Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
cryptocurrency-platform-riskoperational-disruptionbreach-disclosure-notificationinitial-access-method

Step Finance Treasury Wallet Theft via Compromised Executive Devices

Updated 3mo agoFirst seen Feb 4, 20263 sources

Step Finance, a Solana-based DeFi platform and analytics dashboard, reported a breach in which attackers compromised devices belonging to company executives and used that access to drain multiple treasury wallets. The incident was detected on January 31, with the threat actor described as leveraging a “well-known attack vector,” though Step Finance did not publicly disclose the specific technique or attribution.

Initial third-party estimates from blockchain analytics firm CertiK put the theft at 261,854 SOL (~$28.9M), but Step Finance’s internal investigation later assessed total losses at ~$40M. Step Finance said it has recovered ~$3.7M in Remora assets and ~$1M in other positions through partner coordination and Token22 protections, temporarily halted some operations to reinforce security, and stated that Remora Markets is isolated from the incident with rTokens remaining 1:1 backed; users were also advised not to engage with the STEP token until the investigation concludes.

Share:
Step Finance Treasury Wallet Theft via Compromised Executive Devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 3, 20265mo ago

Step Finance reports partial recovery and Remora isolation

Step Finance said it had recovered about $3.7 million in Remora assets and roughly $1 million in other positions through Token22 protections and partner coordination. It also stated that Remora Markets was isolated from the incident and that all rTokens remained fully backed 1:1.

Step Finance discloses total losses of about $40 million

Step Finance publicly said its internal investigation found the total losses were approximately $40 million, significantly higher than the initial blockchain-based estimate. The company attributed the incident to a compromised executive-device attack using a 'well-known attack vector,' without naming the attackers or specific method.

CertiK estimates initial theft at 261,854 SOL

Blockchain analytics firm CertiK reported that 261,854 SOL, worth about $28.9 million, had been illicitly withdrawn from Step Finance. This was the first public estimate of the scale of the theft.

Jan 31, 20265mo ago

Step Finance halts some operations and notifies authorities

After detecting the breach, Step Finance engaged cybersecurity researchers, notified authorities, and temporarily halted some operations to reinforce security. The company also warned users not to use STEP tokens until the investigation concludes.

Step Finance detects executive-device compromise and wallet breach

On 2026-01-31 during APAC hours, Step Finance detected a security incident in which attackers compromised devices used by company executives and gained unauthorized access to multiple treasury wallets. The breach led to a drain of platform-held digital assets and prompted an internal investigation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Organizations
5 linked
CertiKStep FinanceBleepingComputerTinesRemora Markets
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Step Finance Treasury Wallet Theft via Compromised Executive Devices | Mallory