The largest crypto theft ever recorded did not start with a smart contract bug, a leaked private key, or a phishing site. It started with a job interview.

On February 21, 2025, roughly $1.5 billion in ether left Bybit’s cold wallet after three signers approved what looked like a routine withdrawal. The FBI officially attributed the theft to North Korean state actors. But the part of the story that matters for anyone working in crypto came out in the post-mortems: the attackers had compromised a DevOps engineer at Safe {Wallet} months earlier through a fake job offer, and quietly waited.

If you work in crypto — as a developer, an ops person, a designer, or even a part-time community moderator — the hiring pipeline aimed at you is also an attack pipeline. This article breaks down exactly how these campaigns work, what the file-based lures look like, and how to tell a real recruiter from a weaponized one.

The attack chain, step by step

The Bybit incident is the best-documented example, investigated by Sygnia with technical analysis from NCC Group. The chain looks like this:

  1. Contact. A recruiter profile on LinkedIn or another platform messages a target employee of a crypto infrastructure company. The profile is polished, the role is plausible — senior, remote, well paid.
  2. The lure file. The conversation moves to a “job description,” a resume template, or a take-home exercise. The file is weaponized. When opened on the engineer’s Mac, it installed an infostealer.
  3. Credential theft. The infostealer harvested credentials and session tokens, including access to the company’s cloud infrastructure.
  4. Dormancy. The attackers then waited. Bybit’s post-mortem timeline shows the initial compromise happened long before the theft — the intrusion wasn’t detected during the waiting period.
  5. Interface tampering. Using the stolen access, the attackers modified the JavaScript served by the wallet interface that Bybit’s signers trusted. The multisig UI showed one address; the actual transaction data contained another.
  6. The blind spot. Three authorized signers saw a clean-looking screen and signed. The transaction redirected ~$1.5 billion to attacker-controlled addresses.

Notice what’s missing: no zero-day in the smart contract, no brute-forced key. Every technical control held. The attack worked because a human being wanted a better job.

This is why investigators classify these incidents as supply chain attacks rather than simple phishing — the target wasn’t the engineer’s personal funds, but the infrastructure he could reach.

The coding-test variant: Ginco

The Bybit case isn’t isolated. In March 2024, according to a deep dive by Wiz on the TraderTraitor cluster, an operative posing as a recruiter lured a developer at the Japanese crypto company Ginco into running a malicious Python script disguised as a take-home coding test.

The mechanics are brutal in their simplicity: the interview process itself becomes the infection vector. A developer who would never open a random attachment from a stranger will happily clone a repository and run a script when it’s framed as “complete this task so we can evaluate your code.” The script runs with the developer’s own permissions, on a machine that often holds SSH keys, wallet files, and exchange sessions.

Two details make this variant especially effective:

  • It selects for skilled targets. Only working developers get to the coding-test stage, so the attacker’s malware lands on machines belonging to exactly the people with valuable access.
  • It provides natural cover for follow-up questions. “Did the test run okay for you?” is a legitimate-sounding reason to keep the conversation going while the payload does its work.

Scale: this is an industry, not a hobby

The fake-recruiter playbook sits inside a much larger North Korean revenue operation. Chainalysis counted $1.34 billion stolen by North Korea-linked groups in 2024 across 47 incidents — roughly 61% of all funds stolen from crypto services that year, up from $660.5 million across 20 incidents in 2023. Their mid-year 2025 update recorded over $2.17 billion stolen in the first half of 2025 alone, with Bybit the single largest event.

The staffing side of the operation is equally industrial. In June 2025, the US Department of Justice unsealed charges against fourteen North Korean nationals for a multi-year scheme placing fraudulent remote IT workers inside US companies; Reuters reported the workers used identities of more than 80 US citizens to obtain jobs at more than 100 companies. In August 2025, two US nationals were sentenced for operating “laptop farms” — relay hardware that made overseas operators appear to log in from US addresses, generating millions in illicit salary revenue.

The same workforce that fills fake remote jobs also staffs the recruiter personas. When a “senior talent partner” messages you about a protocol role, there is no way to know from the profile whether you’re talking to a real person, a North Korean operative, or both.

The consumer variant: fake Web3 gigs and “test our dapp”

Most readers won’t be DevOps engineers at wallet infrastructure companies. But the same psychology scales down to part-time gigs, and Chinese- and English-speaking job groups on Telegram are full of it:

  • “Test our dapp, we pay in USDT.” You’re asked to connect your wallet to an unfamiliar frontend and complete an interaction. The interaction is a malicious signature request or a token approval. Nothing looks wrong because the scam is the job.
  • “Fill out this onboarding form.” The form is a cloned Google-login page harvesting credentials, or the “HR document” is a macro-laced spreadsheet.
  • “We pay your salary in our token — here’s your allocation, claim it here.” The claim site asks for your seed phrase or an unlimited approval.

The tell in all three: legitimate employers screen you; they don’t need your wallet. The moment a job application requires connecting a wallet, approving a token transfer, or entering a seed phrase, it is not a job application. It’s wallet drainer infrastructure wearing a hiring banner — the same playbook covered in how to spot wallet drainers, aimed at people whose guard is down because they’re in “work mode.”

Red flags: how to screen the screener

SignalReal processWeaponized process
First contactRecruiter’s email matches the company domainPersonal Gmail, or a lookalike domain registered recently
MaterialsLinks to a public careers pageAttachments: “JD.pdf”, resume templates, coding-test archives
InterviewVideo call with verifiable employeesText-only chat; camera “broken”; urgency to skip calls
CompensationDiscussed after mutual interestSalary quoted in the first message, unusually high
The taskSanity interview questionsRun this script / connect this wallet / share your screen
Domain ageCompany site years old”Careers” domain registered weeks ago

None of these signals is conclusive alone. Together, they form a filter that catches nearly every fake-recruiter approach documented in public incidents.

Practical rules that survive contact with real campaigns:

  1. Never open unsolicited job files on a machine that touches crypto. Keep a separate, cheap device for job hunting — the same isolation logic as a hardware wallet, applied to your career.
  2. Verify the recruiter out-of-band. Find the company’s careers page yourself, and message the official HR contact listed there to confirm the person exists.
  3. Treat “run this locally” as a security decision, not a hiring step. A real take-home test can run in a browser sandbox or a fresh VM. Ask to use one; a legitimate employer won’t care.
  4. Assume dormancy. The Bybit compromise sat quiet for months. If you fell for one of these last year and “nothing happened,” that is not evidence you were safe — it’s the normal shape of these operations. Rotate credentials anyway.
  5. Report the profile. Every platform where the persona operates will take recruiter-impersonation reports. It won’t stop the campaign, but it shortens the life of that particular persona.

If you’re hiring: the mirror-image problem

The DOJ’s laptop-farm cases mean the threat runs in both directions — the “employee” can be the attack. For crypto companies, the standard countermeasures after Bybit have hardened around a few points: dedicated, network-isolated machines for transaction signing (so a compromised laptop elsewhere can’t reach the signing flow), mandatory verification of transaction data independent of the rendered UI, and social-engineering drills that specifically rehearse recruiter approaches, not just password phishing.

For individuals, the summary is one line: in this industry, an unsolicited opportunity is a security event until proven otherwise. Proving it otherwise takes minutes. Skipping the check is how a $1.5 billion theft began.

Frequently Asked Questions

Can a fake job offer really compromise a whole exchange?

Yes. The FBI attributes the $1.5 billion Bybit theft of February 2025 to North Korean actors whose entry point was a compromised Safe {Wallet} DevOps engineer, reached through a fake recruiter contact months earlier. His infected workstation exposed credentials that eventually let attackers tamper with the signing interface Bybit's team trusted.

What files do fake crypto recruiters send?

Job descriptions, resume templates, and coding-test archives are the common carriers. They look like PDFs or Python projects but contain malware that steals browser sessions, cryptocurrency wallet files, and cloud credentials. Some malicious PDFs abuse macros; some 'tests' ask you to run a script locally.

How do I verify a crypto job offer is real?

Check the recruiter's domain against the company's official careers page, refuse to run any local files before an interview, and move the conversation to a verified company email or video call. A real employer will never ask you to connect a wallet or test a dapp as part of screening.

Are remote Web3 jobs more dangerous than other remote jobs?

The screening stage carries extra risk because attackers specifically target crypto companies and developers. Chainalysis counted $1.34 billion stolen by North Korea-linked groups across 47 incidents in 2024, and fake-job social engineering is a documented entry point in several of the largest cases.

What should I do if I already opened a suspicious job file?

Disconnect the machine from the internet, move funds from any wallet whose files touched that device, and rotate every password and session token from a clean device. Then scan the machine and report the account to the platform where the recruiter contacted you.