Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 7 of 31 entries · page 2 of 2
August 2022·CryptocurrencyCampaign

Deepfake of Binance communications chief used to scam crypto projects on video calls

Multiple cryptocurrency projects seeking Binance listings · Multiple countries

In August 2022 Binance disclosed that a 'sophisticated hacking team' had produced a deepfake video likeness of chief communications officer Patrick Hillmann and used it on Zoom calls with representatives of cryptocurrency projects. The impersonator offered help getting tokens listed on Binance and solicited payments and information. Hillmann said several project managers were convinced before the fraud was discovered, and that the clone was built from his publicly available interview footage.

Deepfake Video CallConfirmed AI-enabled
Reported2 sources
June 23, 2022·Cryptocurrency

Phishing of a Harmony developer preceded the $100M Horizon Bridge theft

Harmony (Horizon Bridge) · United States

Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.

Spear Phishing (Email)
$100.0M funds lostConfirmed2 sources
April 3, 2022·Cryptocurrency

Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds

SatoshiLabs (Trezor), via email provider Mailchimp · Czech Republic

Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.

Vendor / Supply Chain Impersonation
Confirmed2 sources
March 23, 2022·Cryptocurrency

Ronin Bridge crypto theft caused by a fake LinkedIn job offer PDF

Sky Mavis (Ronin Network / Axie Infinity) · Vietnam

On 23 March 2022 attackers drained the Ronin bridge that underpinned the Axie Infinity game, in one of the largest cryptocurrency thefts on record; the loss was noticed only six days later. Reporting by The Block and others established that a senior Sky Mavis engineer had been approached on LinkedIn by fake recruiters, taken through several rounds of interviews, and sent an offer document as a PDF whose opening installed spyware.

Fake Job Offer / Recruitment Lure
$620.0M funds lostConfirmed4 sources
November 13, 2020·Cryptocurrency

Vishing of GoDaddy staff hijacked domains of crypto firms Liquid and NiceHash

GoDaddy (registrar); Liquid.com and NiceHash · United States

Attackers social-engineered a small number of GoDaddy employees into transferring control of domains belonging to at least six cryptocurrency businesses, including Liquid.com and NiceHash. With registrar-level control they altered DNS records, which for Liquid gave them access to internal email accounts and document storage. GoDaddy confirmed the social engineering and said the affected accounts were locked down. It followed a similar March 2020 voice-phishing incident at the same registrar.

Vishing (Voice Phishing)
Confirmed2 sources
January 2018·Cryptocurrency

AT&T SIM swap drains $24M in crypto from investor Michael Terpin

Michael Terpin (individual investor; Transform Group) · United States

Cryptocurrency investor Michael Terpin lost roughly $24 million in tokens after attackers took over the mobile phone number tied to his accounts. Terpin sued AT&T, alleging the carrier failed to protect his subscriber information under Section 222 of the Federal Communications Act. He separately won a $75.8 million civil judgment against Nicholas Truglia in what his counsel described as the first SIM-swap racketeering case.

SIM Swap
$24.0M funds lostConfirmed2 sources
2018·Cryptocurrency

Joel Ortiz gets 10 years for $7.5M SIM-swap crypto theft spree

Approximately 40 individual cryptocurrency holders · United States

Joel Ortiz, a 21-year-old college student, pleaded no contest to ten felony theft counts after hijacking the phone numbers of roughly 40 cryptocurrency holders and draining their wallets. He was sentenced to ten years in prison by a Santa Clara County judge, in what is widely described as the first US conviction for crypto theft by SIM swapping. The REACT (Regional Enforcement Allied Computer Team) task force investigated.

SIM Swap
$7.5M multi-victim totalConfirmed2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Cryptocurrency.