Social Engineering Breaches Hit Figure Technology and Step Finance

SOL4.86%
DEFI-4.02%
  • Figure Tech breached after an employee fell for a scam; ShinyHunters leaked 2.5GB of sensitive data.

  • Step Finance lost $29M in SOL after hackers accessed treasury wallets, cause remains unclear.

  • Social engineering and AI scams are rising, threatening both tech firms and crypto platforms alike.

A growing wave of cyberattacks has shaken the tech and crypto sectors, highlighting the risks of human-targeted exploits. Recently, Figure Technology disclosed a breach after an employee fell for a social engineering scam, allowing hackers to access a few files.

The company confirmed that it had notified the affected partners and provided them with free credit monitoring services. Moreover, the reporters highlighted that the spokesperson of Figure did not respond to several specific questions regarding the breach. The black-hat hacking group ShinyHunters took responsibility for the breach on their dark web platform, claiming that the company failed to satisfy their demands, leading to the leakage of 2.5 GB data.

In addition, Figure explained, “We also recently discovered that an individual was tricked into handing over their login credentials, which allowed a user to download a few files using their account. We immediately acted to put a stop to it and retained a forensic firm to help determine which files were compromised.” As a result, it was determined that the attack was a social engineering attack, which relies on psychological manipulation to obtain unauthorized access.

Recently, Chainalysis reported that scammers have managed to steal a staggering $17 billion in cryptocurrency within the last year using AI to enhance impersonation and social engineering attacks. This is in line with the industry concern that arose after a report by Privacy Rights Clearinghouse in December 2025, which indicated that regulators have filed over 8,000 filings that affect at least 374 million people.

Broader Implications for Tech and Crypto

Anonymous sources revealed that Figure’s breach might be part of a larger campaign targeting companies using Okta’s single sign-on service. Other alleged victims include the University of Pennsylvania and Harvard University.

Meanwhile, Step Finance, a major DeFi platform on Solana, confirmed a breach affecting several treasury and fee wallets. Onchain data shows hackers unstaked about 261,854 SOL, moving funds to unknown addresses. At a price of $110 per SOL, these transfers total nearly $29 million.

Step Finance posted on X, “We experienced a security breach in some of our treasury wallets a few hours ago, and we are currently looking into it… We will share more details later.” However, the company did not specify the breach’s root cause, sparking speculation over smart contract flaws or access control issues.

Consequently, the community questioned whether user funds outside treasury wallets faced risk. Despite repeated media inquiries, Step Finance declined to provide further comment.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Blockchain Lender Figure Confirms Customer Data Breach

_Figure probes customer data breach as hackers leak files, adding to rising crypto fraud and identity crime concerns._ Figure Technology, a blockchain-based lending company, has confirmed a data breach following a social engineering attack. Hackers gained access after tricking an employee and st

LiveBTCNews2h ago

The Israeli military is hunting for spies on Polymarket

Israeli Defense Forces reservists and civilians have been charged for placing bets on military secrets on Polymarket,涉嫌 insider trading. This incident highlights the risks of unfair competition and insider involvement in prediction markets, especially in sensitive areas like war. It calls for potential future regulation to prevent similar issues.

区块客3h ago

Ripple's former CTO confirms no issuer for XRP: NFT scam led to funds being stolen, victims unable to recover tokens

On February 14, former Ripple Chief Technology Officer and current Honorary CTO David Schwartz reiterated that XRP has no issuer, so in cases of theft or scam, no one can freeze, revoke, or recover these tokens. This statement was made in response to a recent "LP Reward Coupon" NFT scam, which resulted in a major liquidity provider’s wallet funds being transferred out and sparked widespread discussion in the community about the XRP Ledger’s recovery features. The first to disclose this was X platform user Apex589, who pointed out that a liquidity provider suffered losses after receiving suspicious NFTs. Subsequently, GTFXRP added that the affected address belongs to a venture capital firm and called for the situation to be directly reported to David Schwartz. Some users asked whether losses could be recovered through XRPL’s recovery mechanism, but Schwartz responded that only assets with an issuer can be recovered, and since XRP is a native asset with no issuer, it cannot be recovered.

GateNewsBot9h ago

Brave Research Report: zkLogin Has Three Main Vulnerability Types, Arising from Semantic Ambiguity, Lack of Binding Guarantees, and Architecture Trust Transfer

The Brave research team released a report indicating that the blockchain transaction authorization system zkLogin has three inherent vulnerabilities related to external document dependencies, authentication document conversion, and trust centralization, which pose privacy and governance risks. These issues stem from architectural flaws rather than cryptographic breaches.

GateNewsBot9h ago

Ripple CTO David Schwartz: Clawback cannot recover stolen XRP

David Schwartz, Ripple's CTO, clarified that the "Clawback" feature cannot reverse fraudulent transactions involving XRP after a security incident within the GTF community. He emphasized that XRP is not a recoverable asset since it lacks an issuing account, distinguishing it from other tokens on the XRP Ledger that can be subject to Clawback mechanisms.

TapChiBitcoin11h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)