Valuethemarkets Step Finance Crypto Heist: $40M Lost, Recovery Efforts Complicated
Article Content
- •Step Finance lost approximately $40 million due to a hack exploiting treasury wallet vulnerabilities.
- •Only $4.7 million has been recovered, reflecting a 12% recovery rate from the total losses.
- •The attacker laundered stolen funds through Tornado Cash, complicating future recovery efforts.
On January 31, 2026, Step Finance, a DeFi platform on Solana, was hacked, resulting in the theft of approximately 261,854 SOL tokens valued between $27 million and $30 million. The attack exploited vulnerabilities in the management of treasury and fee wallets, likely through compromised devices of executive team members via phishing or social engineering. Total losses from the incident have escalated to around $40 million, with only $4.7 million recovered, marking a recovery rate of about 12%. The attacker laundered funds by converting stolen SOL into ETH and routing them through Tornado Cash, complicating recovery efforts. The planned buyback of the STEP token is hindered by the cessation of operations and shutdown of affiliates. The incident underscores the critical need for enhanced cybersecurity measures in decentralized finance ecosystems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Step Finance in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…