CryptoReal
CASE FILE — Feb 4, 2026

Phished Executive Devices, Not Buggy Code, Cost Step Finance $27.3 Million

It took roughly ninety minutes and a single compromised executive laptop to separate the Solana analytics platform Step Finance from $27.3 million. The protocol's smart contracts performed exactly as designed throughout — the failure sat entirely with the people holding the keys.

Step Finance later described the intrusion as stemming from "a well known attack vector," carefully vague phrasing that stops just short of admitting a phishing email was involved. This despite the protocol having checked most of the usual boxes: audited contracts, bug bounty programs, and public security reviews, coverage from a dedicated Solana media outlet it had built, and ambitions to bring tokenized equities to the chain.

None of that stopped 261,854 SOL from being unstaked and moved out before most people had breakfast, sending the STEP governance token down 93% and undercutting the project's self-styled status as a flagship Solana application.

CertiK was first to flag the outflow publicly, while Step Finance's own team scrambled to line up outside security help over social media. Days later, the protocol said it had clawed back $4.7 million via Token22's built-in protections — a modest recovery set against a $27.3 million loss.

Credit: CoinTelegraph, StepFinance, Piotr Rzonsowski, CertiK, Chainalysis, CoinGecko, Remora Markets, SolanaFloor, PeckShield

01How the morning unfolded

The trouble began quietly on January 31st. Step Finance's first public acknowledgment came early in the day, stating simply that "there has been a breach of security for some of our treasury wallets hours ago." By the time that message went out, the attack itself was already complete.

A follow-up post arrived minutes later: "We are contacting Cybersecurity firms to assist. Any firms who can assist feel free to slide into DMs."

The framing shifted by late morning. A subsequent statement recast the incident as the work of a "sophisticated actor during APAC hours" using "a well known attack vector" — language that, stripped of its polish, amounts to: an executive got phished and the treasury walked out the door.

CertiK's technical alert cut through the euphemism, reporting that 261,854 SOL had been unstaked once "stake authorization had been transferred" to a newly created wallet. On Solana, unstaking simply requires holding the correct wallet permissions — there was no contract exploit to speak of, just legitimate-looking authority in the wrong hands. Step Finance wasn't breached so much as handed over.

02The confession

Two days later, on February 2nd, Step Finance confirmed the root cause: "This was a result of our executive team's devices being compromised." Not a zero-day vulnerability. Not a compromised dependency somewhere in the supply chain. Not an insider settling a score. Multiple executive devices, compromised — plural.

This is a team that had built out a full ecosystem: it ran validator infrastructure, operated the Step dashboard, acquired Moose Capital and rebranded it Remora Markets to push tokenized equities on Solana, ran industry conferences, and operated its own media publication. Somewhere in that operation, someone with signing authority opened the wrong email, clicked the wrong link, or signed off on the wrong transaction.

QuillAudits' assessment was blunt: "most likely a social engineering attack." It's a pattern that dominated 2025 — private key compromises accounted for 88% of that year's Q1 losses industry-wide, according to Chainalysis — and one that evidently carried straight into 2026.

The irony is that Step Finance's security credentials looked solid on paper: audited contracts, an active bug bounty, public reviews. All of it was irrelevant once the actual weak point turned out to be a person with inbox access and transaction-signing rights.

Sums referenced in this case file

Security researcher Piotr Rzonsowski published a detailed breakdown of the operational gaps: weak key management practices, insufficient access controls, no monitoring outside business hours, and reliance on single points of failure. His full postmortem summarized it this way: "Step Finance's hack is a reminder that security is a chain, and chains break at the weakest link."

The $27.3 million loss came with a partial silver lining: $4.7 million was later recovered, thanks to Token22's built-in protections covering the Remora-related assets.

03Tracing the funds

CertiK's on-chain investigation reconstructed the mechanics cleanly. Stake authorization was first reassigned to a newly created address, LEP1uHXcWbFEPwQgkeFzdhW2ykgZY6e9Dz8Yro6SdNu.

From there, unstaking proceeded via this transaction: 5EeXqPQci3ZnbFGWPJf622cLqLGnMuNcAr1rDGCizKRFt9owawCzovNpBC4xNh7A4a5p7Qkvsg8nPaYmw3MiYCvF, pulling 261,854 SOL (roughly $27.3 million) out of Step Finance's treasury and fee wallets.

The decisive withdrawal followed in a transaction moving 261,932 SOL: 4Ly35PsVTBNPVibpDRww6FC43pU5Tuw6UtaKECzcLKXtWTPyyvw1dw8LoNRLBDMgQUP81nN69mhiAEDJvzL8X317.

A second wallet also played a role in the operation: 7raxiejD8hDUH1wyYWFDPrEuHiLUjJ4RiZi2z1u2udNh. QuillAudits reported that most of the stolen funds are still sitting in the attacker's wallets, concentrated in this secondary address. There's been no rush to bridge the funds elsewhere and no Tornado Cash deposits yet — just an address holding its position, presumably waiting for scrutiny to fade.

The reported loss figures don't fully agree with each other. Step Finance itself cited losses of "approximately $40M," while the on-chain record points to a single theft of 261,932 SOL, worth about $27.3 million at the time it was extracted. The roughly $13 million gap between those two figures has not been explained on-chain, and may depend on a more detailed post-mortem from the team.

Step Finance has recovered $3.7 million in Remora-related assets through Token22's built-in protections, plus a further $1 million from other positions — a combined $4.7 million clawed back against a roughly $27 million drain. The remaining funds sit openly visible on Solscan, traceable but currently out of reach.

04Token collapse and knock-on effects

STEP didn't dip — it collapsed. The token fell from $0.023 to $0.001578 within 24 hours, a 93.3% decline that hit before the team had even finished its initial public statement. The sell-off had largely run its course by the time "sophisticated actor" and "well known attack vector" entered the official narrative.

Step Finance's February 2nd statement reflected the pressure the team was under: "At this time, we do not recommend anyone engage with the STEP token until our investigation is complete." The team also indicated a pre-exploit snapshot would be used to determine compensation for affected holders, assuming a viable path forward exists.

The fallout extended to Remora Markets, the tokenized-equities platform Step Finance had built out of its acquisition of Moose Capital in late 2024. Remora reported that some of its rStocks were caught up in the stolen treasury assets, a direct consequence of Step Finance having served as Remora's largest liquidity provider. Remora moved to reassure users that rTokens remained backed 1:1 with its broker while pausing LP activity as a precaution. It later confirmed that all affected Remora rStocks were ultimately recovered through Token22's protections.

Step Finance's media arm, SolanaFloor, continued operating as normal, and the Solana Crossroads conference it powers is still listed as planned for 2026. Even so, the broader ecosystem Step Finance had spent years cultivating now carries the weight of a $27.3 million breach.

Whether the protocol recovers from the reputational damage is an open question. Immunefi CEO Mitchell Amador has noted that "nearly 80% of crypto projects that suffer a major hack fail to fully recover" — a statistic driven less by the size of the loss than by the erosion of user trust.

05The bigger pattern

More than $4 billion left crypto to theft in 2025, and code vulnerabilities were far from the only cause. Chainalysis attributes 88% of all Q1 2025 losses to private key compromises, and separate data puts wallet compromises at $1.71 billion in theft across the first half of the year. The trend line is consistent: human operators, not smart contracts, remain the industry's softest target.

Step Finance's $27.3 million now sits within that same pattern — a loss driven not by a failure in its code, but by a failure in someone's inbox. Audits confirm code correctness. Bug bounties incentivize outside scrutiny. Security reviews stress-test logic. None of it addresses what happens when the person holding the keys clicks the wrong link on the wrong morning.

Step Finance is far from the first protocol to pay an eight-figure price for that lesson, and with total industry losses for January 2026 already reported at $370 million, it's unlikely to be the last.

Admin PrivilegesStep Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.