Scams

The $11.8M Recruitment Scam: Why Your MFA Is Useless Against Session Token Theft

Larktoshi

An 11.8 million dollar loss. That is the headline. But the number is not the story. The story is the surgical precision of the attack chain โ€” a combination of social engineering, malicious software, and a CI/CD pipeline hijack that bypassed every layer of authentication the victim company had deployed.

Official sources from the Singapore Police Force and the Cyber Security Agency confirmed the incident on August 14, 2025. The victim was a cryptocurrency firm based in Singapore. The attackers posed as recruiters on LinkedIn, conducted fake video interviews with the camera off, and convinced the target to download a 'technical test' from a spoofed website. That download was the pivot point.

From my own experience auditing DevOps pipelines for DeFi protocols, I have seen similar patterns โ€” but never executed with this level of coordination. The attack is not a single exploit. It is a multi-stage operation that weaponizes the trust embedded in hiring processes.

The Core Attack Chain

Let me walk through the technical sequence as reconstructed from the official report and my own analysis of similar incidents.

  1. Initial Reconnaissance: The attackers identified a target employee on LinkedIn, likely someone with access to code repositories and deployment tools. They used a fake company email domain mimicking the victim's firm.
  1. Trust Building: A video interview was conducted with the camera off. The excuse: 'technical issues.' This is a common social engineering tactic โ€” it prevents the victim from seeing the attacker's face, and it sets up the next step.
  1. Malicious Payload Delivery: The victim was asked to download a 'coding test' from a fake website. The file contained a remote access trojan (RAT) or an information-stealing malware. This is the critical breach point โ€” the moment the external attacker enters the internal network.
  1. Session Token Theft: Once inside the company device, the malware stole active session tokens for internal tools โ€” likely Bitbucket, Jira, and the CI/CD platform. This is the most technically sophisticated part of the attack. The tokens allowed the attackers to impersonate the victim without triggering any multi-factor authentication (MFA) prompt.
  1. CI/CD Supply Chain Manipulation: With access to the code repository, the attackers modified the automated deployment scripts for the company's crypto asset transfer system. They injected a backdoor that redirected a portion of outgoing transfers to a wallet under their control.
  1. Privilege Escalation and Fund Transfer: Using stolen credentials from the session hijack, they bypassed internal transaction limits and approval workflows. The funds were moved out in multiple batches over a period of hours.

The entire chain took less than 48 hours from initial contact to fund exfiltration.

The Contrarian Angle: MFA Is Not a Silver Bullet

Most security teams in Web3 believe that MFA + smart contract audits are sufficient. This case proves otherwise. The attackers never needed to bypass MFA โ€” they simply stole the session token after the MFA challenge had been completed. This is a classic session hijacking technique, but it is rarely discussed in the context of crypto companies.

Silence is the most expensive asset in a bubble. The industry has poured millions into formal verification and chain-level security, but the weakest link is the human sitting at a laptop with a valid session token. The attack did not exploit a zero-day vulnerability. It exploited a process gap: the lack of device binding for session tokens, the absence of continuous authentication, and the over-reliance on static credentials.

Yield is often the interest paid on risk you didn't see. Here, the yield was the $11.8M โ€” the interest paid on the risk of trusting a recruitment process without verifying the endpoint security.

I trust the code, not the community. But in this case, the code was compromised because the community (the employee) was compromised first. The attack is a textbook example of how chain-level security is only as strong as the operational security of the people who manage the keys.

The $11.8M Recruitment Scam: Why Your MFA Is Useless Against Session Token Theft

Takeaway: This Attack Will Be Replicated

The playbook is now public. The technical components are all known and available: social engineering templates, RATs, session token stealers, and CI/CD pipeline manipulation scripts. The only barrier to replication is the initial reconnaissance, which is easy to automate.

Every Web3 company should audit their session management policies immediately. Bind session tokens to device fingerprints. Implement short-lived tokens with continuous re-authentication. Treat every CI/CD pipeline as a high-value target requiring hardware-backed signing and multi-party approval. The next victim might not be in Singapore. The next loss might be your protocol's treasury.

The question is not whether you will be targeted. It is whether your session tokens are worth $11.8M.

Market Prices

BTC Bitcoin
$77,411.3 +0.83%
ETH Ethereum
$2,396 -0.28%
SOL Solana
$99.48 +0.67%
BNB BNB Chain
$687.1 +1.39%
XRP XRP Ledger
$1.34 -0.25%
DOGE Dogecoin
$0.0815 +0.39%
ADA Cardano
$0.1970 +1.29%
AVAX Avalanche
$7.17 -0.06%
DOT Polkadot
$0.8604 -0.49%
LINK Chainlink
$11.15 -0.14%

Fear & Greed

63

Greed

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

Market Cap

All โ†’
1
Bitcoin
BTC
$77,411.3
1
Ethereum
ETH
$2,396
1
Solana
SOL
$99.48
1
BNB Chain
BNB
$687.1
1
XRP Ledger
XRP
$1.34
1
Dogecoin
DOGE
$0.0815
1
Cardano
ADA
$0.1970
1
Avalanche
AVAX
$7.17
1
Polkadot
DOT
$0.8604
1
Chainlink
LINK
$11.15

Tools

All โ†’

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

๐Ÿ‹ Whale Tracker

๐ŸŸข
0x7963...cf1d
1h ago
In
3,121.00 BTC
๐Ÿ”ด
0x11d5...852b
6h ago
Out
48,971 BNB
๐ŸŸข
0x2651...8ad2
1h ago
In
14,203 SOL

๐Ÿ’ก Smart Money

0xc006...2635
Institutional Custody
+$0.9M
65%
0xc4c1...a293
Institutional Custody
+$4.6M
62%
0x4197...c929
Institutional Custody
+$4.0M
93%