Scam defense / Updated 2026-07-30

Fake Job Offers That End in a Crypto Loss: Task Scams, Fake Recruiters, and Interview Malware

Crypto is now the most common way money is lost to job scams. Learn the two shapes — task scams that ask you to deposit, and fake interviews that install malware — and how to check an offer first.

How this guide is checked

Official sources first, no wallet connection, no guaranteed returns.

Reviewed on 2026-07-30 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.

Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.

crypto job scam matters because A message arrives offering remote work, decent pay, and no experience required — or a recruiter finds you for a role you would genuinely want. It feels like luck, and that feeling is doing the work the scam needs.

This guide separates the two completely different crypto job scams, so you can recognise either one within the first few messages instead of the first few thousand dollars.

You will learn how task scams manufacture fake earnings, how fake interviews install wallet-draining malware, and the checks that settle whether an employer is real.

Why job offers became a crypto attack surface

The numbers moved faster here than almost anywhere else in consumer fraud. According to the Federal Trade Commission, the number of reports about job and employment agency scams tripled between 2020 and 2024, and the amount people reported losing to them rose from about $90 million to $501 million over the same period. That is not a niche problem drifting upward; that is a category being industrialised.

Crypto sits at the centre of it. The FTC's analysis of these scams found that cryptocurrency is the payment of choice, with reported crypto losses to job scams reaching about $41 million in the first half of 2024 alone — nearly double the roughly $21 million reported across all of 2023 — and concluded that people now report losing far more money to job scams paid in cryptocurrency than through any other payment method. The reason is mechanical rather than mysterious: crypto payments settle quickly, cross borders without a bank in the middle, and cannot be reversed once sent, which is exactly the combination a fake employer in another jurisdiction needs.

What makes this worth a guide of its own is that two entirely different attacks share the same disguise. In one, you never meet malware at all — you are persuaded, over days, to send your own money to an employer. In the other, no money is requested — you are persuaded to run something on your computer, and the theft happens without your participation. They look similar in the first message and diverge completely afterwards, so recognising which one you are in determines what you need to protect.

Shape one: the task scam, where you pay to get paid

The FTC's description of these is precise because the format barely varies. You are asked to do simple repetitive tasks — liking videos, rating product images — inside an app or platform that displays commissions accumulating with every click. Tasks arrive in sets, often groups of forty, with the promise of levelling up once a set is finished, and sometimes a 'double task' worth a bigger commission. Many people receive small real payouts early, which is the point: the payout is the cost of buying your trust in the dashboard.

Then the mechanism turns. At some stage you are told you must make a deposit to unlock the next set of tasks or to release the earnings the app is showing you. The FTC's finding is blunt — no matter what the system says you have earned, you have not, that money is not real, and if you deposit money you will not get it back. If you hesitate, you are often invited into a group chat where supposedly experienced workers share success stories; those people are part of the operation. The displayed balance is a number in someone else's database, and the only real transaction in the entire relationship is the one leaving your wallet.

The scale is what makes this the defining version. About 20,000 people reported these gamified task scams in the first half of 2024, compared with roughly 5,000 in all of 2023, and reported losses to job scams overall topped $220 million in that same half-year. In April 2026 the FTC flagged a newer twist in how they open: fake recruiters claiming to be with companies you would recognise, advertising roles like 'online assessor' or simply a 'remote position', quoting daily or weekly pay with no detail about the actual work, and asking you to reply YES or INTERESTED rather than click a link — because a reply proves the number is live and starts the conversation on their terms.

If a platform ever shows you a balance and then asks for money before releasing it, the mechanics are identical to the pay-to-withdraw scam covered elsewhere on this site, and so is the answer: the request for a fee is the proof, not the obstacle.

Checklist

  • Unexpected job messages by text, WhatsApp, or Telegram with pay quoted but no job detail.
  • Work that consists of liking, rating, or 'boosting' things online.
  • Small early payouts followed by a required deposit.
  • A dashboard showing earnings you cannot withdraw without paying first.
  • A group chat of enthusiastic colleagues who materialised when you hesitated.

Shape two: the interview that installs malware

The second version never asks for a deposit, which is exactly why it slips past people who know about task scams. Microsoft Threat Intelligence published an analysis in March 2026 of a long-running campaign in which attackers pose as recruiters from cryptocurrency trading firms or AI companies and run what looks like a genuine hiring process. The malicious step is disguised as a technical assessment: the candidate is asked to clone and run a package hosted on a mainstream code platform such as GitHub, GitLab, or Bitbucket, and running it quietly installs a backdoor.

What that backdoor collects is aimed squarely at crypto holders. Microsoft lists wallet recovery phrases, password stores including password-manager artefacts, notes, and cryptographic keys among the harvested material, alongside API tokens, cloud credentials, clipboard contents, and screenshots. The campaign has been running since at least December 2022 with detections continuing through late 2025, which tells you this is an established operation rather than a passing trend.

It would be comfortable to conclude that only developers are exposed, and that is no longer true. Sekoia's researchers documented a related campaign built specifically for non-technical roles — business development managers, asset management, product roles, and decentralised-finance specialists — using more than forty lookalike interview websites. Candidates fill in a form, answer crypto questions, and are asked to record a short video introduction, at which point a fabricated error claims the camera or microphone is blocked and offers a command to paste in to fix the driver. That command is the installer. It is the same paste-to-continue technique covered in our guide to fake CAPTCHAs and fix-it prompts, wrapped in a job interview instead of a video page.

The tell is structural and does not require you to evaluate any code: at some point, a stranger needs something to run on your computer before the process can continue. Real hiring never has that dependency.

Checklist

  • A recruiter for a crypto or AI firm who found you unprompted.
  • An assessment that requires running code, a package, or an installer from them.
  • An interview platform you have never heard of, on a domain you cannot verify.
  • A camera, microphone, or driver error with a copy-paste fix offered mid-interview.
  • Any request to disable a security warning to proceed.

How to check an offer before you engage

Verify the employer, never the messenger. Type the company's domain into your browser yourself, find their careers page, and check whether the role exists as advertised. If it does and you are still interested, apply through that page or contact the company using details from their own site — not a phone number, email address, or link supplied by the person who approached you. A convincing profile, a company logo, and a polished interview site cost a scammer almost nothing; Sekoia catalogued more than forty fake interview sites in a single campaign.

Then apply the FTC's own rules, which are short and hold across every variant. Real employers do not recruit through unexpected texts, WhatsApp, or Telegram messages. You should never pay to get paid or to get a job, which the FTC calls a sure sign of a scam. And nobody legitimate pays you to leave positive ratings or likes online, because doing that is itself unlawful. If a message trips any one of these, you do not need to investigate further.

For anything that involves your computer, separate the machine from the money. Microsoft's guidance for take-home assessments is to use a dedicated, isolated environment such as a non-persistent virtual machine, and to review any recruiter-provided repository before running scripts, installing dependencies, or executing tasks. If you are not technical, the simpler version is absolute: no genuine interview requires you to install a verification tool, update a driver, or paste a command to continue, so treat any such request as the end of the conversation. As a general habit, the device that holds your wallets should not be the device on which you meet strangers, and keys for meaningful holdings belong on a hardware wallet where an infected computer cannot read them.

Finally, watch for the fake-check pattern the FTC warns about, where a new 'employer' sends a check, asks you to deposit it and send part of the money back, and the check bounces weeks later leaving you owing the bank the full amount while the scammer keeps the real funds you sent.

Checklist

  • Find the job on the company's own site by typing the domain yourself.
  • Ignore unexpected job offers arriving by text, WhatsApp, or Telegram.
  • Never pay anything to start work or to release earnings.
  • Never run recruiter-supplied code or installers on your everyday device.
  • Never accept a check-and-send-money-back arrangement.
  • Keep wallets and keys off the machine you use to talk to strangers.

If you already deposited, or already ran it

If you deposited money, stop paying immediately, including any final fee framed as tax, verification, or the last unlock. Every additional payment exists to fund the next request. Preserve what you have — screenshots of the dashboard and chats, wallet addresses you sent to, transaction records, and the recruiter's contact details — because that material is what makes a report useful. Report it to the FTC at ReportFraud.ftc.gov and, in the United States, to the FBI's Internet Crime Complaint Center; if any part of the payment went through a bank or card, contact that institution promptly, since fiat rails occasionally retain options that crypto transfers do not.

If you ran something they sent, treat it as a full device compromise rather than a single bad file, and switch to a different, clean device before doing anything else. From that clean device, change your primary email password and sign out of all sessions first, then do the same for exchange accounts and move two-factor authentication onto an app or a hardware key. Treat any wallet whose keys or recovery phrase ever existed on that computer as exposed: create a new wallet on a clean device, move the funds, and reinstall the operating system on the compromised machine rather than relying on a scan, since this malware category is built to survive one.

If you handed over identity documents to a fake employer, assume they are now in circulation. Monitor for accounts opened in your name where that service exists in your country, and be especially sceptical of any future call or message that references those documents to prove it is legitimate — scammers reuse what they collected to make the next approach convincing. And as with every crypto loss, treat anyone who surfaces afterwards offering to recover your funds for an upfront fee as the second scam in the sequence, not the solution to the first.

Checklist

  • Send nothing further, including any 'final' fee.
  • Save chats, screenshots, addresses, and transaction records before accounts vanish.
  • Report to the FTC and, in the US, to the FBI's IC3.
  • After running unknown software, rebuild the device and rotate credentials from a clean one.
  • Assume shared ID documents will be reused against you later.

Authority sources used

Outbound links are included for verification and entity authority, not decoration.

FAQ

The recruiter has a real-looking company page and interview site. Doesn't that prove the job is real?

No — that layer is the cheapest part of the operation to fake. Sekoia's researchers documented a single campaign running more than forty separate lookalike job-interview websites, professionally built to mimic real hiring platforms, complete with contact forms, screening questions, and video-introduction steps. A convincing site, a logo, and a well-written job description can be produced in an afternoon and cost the scammer effectively nothing, so their existence tells you about the attacker's effort, not the employer's legitimacy. The check that actually resolves it costs you two minutes and runs in the opposite direction: type the company's real domain into your browser yourself, go to their careers page, and see whether this role exists and whether the person contacting you appears in the company's own directory or is reachable at an address published on that site. If the role only exists inside the channel that approached you, treat the entire process as fabricated regardless of how polished it looks — and never let the quality of the presentation substitute for that independent check.

Why would a scam pay me real money at the start?

Because those early payouts are the cheapest advertising the operation can buy. In the task-scam format the FTC describes, many people receive small genuine payments after their first set of tasks, and the purpose is to convert scepticism into trust in the dashboard — once you have seen real money arrive, the growing balance on screen stops feeling like a claim and starts feeling like an account. That belief is what makes the later request work, when you are told you must deposit your own money to unlock the next set of tasks or to release your accumulated earnings. A scammer who pays out twenty dollars to unlock a two-thousand-dollar deposit is running a straightforward and highly profitable trade. The rule that survives this manipulation is directional rather than emotional: a real job never requires you to send money to your employer, regardless of what you were paid earlier or what the platform shows you have earned. Treat the first request for a deposit as the end of the relationship, not a hurdle within it.

I'm not a developer. Am I actually a target for the malware version?

Yes. That assumption was reasonable a couple of years ago and is not anymore. Sekoia documented a campaign that specifically targeted non-technical roles — business development managers, asset management, product roles, and decentralised-finance specialists — precisely because those candidates are less likely to scrutinise a technical instruction. The delivery method was adjusted to match: instead of asking the candidate to run code, the fake interview site staged a camera or microphone error during a video-introduction step and offered a command to paste in to fix the supposed driver problem. Following that instruction installs the malware just as effectively as running a package would, and it requires no technical background from the victim at all — only compliance. The defence does not require technical skill either. No legitimate interview, on any platform, ever needs you to paste a command into your computer, install a driver, or run a verification tool to continue. Treat that request itself as the conclusion, without needing to evaluate what the command does.

Is it safe to do an unpaid take-home task for a company I'm unsure about?

Doing the work is not the risk — running their software is. Writing a document, preparing an analysis, or answering questions in your own tools carries no security exposure, so a take-home assignment is not inherently a red flag. The danger appears when the assignment requires you to clone a repository, install dependencies, run a script, or open a project in an editor that executes configured tasks automatically, which is exactly the step Microsoft documented attackers using to deliver backdoors that harvest wallet recovery phrases, password stores, cryptographic keys, and API tokens. Microsoft's own recommendation is to use a dedicated, isolated environment such as a non-persistent virtual machine for any coding test, and to review any recruiter-provided repository before running anything from it. If setting that up is beyond what you want to do for an unverified employer, the reasonable answer is to verify the company independently first and decline to run their code until you have. Either way, never run an unknown assignment on the same machine that holds your wallets or your password manager.

A new employer wants my ID and bank details for onboarding. Is that normal?

Legitimate employers do collect identity and payment details, so the request alone is not proof of a scam — the sequence and the channel are what matter. A real process asks for those documents after a verified offer, through a company system on a domain you can confirm, and never over a chat app link sent by someone who approached you unprompted. So verify the employer independently before sending anything: reach the company through its own published contact details and confirm both the role and the person. Two specific patterns should stop you outright. The first is any arrangement where you deposit a check and send part of the money back — the FTC warns this is a fake-check scam that leaves you owing your bank the full amount once the check bounces. The second is a request for wallet keys, a recovery phrase, or a deposit of your own money for equipment, training, or 'verification', none of which any real employer requires. If you have already sent documents to an operation you now doubt, assume they will be reused in a future approach and treat any later contact that cites them as suspect rather than reassuring.