Cybersecurity

Recent Centralized Platform Hack Tactics & Mitigation

Mapping the attack tactics behind over $2 billion in centralized platform losses and the layered controls that can disrupt them.

Published May 2025

Share:

Research details

Context

The same playbook keeps working. Between 2023 and 2025, state-sponsored attackers breached multiple centralized platforms through spearphishing, trojanized applications, fraudulent IT workers, and supply-chain infiltration, with collective losses exceeding $2 billion. The targets changed but the tactics barely evolved, which means the defences are failing at the same points.

Key takeaways

  1. The initial compromise is almost always a person, not a system. Spearphishing campaigns, trojanized job offers, and fraudulent IT contractors gave attackers a foothold inside platform infrastructure, often weeks or months before the theft itself. Technical controls alone cannot close this gap without employee verification and security-aware operational procedures.
  2. No single control would have prevented these attacks. Endpoint protection, vendor oversight, least-privilege access, privileged-access management, and network segmentation each address a different stage of the attack chain. When any one is missing or misconfigured, the attacker moves through it. Coordinated deployment across all layers is what raises the cost of compromise.
  3. Wallet controls failed because they verified identity, not intent. In multiple incidents, authorised signers approved transactions that had been altered before reaching them. Clear signing, independent transaction checks, segregation of duties, authorisation thresholds, and real-time anomaly detection shift the verification from “who signed” to “what was actually signed.”

Contributors

  • OneInfinity R&D team

Interested in working together?

Our team is expanding research across Web3, Cybersecurity, and AI.