Wallets and Security
Recognising Fake Crypto Job Offers
How attackers use fake crypto job offers to deliver malware and steal wallets, the red flags in recruiter messages and tasks, and safe habits for job seekers.

Crypto companies hire remotely across the world, which makes job seekers easy to approach and hard to verify. Attackers exploit this with fake job offers. A recruiter reaches out with an attractive role, the interview seems professional, and then the candidate receives a coding test, a document or a meeting app that installs malware. Within hours, wallets and browser sessions are drained.
Developers, designers, community managers and even executives have been targeted.
How fake job offers work
A typical fake job scam follows this pattern:
- A recruiter contacts you on LinkedIn, X, Telegram or email with a well-paid role
- The company appears real, sometimes impersonating a known project
- Interviews happen quickly, often with friendly, convincing people
- You receive a task: a repository to run, a document to open or an app to install for meetings
- The file contains malware that steals browser data, wallet files or keys
- Attackers drain wallets and take over accounts
Some campaigns are run by sophisticated groups with detailed fake profiles and websites.
Red flags in the approach
| Red flag | Why it matters |
|---|---|
| Unusually high pay for vague responsibilities | Designed to lower your guard |
| Urgency to complete tasks quickly | Pushes you to skip checks |
| Recruiters with new or thin profiles | Fake identities |
| Company domain slightly different from the real one | Impersonation |
| Interviews moved to unfamiliar meeting software | Malware delivery |
| Communication only through personal messaging apps | Avoids official channels |
Red flags in tasks
Be especially careful with:
- Repositories that require running install scripts or unusual dependencies
- Coding tests that must run on your main machine
- Documents that ask you to enable macros or content
- "Meeting apps" that must be downloaded rather than used in a browser
- Browser extensions required for a task
- Requests to connect a wallet to "test" a product

Safe habits for job seekers
- Verify the company. Check the official website's careers page and confirm the role exists.
- Verify the recruiter. Contact the company through official channels to confirm the person works there.
- Use known meeting platforms in the browser.
- Run code only in isolated environments, such as a virtual machine, a separate device or a cloud sandbox, never on a machine with wallets or saved logins.
- Review code before running it, especially install scripts and dependencies.
- Never share seed phrases or connect wallets for hiring tasks.
- Keep a separate device or profile for job searching if you work in crypto.
For hiring teams
Legitimate companies can protect candidates and their own reputation:
- List open roles on the official website
- Use official email domains for recruitment
- Publish a warning about fake recruiters
- Avoid asking candidates to run untrusted code locally
- Provide a way for candidates to verify recruiters
Impersonation of your company can damage trust even if you are not involved.
If you ran something suspicious
Act immediately:
- Disconnect the device from the internet
- Move funds from any wallets accessible on that device, using a clean device
- Change passwords and revoke sessions from a clean device
- Reset or reinstall the affected device
- Report the scam to the platform where it started and warn the impersonated company
Make real opportunities easy to verify
Candidates check several places before trusting an employer. Crypto teams that list roles on their official site and keep consistent public profiles, including a Proud Globe pin linking to the official careers page, give applicants one more way to confirm they are talking to the real company.
Educational content only. Nothing here is financial, legal or tax advice. Crypto assets carry risk, so check the details for your own situation.