📈 Get daily crypto insights that make you smarter about your money

Spotting the Red Flags: A Beginner’s Guide to Identifying Fake Crypto Companies and Job Scams

The cryptocurrency job market is booming, with thousands of positions available across DeFi protocols, blockchain infrastructure companies, and AI-crypto startups. But in April 2025, the FBI seized the domain of a company called Blocknovas — a cryptocurrency startup that looked completely legitimate but was actually a front for North Korean hackers. If you are looking for work in the crypto industry, this guide will help you identify the red flags before you become the next victim.

The Basics

State-sponsored hacking groups, particularly North Korea’s Lazarus Group, have increasingly targeted cryptocurrency professionals through fake job recruitment schemes. The Blocknovas campaign, exposed in late April 2025, revealed just how sophisticated these operations have become. The hackers created three fake companies — Blocknovas, Angeloper, and SoftGlide — complete with professional websites, AI-generated employee headshots, and fabricated LinkedIn profiles with realistic career histories.

The scheme worked like this: a crypto developer would see a job posting on LinkedIn or a job board, apply for the position, go through multiple rounds of interviews with people who seemed legitimate, and then be asked to download a “coding exercise” or “technical assessment tool” as part of the final round. That download contained malware designed to steal cryptocurrency wallet credentials, private keys, and access to the victim’s development environment.

With Bitcoin trading around $94,647 and the total cryptocurrency market valued at over $3.3 trillion, developers who work in this industry are high-value targets. A single compromised wallet or stolen private key can result in losses worth millions of dollars.

Why It Matters

You might think this only happens to other people, but the Lazarus Group’s campaign targeted dozens of experienced blockchain developers across multiple countries. These are smart, cautious professionals who simply encountered a scam that was more sophisticated than anything they had seen before. The use of AI-generated content means the old indicators of a scam — poorly written emails, obviously fake photos, broken website links — are no longer reliable.

Beyond the immediate financial loss from stolen credentials, victims of these schemes face additional consequences. Personal information shared during the fake interview process — including work history, technical skills, and current employer details — can be used for future targeted attacks. In some cases, compromised developer credentials have been used to inject malicious code into open-source repositories, affecting thousands of downstream users.

Getting Started Guide

Protecting yourself starts with a simple verification framework that you should apply to every job opportunity in the crypto space. Here is a step-by-step approach:

Step 1: Verify company registration. Every legitimate US company must be registered with a state government. Use the Secretary of State website for the state where the company claims to be incorporated. Search for the company name and verify that the registration date, registered agent, and business address are consistent with what the company claims. The Blocknovas domain was registered only weeks before the campaign launched — a major red flag for a company claiming years of operation.

Step 2: Cross-reference employees. If someone from the company contacts you on LinkedIn, look at their profile carefully. Do they have connections you recognize in the industry? Can you find evidence of their employment on other platforms — GitHub contributions, conference talks, academic papers? AI-generated profiles often have generic work histories that cannot be independently verified.

Step 3: Check for a physical presence. Can you verify the company’s office address using Google Street View? Do they have a phone number that connects to a real receptionist? Can you find independent news articles mentioning the company from before you were contacted? Fake companies often list addresses that are actually virtual office services or co-working spaces.

Step 4: Never download software from an interviewer. This is the single most important rule. No legitimate employer will ask you to download executable files during a job interview. If a company asks you to install a custom application, browser extension, or development tool as part of the interview process, stop all communication immediately. Legitimate technical assessments use standard platforms like CoderPad, HackerRank, or your own local development environment.

Step 5: Use sandboxed environments. If you must interact with a company’s platform as part of an assessment, do it inside a virtual machine or Docker container that you can discard afterward. Never use your primary development machine or a machine that has access to your cryptocurrency wallets.

Common Pitfalls

The biggest mistake crypto professionals make is assuming that a polished online presence indicates legitimacy. In 2025, AI tools can generate an entire corporate identity — website, blog posts, employee photos, social media profiles — in hours. A professional-looking website means nothing.

Another common pitfall is letting excitement override caution. The crypto job market is competitive, and when a promising opportunity appears, it is natural to want to move quickly. Attackers exploit this urgency by creating time pressure — claiming the position needs to be filled immediately, scheduling rapid-fire interview rounds, and pushing candidates to complete assessments quickly. Legitimate companies understand that good security practices take time.

A third pitfall is assuming that because you found the job listing on a reputable platform, it must be legitimate. The Lazarus Group posted their fake positions on mainstream job boards and LinkedIn, platforms that do not independently verify every employer.

Next Steps

Start applying this verification framework to every professional contact you receive in the crypto space, starting today. Bookmark your state’s Secretary of State business search page. Set up a dedicated virtual machine for any interactions with new companies. And most importantly, share this knowledge with your colleagues — the best defense against social engineering is a community that knows what to look for.

If you believe you have been targeted by a fake company, report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and notify the platform where you encountered the fraudulent listing. Your report might prevent the next developer from becoming a victim.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Spotting the Red Flags: A Beginner’s Guide to Identifying Fake Crypto Companies and Job Scams”

  1. three fake companies with full HR pipelines and AI headshots. lazarus is running better ops than half of real crypto startups

    1. hr_nightmare_

      blocknovas had a glassdoor page with fake reviews. nation state hackers built a more convincing company than half the real startups in this space

  2. the fake LinkedIn profiles with AI headshots got 3 devs i know last year. one almost installed the payload before the real company posted a warning. terrifying stuff

    1. Luca Bianchi

      the coding exercise malware trick is brutal. devs literally applying for jobs and downloading their own compromise

      1. imagine applying for your dream crypto job and the coding exercise is literally a trojan. devs need to verify companies independently before downloading anything

      2. exactly. the malware was disguised as a take-home coding challenge. you literally build the exploit into your own dev environment and run it yourself

        1. torstein_b the malware disguised as a take-home challenge is brutal. you literally build the exploit into your own dev environment and compile it yourself. no delivery mechanism needed

        2. the take-home coding challenge being the delivery mechanism is brutal. you literally compile the malware yourself and run it on your own machine. no phishing link needed

  3. ran reverse image searches on three crypto startup staff photos last month. all came back as AI generated faces. the tools to verify are free and almost nobody uses them before applying

  4. linkedin verification badges mean nothing for these fake companies. lazarus built full profiles with work histories and recommendations. the platform has no real vetting for employers

  5. the Glassdoor page with fake reviews is what gets me. job seekers actually trust those ratings to decide where to work. Lazarus basically weaponized the entire trust infrastructure of tech recruiting

  6. northkorea_watch

    three fake companies with AI headshots and fabricated linkedin profiles. lazarus group is running a full HR department at this point

    1. lazarus running a full HR pipeline with AI headshots and fake linkedin histories is next level. the blocknovas setup had a careers page and everything

      1. the careers page was fully functional too. job descriptions, benefits, even a glassdoor listing. lazarus basically built a complete startup just to trap a handful of devs

        1. n0sec_ the glassdoor listing detail is what got me. they literally created fake reviews too. social engineering at nation state level

          1. mateo r the glassdoor fake reviews detail is insane. nation state level social engineering. most legit startups dont even have their glassdoor sorted

  7. ran into a similar setup last year. startup called NetWave Labs. website looked clean, team page had 12 people. reverse image search showed every single face was generated. the take-home test was a node.js project that wanted network access to your local env

  8. companies using AI headshots for fake employees is wild. ran a reverse image search on three staff photos from a crypto startup last month, all came back as generated faces

  9. syntax_wraith_

    the Glassdoor page with fake reviews is the detail that got me. Lazarus built a more convincing company than half the seed-stage startups pitching at Token2049

    1. phish_bucket_

      and nobody verifies the verifier. LinkedIn profiles with 500+ connections all fabricated. the platform has zero incentive to crack down because engagement metrics look good

  10. reverse image searching staff photos takes 10 seconds and almost nobody does it. free tool that could save your wallet and your laptop

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,865.00-2.0%ETH$1,869.76-2.6%SOL$75.93-1.5%BNB$599.60-1.4%XRP$1.02-2.2%ADA$0.1945-1.6%DOGE$0.0696-1.2%DOT$0.8029-0.4%AVAX$6.48-0.9%LINK$8.23-1.1%UNI$3.93-2.7%ATOM$1.41+1.9%LTC$45.08-2.4%ARB$0.0805+2.6%NEAR$1.60-2.2%FIL$0.7006-1.2%SUI$0.6889-1.5%BTC$63,865.00-2.0%ETH$1,869.76-2.6%SOL$75.93-1.5%BNB$599.60-1.4%XRP$1.02-2.2%ADA$0.1945-1.6%DOGE$0.0696-1.2%DOT$0.8029-0.4%AVAX$6.48-0.9%LINK$8.23-1.1%UNI$3.93-2.7%ATOM$1.41+1.9%LTC$45.08-2.4%ARB$0.0805+2.6%NEAR$1.60-2.2%FIL$0.7006-1.2%SUI$0.6889-1.5%
Scroll to Top