Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 24 of 31 entries
April 13, 2026·Cryptocurrency

Kraken refuses extortion after two support insiders accessed client data

Kraken · United States

CoinDesk reported on April 13, 2026 that Kraken faced an extortion attempt in which criminals threatened to release video purporting to show access to internal systems. The threat followed two separate incidents in which individuals on Kraken's support team gained inappropriate access to limited client support data. Roughly 2,000 client accounts, about 0.02 percent of the customer base, had limited data potentially viewed.

Insider RecruitmentAttempt blocked
2.0K affectedConfirmed1 source
April 1, 2026·Cryptocurrency

Six-month DPRK social engineering operation preceded $285M Drift Protocol theft

Drift Protocol · Unknown

Drift Protocol lost $285 million on April 1, 2026. Beginning in autumn 2025, people posing as a quantitative trading firm approached Drift contributors in person at cryptocurrency conferences, opening Telegram groups at first contact and holding months of substantive conversations about trading strategies and vault integrations. Between December 2025 and January 2026 the group deposited over $1 million to onboard an Ecosystem Vault on Drift, establishing legitimacy inside the ecosystem. Attribution to a North Korean cluster carries medium confidence.

Vendor / Supply Chain Impersonation
$285.0M funds lostReported2 sources
February 2026·Cryptocurrency

Deepfake of a crypto CEO on a fake Zoom call delivered macOS malware

An unnamed cryptocurrency company executive · Unknown

Mandiant reported in February 2026 that North Korean group UNC1069 targeted a cryptocurrency company official using a hijacked Telegram account belonging to another crypto executive. The victim was sent a Calendly link leading to a Zoom meeting hosted on attacker infrastructure, where they were shown what appeared to be a deepfake of a cryptocurrency CEO. The attackers then ran a ClickFix pretext and installed the WAVESHAPER and HYPERCALL backdoors plus DEEPBREATH and CHROMEPUSH stealers on the victim's macOS device.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
January 10, 2026·Cryptocurrency

$282M in Bitcoin and Litecoin stolen from a holder via social engineering

Unnamed cryptocurrency holder · Unknown

On 10 January 2026 an attacker drained 1,459 BTC and 2.05 million LTC, worth roughly $282 million, from a single hardware-wallet holder in what on-chain investigators described as a social engineering attack. Most proceeds were swapped into Monero across multiple instant exchanges, driving a 70 percent XMR price rise over four days, with some Bitcoin bridged out via Thorchain. Investigator ZachXBT said there was no indication of North Korean involvement.

Tech Support Scam
$282.0M funds lostReported2 sources
August 2025·Cryptocurrency

Scattered Spider member sentenced to 10 years over SIM swap and phishing thefts

Cryptocurrency holders and companies targeted by the group · United States

A Florida federal court sentenced Noah Michael Urban, a member of the Scattered Spider cybercrime group, to 10 years in prison in August 2025 and ordered $13 million in restitution to 59 victims. Urban pleaded guilty to conspiracy, wire fraud and aggravated identity theft over SIM swapping and corporate phishing campaigns that drained cryptocurrency wallets and gave the group access to corporate accounts.

SIM Swap
$13.0M funds lostConfirmed2 sources
July 24, 2025·Cryptocurrency

Crypto exchange WOO X loses $14 million after staff member phished

WOO X · Taiwan

Crypto trading platform WOO X suspended withdrawals on 24 July 2025 after an attacker drained roughly $14 million. The company's post-mortem said the attacker compromised a team member through a phishing attack, then used that access to reach the platform's development environment and issue fraudulent withdrawal requests. WOO X halted trading, said fewer than a hundred accounts were affected, and pledged to reimburse users.

Spear Phishing (Email)
$14.0M funds lostConfirmed2 sources
June 2025·Cryptocurrency

BlueNoroff uses deepfaked executives on a fake Zoom call to plant macOS malware

Employee of a cryptocurrency foundation (Web3 sector) · United States

In June 2025 Huntress published details of an intrusion in which a cryptocurrency foundation employee was contacted on Telegram by a supposed external professional, sent a Calendly link that appeared to be a Google Meet invitation, and redirected to an attacker-controlled fake Zoom domain. Weeks later the employee joined a group video call featuring deepfakes of their own senior leadership. When audio failed, the synthetic participants told them to install a 'Zoom extension' that was in fact a malicious AppleScript, leading to eight malicious binaries on the macOS host including a Go backdoor, keylogger and cryptocurrency stealer. The activity was attributed to DPRK-aligned BlueNoroff.

Deepfake Video CallConfirmed AI-enabled
Confirmed2 sources
May 15, 2025·Cryptocurrency

Bribed overseas support agents leaked Coinbase data; $20M extortion refused

Coinbase · United States

Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.

Insider Recruitment
69K affectedConfirmed3 sources
May 8, 2025·Cryptocurrency

Social engineering of a cloud ops employee preceded BitoPro's $11.5M theft

BitoPro · Taiwan

Taiwanese exchange BitoPro lost about $11.5 million from an old hot wallet on May 8, 2025, during a wallet system upgrade and asset transfer operation, and disclosed the incident on June 3. BitoPro said the attackers first conducted social engineering against an employee who managed cloud operations, then deployed malware on that person's device. The exchange attributed the attack to the Lazarus Group based on methodology matching prior exchange and SWIFT intrusions.

Spear Phishing (Email)
$11.5M funds lostReported2 sources
May 2025·Cryptocurrency

Kraken advanced a North Korean fake job applicant to unmask his tradecraft

Kraken (Payward, Inc.) · United States

Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.

Fake IT Worker InfiltrationAttempt blocked
Confirmed2 sources
May 2025·Cryptocurrency

Binance and Kraken block bribery attempts aimed at support staff

Binance and Kraken · United States

In the weeks around the Coinbase insider breach, the same style of attack was attempted against Binance and Kraken. Bloomberg-sourced reporting said threat actors approached customer support staff at both exchanges over Telegram and offered bribes for system access and customer data. Both exchanges detected and blocked the approaches, and neither reported any user data exposure.

Insider RecruitmentAttempt blocked
Reported1 source
March 2025·CryptocurrencyCampaign

'Elusive Comet' fake VC and podcast Zoom invites drained crypto founders

Multiple cryptocurrency founders, traders and investors; Trail of Bits' CEO was targeted unsuccessfully · Multiple

From March 2025, a group tracked as Elusive Comet ran fake venture capital and media personas, including a bogus firm called Aureon Capital, Aureon Press and The OnChain Podcast, plus impersonated Bloomberg Crypto producers. Targets were booked onto Zoom calls where attackers requested remote control of the victim's machine. Trail of Bits' CEO was approached with a podcast invitation and recognised the campaign before joining. Washington State's financial regulator issued an alert on Aureon Capital.

Vishing (Voice Phishing)
Reported2 sources
February 21, 2025·Cryptocurrency

Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI

Bybit · United Arab Emirates

On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.

Vendor / Supply Chain Impersonation
$1.5B funds lostConfirmed5 sources
October 2024·Cryptocurrency

DPRK actor posing as a former contractor took $50M from Radiant Capital

Radiant Capital · Unknown

Radiant Capital lost about $50 million in October 2024. On September 11, a threat actor impersonating a trusted former contractor messaged a Radiant developer on Telegram from a spoofed version of the contractor's real domain and shared a ZIP file framed as a request for feedback. The file was passed among other developers, spreading malware. Mandiant attributed the attack with high confidence to a DPRK-nexus actor tracked as UNC4736.

Vendor / Supply Chain Impersonation
$50.0M funds lostReported2 sources
August 19, 2024·Cryptocurrency

Fake Google and Gemini support calls cost a Genesis creditor $243M in bitcoin

An individual Genesis creditor in Washington, D.C. · United States

On August 19, 2024, a Genesis creditor in Washington, D.C. lost 4,064 BTC, about $243 million, in what was among the largest single-victim crypto thefts on record. The victim received a call from a spoofed number purporting to be Google support, followed by callers impersonating Gemini support. Malone Lam, 20, and Jeandiel Serrano, 21, were arrested in September 2024 and charged with conspiracy to steal and launder cryptocurrency.

Vishing (Voice Phishing)
$243.0M funds lostReported2 sources
July 18, 2024·Cryptocurrency

WazirX signers approved a spoofed transaction and lost $235M

WazirX · India

Indian exchange WazirX lost about $234.9 million on July 18, 2024 from a multisignature wallet operated jointly with custody provider Liminal. The wallet used a four-of-six scheme with five WazirX keys and one Liminal key. Attackers had staged the operation in advance by opening an account and moving tokens through it. Multiple analyses attributed the theft to the Lazarus Group; WazirX and Liminal publicly disputed where the compromise originated.

Vendor / Supply Chain Impersonation
$234.9M funds lostReported2 sources
May 2024·Cryptocurrency

LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft

DMM Bitcoin, via wallet software vendor Ginco · Japan

Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.

Fake Job Offer / Recruitment Lure
$308.0M funds lostConfirmed2 sources
March 26, 2024·Cryptocurrency

Munchables loses $62.5M to a developer it hired who was linked to North Korea

Munchables (NFT game on Blast) · Unknown

Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.

Fake IT Worker Infiltration
$62.5M funds lostReported2 sources
December 14, 2023·Cryptocurrency

Ledger Connect Kit poisoned after a former employee's npm account was phished

Ledger SAS · France

On 14 December 2023 Ledger's Connect Kit, a JavaScript library that thousands of decentralised applications load to connect user wallets, was replaced on npm with malicious versions containing a wallet drainer. Ledger's own incident report states a former employee fell victim to a phishing attack that gave the attacker their npmjs account, bypassing two-factor authentication by using the individual's session token. The malicious file was live for about five hours.

Spear Phishing (Email)
$600K funds lostConfirmed3 sources
July 22, 2023·Cryptocurrency

Fake recruiter's coding test cost payment processor CoinsPaid $37M

CoinsPaid · Estonia

Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.

Fake Job Offer / Recruitment Lure
$37.0M funds lostReported2 sources
May 2023·Cryptocurrency

Blockchain Capital co-founder loses $6.3M in SIM swap; $14M attempt blocked

Bart Stephens, co-founder of Blockchain Capital · United States

Blockchain Capital co-founder Bart Stephens lost $6.3 million in cryptocurrency to a SIM-swap attack in May 2023 and sued the unidentified attacker in the Northern District of California on August 16, 2023. A separate attempt to move about $14 million out of a cold storage wallet was blocked when a Blockchain Capital employee saw the withdrawal notification and intervened. The attacker taunted Stephens, claiming the ability to remotely hijack any phone number in the mainland US.

SIM SwapAttempt blocked
$6.3M funds lostReported1 source
February 5, 2023·Cryptocurrency

Coinbase employee phished by SMS then talked through by a fake IT caller

Coinbase · United States

In February 2023 Coinbase employees received SMS messages urging them to log in urgently via a supplied link. One employee entered credentials. When MFA blocked the attacker's remote login, the attacker phoned the same employee posing as Coinbase corporate IT and walked them through actions at their workstation. Coinbase's SIEM flagged the anomaly within about ten minutes and an incident responder reached the employee, who broke off contact. Only limited corporate directory information was exposed.

Smishing (SMS)Attempt blocked
Confirmed3 sources
November 11, 2022·Cryptocurrency

SIM swap at an AT&T store enabled the $400M FTX drain on bankruptcy night

FTX (referred to as 'Victim 1' in the indictment) · United States

On the night FTX filed for bankruptcy, roughly $400 million in cryptocurrency left its wallets. In February 2024 the DOJ indicted three people over a SIM-swapping conspiracy running from March 2021 to April 2023, including a November 2022 swap against an unnamed 'Victim 1'. Investigators and blockchain analysts concluded from the date, amount and transaction pattern that the victim was FTX.

SIM Swap
$400.0M funds lostReported1 source
October 2022·Cryptocurrency

3Commas users phished for API keys, leading to unauthorised trades on FTX accounts

3Commas users (with linked FTX and Binance accounts) · Estonia

In October 2022 users of the crypto trading-bot platform 3Commas reported unauthorised trades on their FTX and Binance accounts. 3Commas said attackers had built counterfeit 3Commas websites that tricked users into entering their exchange API keys, which were then used to execute wash trades that drained value from the victims' accounts. 3Commas later confirmed that a set of API keys had been leaked, and FTX said it would compensate some affected users.

Credential Phishing Portal
$6.0M multi-victim totalReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?sector=Cryptocurrency.