's software systems and reached internal servers, collecting credentials later used to get around transaction limits and approval checks and move funds.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

The Singapore Police Force and the Cyber Security Agency of Singapore have issued a joint advisory on crypto scams built on fake job offers and compromised software systems, putting losses at roughly $11.8 million, or S$15.1 million [1]. The figure is not the interesting part; the delivery mechanism behind the response is, because police have now run three joint operations with crypto exchanges inside about four months [16][9][10][11].

The advisory covers two quite different attacks. The retail version starts with a social media advertisement for an online job or an investment return, after which someone posing as a guide walks the victim through opening a crypto account and buying tokens; the payout never arrives, and some targets are talked into surrendering login details or a seed phrase [8]. The enterprise version, as described by Decrypt, is a supply-chain compromise wearing a recruiter's clothes: an approach on LinkedIn, a move to email from a spoofed domain, several Google Meet interviews with the interviewer's camera off [3], then a coding assessment on a spoofed site completed on a company-issued laptop, which installed malware [4]. The malware captured a session token, which represents an already-authenticated session and so walked past multi-factor authentication into the victim's Bitbucket account [5]. From there the attackers altered the employer's systems, reached internal servers and harvested credentials used to get around transaction limits and approval checks [6]. The agencies name no company, no destination for the funds, and no attacker [7].

The operational cadence is where this stops being a warning notice. From March 16 to April 15, police blocked about S$2.86 million with Coinbase and Upbit, interrupting more than 90 cases in which victims had already started sending funds [9]. A six-week follow-on from April 16 to May 31 stopped more than S$4.2 million with seven firms, including Coinbase, Coinhako, Gemini, Independent Reserve, OKX and StraitsX [10]. June added more than S$2.9 million and contact with over 130 people flagged by exchanges [11]. That is roughly S$9.96 million blocked across the three [1], about two-thirds the size of the single fake-job loss the advisory describes [2] and about 5 per cent of the S$182.2 million Singapore lost to crypto-linked scams in 2025 [3]. Chainalysis and TRM Labs supplied the tracing tools to the Anti-Scam Centre and Cyber Investigation Branch for all three [12], and in June the SPF passed blockchain intelligence to the FBI and the New South Wales Police cybercrime squad [13]. Same tooling, same partners, escalating scope: that is a standing process, not a task force.

The backdrop is a market where headline numbers are improving unevenly. Total scam and cybercrime cases fell 24.8 per cent to 41,974 in 2025 and losses fell to S$913.1 million from about S$1.1 billion [15], but crypto was still about a fifth of the total [14], and average loss per case rose roughly 10 per cent, to about S$21,800 [4]. Fewer victims, each worth more.

For operators, the corporate half of the advisory is the actionable half: secure API keys and internal credentials, harden MFA, watch for unfamiliar devices, and on suspected compromise isolate systems, revoke active sessions and reset credentials [18]. Two things to watch. Whether the seven-firm April operation becomes the floor for participation rather than a high-water mark, and whether any exchange that declines to share customer signals gets named. Note also that Cryptopolitan dates these operations to 2026 while the loss baseline is 2025 [16][14]; the year labelling in secondary coverage is worth checking against the SPF's own releases.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories