cryptonews
2026-02-01 08:29:39

$30M Stolen as Step Finance Treasury Wallets Compromised

Step Finance, a major Solana DeFi platform, confirmed multiple treasury and fee wallets were compromised by a sophisticated attacker during Asian Pacific trading hours, resulting in the theft of approximately 261,854 SOL tokens worth roughly $30 million. The breach sent shockwaves through the Solana ecosystem as blockchain security firm CertiK flagged that the stolen SOL “ has been withdrawn after stake authorization had been transferred ” to an unknown wallet address. The incident triggered immediate market panic, with the platform’s native STEP token plummeting over 90% within 24 hours. Source: CoinGecko While the team insists user funds remained unaffected, questions swirl over whether the breach represents a genuine security failure or a disguised exit scam, particularly given that the attacker appeared to have direct wallet access rather than exploiting smart contract vulnerabilities. Earlier today several of our treasury wallets were compromised by a sophisticated actor during APAC hours. This was an attack facilitated through a well known attack vector. Immediate remediation steps have been taken, and we are working closely with top security professionals.… — Step (@StepFinance_) January 31, 2026 Emergency Response and Damage Control Step Finance disclosed the security breach through a series of urgent social media posts, stating “ several of our treasury and fee wallets were compromised by a sophisticated actor ” and confirming the attack leveraged “ a well known attack vector. “ The platform immediately activated emergency protocols and reached out to cybersecurity firms for assistance. Solana media firm Solana Floor reported that on-chain data showed the stolen 261,854 SOL was “ unstaked and moved during the incident ,” suggesting the attacker had obtained authorization to control staking operations. The team emphasized it had “ notified the relevant authorities ” and implemented immediate remediation steps while working with top security professionals around the clock. We are contacting Cybersecurity firms to assist. Any firms who can assist feel free to slide into DMs https://t.co/uNN5l6TYVL — Step (@StepFinance_) January 31, 2026 Ripple Effects Across Linked Protocols The breach extended beyond Step Finance’s own operations, impacting connected platforms including Remora Markets. The protocol disclosed that as “ majority LP, Step Finance experienced a hack of treasury wallets earlier today ” with some affected assets including Remora rStocks. Remora assured users that despite the incident, “ Remora assets remain held 1:1 in our brokerage account ” while constructing a process for handling redemptions. The market’s swift verdict on Step Finance came through brutal price action, with the STEP token losing most of its value as traders fled amid uncertainty about the platform’s future viability and the legitimacy of the breach. Remora Markets majority LP, Step Finance experienced a hack of treasury wallets earlier today. Some of the assets involved in the incident are Remora rStocks. An investigation is currently underway. Remora assets remain held 1:1 in our brokerage account. A process for handling… — Remora Markets (@RemoraMarkets) January 31, 2026 January’s Relentless Wave of DeFi Exploits The Step Finance hack marks the latest in what security firms describe as a devastating month for cryptocurrency security. According to CertiK’s comprehensive January 2026 security report , “ combining all the incidents in January, we’ve confirmed ~$370.3M lost to exploits ” across multiple attack vectors. Major January incidents included Truebit’s $26.6 million smart contract exploit , SwapNet’s $13.3 million breach affecting Matcha Meta users, Saga’s $6.2 million exploit that forced the Layer-1 protocol to pause its SagaEVM chain, and Makina Finance’s $4.2 million loss through flash loan manipulation. CertiK’s analysis revealed that phishing incidents accounted for $311.3 million of January’s losses, while code vulnerability attacks totaled $51.5 million. #CertiKStatsAlert Combining all the incidents in January we’ve confirmed ~$370.3M lost to exploits. ~$311.3M of the total is attributed to phishing with one victim losing ~$284M due to a social engineering scam. More details below pic.twitter.com/uXhi0P6dl5 — CertiK Alert (@CertiKAlert) January 31, 2026 Notably, the Step Finance breach continues a troubling pattern affecting Solana-based protocols. Swiss crypto platform SwissBorg lost $41.5 million worth of SOL tokens in September 2025 after hackers compromised partner API provider Kiln, while South Korea’s Upbit exchange suffered a $36 million Solana exploit in November 2025, exactly six years after its 2019 hack attributed to North Korean actors. Beyond individual protocol failures, January also witnessed the largest single crypto theft of 2026, when a victim lost over $282 million in Bitcoin and Litecoin through a hardware wallet social engineering scam, as blockchain investigator ZachXBT described it, surpassing the previous record of $243 million set in August 2024. The attacker “ immediately began converting the stolen assets into Monero through multiple instant exchanges, ” obscuring the trail across multiple blockchain networks. CertiK’s data shows that despite these massive losses, less than 2-5% has been recovered so far , as investigations into many cases have only recently begun. Even government-held crypto assets came under scrutiny, as the US Marshals Service confirmed it is investigating a possible hack of federal digital-asset accounts. Patrick Witt, executive director of the President’s Council of Advisors for Digital Assets, acknowledged that the government seizure addresses were among the wallets from which hackers stole more than $60 million in late 2025. The post $30M Stolen as Step Finance Treasury Wallets Compromised appeared first on Cryptonews .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.