Skip to content
ONLINE
--:--:-- UTC
Writing
5 min read6 sources

FinTech security is an access problem

The largest crypto theft on record and one of the costliest exchange breaches of 2025 broke no cryptography. Both abused legitimate access: a tampered signing interface and bribed support staff. That is where FinTech security budgets belong.

Shuja Abrar · Blockchain Consultant & Engineer

  • cybersecurity
  • fintech
  • insider risk
  • dora
  • key management
On this page
  1. 01Bybit was a signing problem
  2. 02Insiders, contractors and fake employees
  3. 03Resilience regulation asks the same questions
  4. 04The customer edge
  5. 05What to prioritise this quarter
  6. Sources (6)

Chainalysis counted more than $3.4 billion stolen from the crypto industry in 2025. North Korean groups accounted for at least $2.02 billion of it, a 51% increase on 2024 achieved with 74% fewer known attacks. The February theft from Bybit alone was $1.5 billion. In May, Coinbase disclosed that criminals had bribed overseas support contractors to copy customer data out of internal support tools, then demanded $20 million. Coinbase refused and estimated the cost of remediation and reimbursement at between $180 million and $400 million.

None of these incidents broke cryptography. No elliptic curve was attacked, no hash function failed. In each case the attacker used access that was legitimate on paper: a signer approving a transaction, a support agent looking up an account, a developer's cloud credentials. For FinTech firms, that is the most important lesson of the past year, and it applies well beyond crypto.

01Bybit was a signing problem

Bybit's cold wallet was a multisig. Multiple people had to approve any movement, on hardware wallets, which is exactly the setup most security reviews recommend. It still failed.

Investigations published in March 2025 traced the attack to a compromised workstation belonging to a developer at Safe{Wallet}, the multisig interface Bybit used. The attackers used that access, including live cloud session tokens, to plant malicious JavaScript in the interface's hosted front end, targeted at Bybit specifically. Signers saw what looked like a routine transfer. What their hardware wallets were actually asked to sign changed the logic of the wallet contract and handed control to the attacker. The FBI attributed the theft to the North Korean cluster it calls TraderTraitor within five days.

A multisig is only as strong as what each signer independently verifies. If every signer reads the transaction through the same web interface, the interface is a single point of failure, and the multiple signatures add little.

The same is true of any FinTech approval flow, crypto or not. A payment release that needs two approvers in an internal dashboard is protected by the dashboard's integrity, its hosting and its build pipeline as much as by the two people. If an attacker can change what the approvers see, dual control becomes a formality. The question to ask of every approval step is where the approver's view of the transaction comes from, and whether anything independent confirms it.

The controls that address this are well understood, and too rarely applied together. Decode every high-value transaction independently of the interface that proposed it, on a separate machine or in a separate tool. Use hardware wallets and message formats that show signers the full structured data, and refuse to sign anything displayed as an opaque hash. Simulate the transaction before signing and compare the resulting state with what was intended. Allowlist the contracts and function selectors a treasury wallet may call, and put a time delay on anything outside the list. Treat any change to a wallet's implementation or owners as its own ceremony, never bundled with a routine transfer.

02Insiders, contractors and fake employees

The Coinbase breach used a different door. Support agents, working for an outsourcing provider, had the access their jobs required to look up customer accounts. A small number were paid to use it at scale. The stolen data, including names, addresses, parts of identity documents and account histories, was then used for social engineering attacks against the affected customers.

Chainalysis' year-end analysis points to a related tactic: North Korean operators getting hired, often as remote IT workers, inside exchanges, custodians and web3 companies, so that the access they abuse is granted to them through normal onboarding.

The defences are unglamorous. Give support tools the minimum data each task needs, and mask the rest by default. Grant elevated access just in time, for a named ticket, and let it expire. Log every lookup and alert on patterns no single ticket explains, such as an agent viewing hundreds of high-balance accounts in a shift. Hold outsourcing providers to the same monitoring standard as staff, contractually and in practice. Verify the identity of remote hires more rigorously than a video call allows, and review access regularly for people whose role no longer needs it.

03Resilience regulation asks the same questions

The EU's Digital Operational Resilience Act has applied since 17 January 2025, and it covers crypto-asset service providers authorised under MiCA as well as banks, insurers and payment firms. In November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers for direct oversight, a list that includes the major cloud platforms.

DORA's emphasis on third-party risk maps directly onto what happened at Bybit. A hosted wallet interface is an ICT third-party service. So are node and RPC providers, custody technology vendors, KYC and screening services, and the outsourced support desk in the Coinbase case. Each one needs an owner inside the firm, a documented understanding of what it can touch, an exit plan, and testing that assumes it may be compromised rather than only that it may go offline.

04The customer edge

Theft from individuals is growing too. Chainalysis counted around 158,000 personal wallet compromises in 2025 affecting roughly 80,000 people, even though the total value taken from individuals fell. Its 2026 crime report puts the wider picture in context: at least $154 billion received by illicit addresses in 2025, most of it in stablecoins.

For FinTech firms offering on-ramps, self-custody or payments, the customer's device and judgement are part of the attack surface whether the firm likes it or not. Product controls help: warnings and confirmation delays for first-time withdrawal addresses, detection of address poisoning where a lookalike address is planted in a user's history, clear display of token approvals, and withdrawal allowlists customers can opt into. After a data breach like Coinbase's, assume affected customers will be targeted by convincing impersonators and tell them precisely what your staff will never ask for.

05What to prioritise this quarter

Inventory every path by which a person or system can move funds or read customer data, including vendors, and name an owner for each. Remove any single interface from the signing path for high-value transactions and add independent decoding and simulation. Put least-privilege, just-in-time access and anomaly alerts on support and operations tools. Bring outsourced and remote staff under the same monitoring as employees. Test a scenario in which a trusted third party is compromised, not just unavailable.

The attacks of the past year were not technically exotic. They were patient and aimed at people and processes. The response should be equally practical.

All writing