Research details
Context
The same playbook keeps working. Between 2023 and 2025, state-sponsored attackers breached multiple centralized platforms through spearphishing, trojanized applications, fraudulent IT workers, and supply-chain infiltration, with collective losses exceeding $2 billion. The targets changed but the tactics barely evolved, which means the defences are failing at the same points.
Key takeaways
- The initial compromise is almost always a person, not a system. Spearphishing campaigns, trojanized job offers, and fraudulent IT contractors gave attackers a foothold inside platform infrastructure, often weeks or months before the theft itself. Technical controls alone cannot close this gap without employee verification and security-aware operational procedures.
- No single control would have prevented these attacks. Endpoint protection, vendor oversight, least-privilege access, privileged-access management, and network segmentation each address a different stage of the attack chain. When any one is missing or misconfigured, the attacker moves through it. Coordinated deployment across all layers is what raises the cost of compromise.
- Wallet controls failed because they verified identity, not intent. In multiple incidents, authorised signers approved transactions that had been altered before reaching them. Clear signing, independent transaction checks, segregation of duties, authorisation thresholds, and real-time anomaly detection shift the verification from “who signed” to “what was actually signed.”
Contributors
- OneInfinity R&D team
Related Research

Bybit Incident Research
How a supply-chain compromise bypassed multi-signature controls in the largest crypto theft in history, and what custody operations can learn from it.
Read the analysis
DMM Bitcoin May 2024 Incident Analysis
Reconstructing the probable attack behind DMM Bitcoin’s $305 million loss through on-chain forensic evidence.
Read the analysis
A Risk Classification Framework for Decentralized Finance Protocols
Classifying the technical, economic, operational and infrastructure risks of DeFi protocols - giving insurers a consistent basis for comparing exposures.
Read the reportInterested in working together?
Our team is expanding research across Web3, Cybersecurity, and AI.

