Medasit

The $11.8M Interview: How a Fake Job Offer Became a CI/CD Supply Chain Attack

LeoFox
Web3

Singapore. A crypto company. $11.8 million gone. The attack vector? A job interview.

No zero-day. No smart contract exploit. Just a LinkedIn message, a Google Meet link, and a 'technical test' that turned into a session token hijack, CI/CD pipeline compromise, and a coordinated fund drain. This wasn't a random phishing attempt. This was a surgical strike on the trust chain between hiring and infrastructure.

Over the past 7 days, the Singapore Police Force and Cyber Security Agency jointly disclosed a novel attack pattern that combines social engineering with DevOps-level access abuse. The attackers posed as recruiters, contacted candidates via LinkedIn, and used fake company domains like @company-careers.com to bypass initial email filters. They scheduled Google Meet interviews with cameras off—an innocuous request that set the stage for the payload.

During the interview, the candidate was asked to download a 'coding test' from a fake website. That file was a malicious payload—likely a remote access trojan (RAT) or an infostealer. Once executed, it grabbed session tokens from the victim's machine. And here's the kicker: those tokens bypassed the company's multi-factor authentication (MFA) entirely. MFA is a single-point verification. Session tokens are the keys to the kingdom once the handshake is done.

The $11.8M Interview: How a Fake Job Offer Became a CI/CD Supply Chain Attack

With valid tokens, the attackers accessed the company's Bitbucket repositories, modified CI/CD deployment scripts, and injected backdoor code into the production update pipeline. They then used stolen credentials to override transaction limits and approval workflows. The funds—$11.8 million—moved out through the company's internal systems, not through a DeFi bridge or a hacked wallet.

This is not a story about chain security. It's a story about operational security—or the lack thereof. The attack chain is as follows:

  1. Reconnaissance: LinkedIn profile scanning for crypto industry employees.
  2. Initial contact: Fake recruiter email from a lookalike domain.
  3. Trust building: Genuine-looking Google Meet interview (camera off to avoid visual identification).
  4. Payload delivery: 'Technical test' binary hosted on a fake site.
  5. Token theft: Session tokens extracted from the victim's browser.
  6. Lateral movement: Access to Bitbucket, then to CI/CD servers.
  7. Privilege escalation: Stolen credentials to bypass transaction limits.
  8. Exfiltration: $11.8M wired out.

Security is a promise; liquidity is the proof. That promise broke here. The company had MFA. It had firewalls. It had code audits. But none of that protected the human-in-the-middle attack vector that started with a job offer.

Now, the contrarian angle. Everyone will focus on the $11.8M loss. That's a headline. But the real story is the replicability of this attack pattern. The attackers used no zero-day vulnerabilities. They used known techniques: malicious software, session hijacking, CI/CD config tampering. The novelty is in the combination—and the target (crypto companies with high-value assets and immature internal security cultures).

This playbook is now available for download on the dark web. Any organized crime group can replicate it. The cost of entry is a fake LinkedIn profile and a $50/month VPS. The ROI? $11.8M in a single operation.

What you see on-chain is not always what you get. In this case, the on-chain activity was legitimate—the funds were moved by authorized accounts. The fraud happened off-chain, in the session management layer. Most crypto companies spend 90% of their security budget on smart contract audits and 10% on endpoint protection, identity management, and CI/CD integrity. That ratio is broken.

Based on my audit experience with 0x protocol and my forensic work on the Terra-Luna collapse, I can tell you: session token theft is the silent killer of 2025. MFA gives a false sense of security. Once a token is stolen, the attacker is in. No password, no 2FA prompt, no alert. And most companies don't bind tokens to device fingerprints or monitor for anomalous usage patterns.

The attack also targeted a specific vulnerability: the trust gap in hiring. Developers are eager to prove their skills. They'll download a 'test' file without thinking twice. The company's onboarding process had no sandbox environment for external candidates—no isolated VM, no controlled browser. That's a governance failure, not just a tech failure.

Chaos is just data waiting to be organized. Let's organize this data. The attack pattern is now public. The next victim is likely within the next 30 days. The Singapore police disclosure may have come after the attackers were already caught, but the methodology is still in the wild. The risk is not just to Singapore-based firms but to any crypto company with a public LinkedIn presence and a DevOps pipeline.

What can you do? First, implement session token binding to hardware keys. Second, use continuous authentication—monitor for token reuse from different IPs or devices. Third, isolate all external candidate interactions in a sandboxed environment. Fourth, add human verification steps to all CI/CD deployments—no automated push should go to production without a second pair of eyes.

This event is a wake-up call. The industry's obsession with chain-level security has created a blind spot. The attackers are now targeting the seams: the hiring process, the CI/CD pipeline, the session management layer. The next $11.8M loss will come from a different vector—but the same root cause: a failure to treat internal operations as a security boundary.

Look at the transaction flows. The funds moved through internal systems. The attacker didn't need to compromise a blockchain. They compromised a process. And that's the story that matters.

Market Prices

BTC Bitcoin
$76,430.7 -2.44%
ETH Ethereum
$2,430.5 -2.86%
SOL Solana
$99.49 -2.28%
BNB BNB Chain
$719.5 -0.28%
XRP XRP Ledger
$1.4 -0.37%
DOGE Dogecoin
$0.0819 -2.38%
ADA Cardano
$0.2025 -2.69%
AVAX Avalanche
$7.45 +0.00%
DOT Polkadot
$0.9852 -2.38%
LINK Chainlink
$11.3 -1.02%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$76,430.7
1
Ethereum ETH
$2,430.5
1
Solana SOL
$99.49
1
BNB Chain BNB
$719.5
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0819
1
Cardano ADA
$0.2025
1
Avalanche AVAX
$7.45
1
Polkadot DOT
$0.9852
1
Chainlink LINK
$11.3

🐋 Whale Tracker

🔵
0x36fa...bcdd
30m ago
Stake
34,755 SOL
🔴
0x1fbc...1ccc
12h ago
Out
17,618 BNB
🟢
0x7be4...4d2c
6h ago
In
2,635,855 USDC

💡 Smart Money

0x4112...8f4f
Early Investor
-$0.5M
87%
0xb587...e291
Institutional Custody
+$2.5M
80%
0xc27e...7f79
Institutional Custody
+$4.4M
72%

Tools

All →