Crypto companies bring together several characteristics that make social engineering exceptionally attractive to cybercriminals: irreversible digital assets, geographically dispersed workforces, complex networks of contractors, and human-risk management programs that are often still developing. As a result, the sector offers attackers unusually high potential rewards with comparatively low operational barriers. This pattern is not accidental. It is rooted in the structure of the industry itself. The factors that place each part of the crypto ecosystem at risk can therefore be traced to specific operational weaknesses that social engineers deliberately exploit.
According to Chainalysis, incidents involving social engineering represented the majority of cryptocurrency-related losses in 2025. The ByBit breach alone resulted in approximately $1.5 billion being removed from cold-wallet infrastructure. The incident did not begin with exploitation of a zero-day vulnerability. Instead, a developer was manipulated into authorizing a malicious transaction. Figure Lending suffered the theft of 2.5 GB of sensitive customer information after one employee was deceived during an Okta-style voice-phishing operation. Transak experienced a similar incident, which exposed information belonging to between 57,000 and 92,000 users.
The same pattern appears across different types of companies, asset categories, and geographic regions: human controls frequently fail before technical defenses are breached.
Why Is Social Engineering More Attractive in Crypto Than in Traditional Finance?
Four fundamental characteristics make the cryptocurrency industry particularly exposed when compared with conventional financial institutions:
| Property | Crypto | Traditional Finance |
| Asset reversibility | Transactions are irreversible, with no chargebacks or recalls | Transactions can be reversed in most jurisdictions |
| Settlement speed | Transactions settle almost immediately, globally, and around the clock | Settlement usually occurs within T+1 or T+2 and is commonly tied to business hours |
| Team distribution | Workforces are global, frequently remote-first, and heavily dependent on contractors | Teams are generally more centralized and office-based |
| Regulatory maturity | Regulation remains fragmented, with frameworks such as MiCA, NYDFS, and SEC requirements still differing significantly | Major financial institutions operate under compliance frameworks developed over several decades |
| Human-risk program maturity | Human-risk programs remain relatively immature at many organizations | Large banks and insurers generally maintain established programs |
Once an attack succeeds, cryptocurrency can be transferred globally almost immediately, and recovery is often impossible. There is usually no equivalent of a traditional fraud department capable of recalling the transaction afterward. This imbalance explains why sophisticated threat actors place such a high value on crypto targets, including nation-state operators, organized criminal groups, and phishing campaigns enhanced by AI.
Crypto Exchange Platforms
Why Are Crypto Exchanges Targeted?
Cryptocurrency exchanges are attractive targets primarily because they control billions of dollars in highly liquid assets stored across hot and cold wallets. Those assets can be transferred globally and generally cannot be recovered once a transaction has been completed. At the same time, rapid expansion often requires exchanges to operate globally distributed teams and depend heavily on overseas contractors to maintain round-the-clock support services. The combination of extremely valuable assets and a broad human attack surface creates an especially favorable environment for social engineering.
Structural vulnerabilities:
- Access to hot-wallet infrastructure is often shared among engineering and operations personnel. This produces a broad human attack surface for credential-stealing phishing campaigns.
- Continuous 24/7 support requires significant reliance on contractors. Security awareness, vetting procedures, and background screening may vary considerably across these teams.
- Integrations with external custodians, market makers, KYC providers, and other third parties introduce supply-chain entry points that may allow attackers to circumvent perimeter defenses.
- Globally distributed teams operate across multiple time zones. Monitoring and incident-response gaps between regions can give attackers more time to remain undetected.
What Are the Real Threat Risks for Exchanges?
- Supply-chain social engineering can focus on developers of third-party tools, transaction signers, or other participants in critical approval workflows. This was the attack path associated with the ByBit hack in 2025. Attackers socially engineered a developer or signer involved in the transaction-signing process. They subsequently altered the signing workflow so that multisignature reviewers unknowingly authorized malicious transfers from cold-wallet infrastructure. The estimated loss reached approximately $1.4 billion to $1.5 billion in ETH and stETH.
- Insider recruitment and bribery: malicious actors may persuade employees or contractors to steal customer information such as names, email addresses, and KYC records. That information can later support highly convincing impersonation campaigns or fraudulent transaction approvals.
- Support desk compromise through vishing: attackers may impersonate customers or internal personnel in order to request account resets, obtain withdrawal authorization, or bypass two-factor authentication controls.
- Cascading financial and reputational consequences: a successful compromise can lead to customer reimbursement costs, regulatory investigations, and significant customer attrition.
What Compliance Requirements Apply to Exchanges?
- MiCA (EU): CASP-licensed entities must comply with comprehensive AML/KYC requirements, the Travel Rule, and cybersecurity governance obligations that include awareness of social-engineering threats.
- NYDFS BitLicense (NY): requirements include annual penetration testing under §500.05, cybersecurity awareness training under §500.14, and controls over privileged access under §500.07.
- SEC: exchanges that hold customer assets may be subject to custody-related obligations as well as cybersecurity disclosure requirements for material incidents.
- Travel Rule (FATF): organizations must maintain strong identity-verification processes. Those workflows also represent valuable targets for social engineers seeking to manipulate identity and transaction data.
Custody Wallets
Why Are Crypto Custodians Targeted?
Crypto custodians are especially valuable targets because they hold private keys and manage institution-scale digital assets while carrying full custody responsibility. A successful compromise can therefore produce immediate and potentially catastrophic consequences. Multisignature architectures and globally distributed contractor support also create complex chains of authorization. Attackers can study these processes in detail before attempting a compromise. A successful social-engineering campaign against a custodian may affect far more than the custody provider itself. Every institutional organization whose assets are held by that custodian may also be exposed.
Structural vulnerabilities:
- Private-key operations require human authorization at several stages. Every authorization point represents another possible social-engineering opportunity.
- Multisignature systems depend on a quorum of authorized signers. An attacker may therefore only need to compromise part of the signer group rather than every participant.
- Technical support functions frequently depend on contractors. Differences in vetting and access controls can create inconsistently protected entry points.
- Institutional customers such as hedge funds, family offices, and DAOs represent high-value identities that can be impersonated in fraudulent withdrawal requests.
What Are the Real Threat Risks for Custodians?
- Private-key theft through phishing or insider recruitment: compromise of key material can enable immediate and irreversible theft of assets at institutional scale.
- Contractor compromises that remain undetected: a breached or malicious third party may insert unauthorized code or initiate withdrawal operations without authorization.
- Fraudulent withdrawal requests: attackers may impersonate an institutional customer or authorized internal employee in order to trigger an illegitimate transfer.
- Regulatory sanctions and potential loss of licenses: failures involving asset segregation, incomplete audit records, or inadequate documentation of incident-response procedures can result in significant enforcement consequences.
The 2024 Transak incident provides a useful example. An employee was manipulated during an Okta-style voice-phishing operation, allowing attackers to enter corporate systems and expose information associated with approximately 57,000 to more than 92,000 users. Within a custody environment, an equivalent compromise could place customer assets at direct risk rather than exposing only personal or corporate data.
What Compliance Requirements Apply to Custodians?
- CCSS (Cryptocurrency Security Standard): organizations are expected to align key-management procedures, multisignature practices, and operational security controls with CCSS requirements.
- SEC 2025 Custody Rules: requirements include documented policies addressing distributed-ledger risks, qualified-custodian obligations, and stronger programs for managing insider threats.
- DORA (EU): organizations must meet operational-resilience and ICT-risk testing requirements. Advanced testing requirements can also encompass social-engineering simulation.
- NYDFS: contractor oversight requirements are strict, while §500.05 also requires simulated social-engineering testing.
Stablecoin Issuers
Why Are Stablecoin Issuers Targeted?
Stablecoin issuers oversee large fiat-backed reserves while handling high-volume and high-speed flows between traditional currencies and digital assets. These treasury processes require frequent human approvals involving banking institutions, cryptocurrency exchanges, and other partners located across multiple regions. Extensive dependence on exchanges and custodians also creates intermediation chains that attackers can exploit. A successful compromise of a stablecoin issuer’s treasury function can consequently produce effects throughout the broader ecosystem rather than remaining limited to the issuer.
Structural vulnerabilities:
- Treasury departments regularly approve large and frequent conversions between fiat currency and cryptocurrency. These high-value, high-frequency processes are especially attractive targets for Business Email Compromise.
- Reserve administration involves numerous banking counterparties. This creates a broad impersonation surface for fraudulent payment instructions and falsified wire-transfer requests.
- Connections with exchanges and custodians provide access to valuable information about transaction patterns. Social engineers can collect this information to determine the most effective timing and targets for an attack.
- External auditors participate in reserve-verification processes. Their involvement introduces another possible route for credential theft and unauthorized extraction of sensitive information.
What Are the Real Threat Risks for Stablecoin Issuers?
- Business Email Compromise (BEC) and AI-powered deepfake fraud can be used to redirect treasury assets or authorize fraudulent redemption requests. A convincing impersonation of a CFO or a trusted banking representative could potentially result in transfers worth hundreds of millions of dollars.
- Insider-assisted reserve theft: recruited personnel may initiate unauthorized redemptions. Stolen assets can then be rapidly laundered through connected cryptocurrency exchanges before the activity is discovered.
- Cascading regulatory consequences: weaknesses in AML controls, inconsistencies in reserve audits, or shortcomings in post-incident response can lead to enforcement under MiCA or FinCEN requirements and can seriously damage confidence in the issuer.
What Compliance Requirements Apply to Stablecoin Issuers?
- MiCA Titles III and IV: requirements include ongoing reserve transparency, AML controls covering redemption activity, and governance obligations applicable to issuers of e-money tokens and asset-referenced tokens.
- FinCEN/BSA: money services businesses must maintain appropriate AML programs, including relevant employee training.
- NYDFS: stablecoin guidance requires issuers to maintain effective AML controls and comprehensive cybersecurity programs.
- Internal requirements: treasury operations should include monitoring of privileged access, dual authorization for high-value redemptions, and employee training specifically focused on BEC and impersonation threats.
Tokenized Finance (RWA Platforms)
Why Are Tokenized Finance Platforms Targeted?
Platforms for tokenized real-world assets represent a comparatively new and rapidly expanding attack surface. They place regulated, high-value securities on-chain and often use controls similar to those employed by custodians. However, their security programs may be less mature than those found at established traditional custody institutions. Hybrid processes involving issuance, redemption, and custody introduce multiple points at which human supervision can fail. These platforms also combine blockchain infrastructure with valuable off-chain information, including property records, equity registers, and bond terms. Such data can attract sophisticated threat actors, including state-sponsored groups seeking either financial returns or intelligence.
Structural vulnerabilities:
- Token creation and destruction processes frequently require approval from personnel responsible for key management. Those approval workflows create direct targets for social engineering.
- Hybrid architectures connect on-chain activity with off-chain systems. The transition points between the two environments create opportunities for attackers to use social engineering to circumvent technical controls.
- Investor information such as names, KYC records, and portfolio data can be extremely valuable. Stolen records may be used to support impersonation fraud during secondary-market transaction requests.
- Security programs may remain relatively immature despite the substantial value of assets managed by these platforms.
What Are the Real Threat Risks for RWA Platforms?
- Compromise of key management through social engineering: attackers who obtain control over key-management processes may be able to conduct unauthorized token issuance or burns. Such actions can directly alter investor holdings and create violations of securities regulations.
- Supply-chain compromise affecting tokenization infrastructure: attacks against infrastructure providers can expose investor information. They may also create securities-law violations and regulatory liabilities that extend well beyond the immediate financial consequences.
- Figure Lending (2025): an employee was manipulated through social engineering, allowing attackers to enter company systems and exfiltrate approximately 2.5 GB of sensitive information. The incident used an Okta-style voice-phishing campaign. It illustrates the risk faced by RWA platforms whose internal access depends heavily on identity-provider authentication.
- Legal and reputational consequences: a breach capable of damaging confidence in tokenized assets may create broader systemic concerns for the RWA sector rather than affecting only the organization that was initially compromised.
What Compliance Requirements Apply to RWA Platforms?
- SEC Securities Custody Standards: relevant obligations include documented policies addressing DLT risks, qualified-custodian requirements, and measures designed to protect investors.
- MiCA: RWA platforms that fall within CASP licensing requirements must comply with cybersecurity governance obligations and security-awareness requirements.
- Global RWA licensing: frameworks administered by Singapore’s MAS, the UK’s FCA, and the UAE’s VARA increasingly expect organizations to maintain documented programs addressing human-related security risks.
- Mandatory controls: social-engineering simulations, continuous monitoring, and formal incident-response playbooks are increasingly treated as baseline security and compliance practices.
DeFi Platforms
Why Are DeFi Platforms Targeted?
DeFi protocols can concentrate substantial amounts of liquid value within protocol treasuries, governance tokens, and front-end infrastructure. At the same time, some operate without a conventional legal entity, a dedicated compliance department, or mature security-governance processes. Heavy reliance on contractors and publicly accessible development platforms gives attackers extensive opportunities for reconnaissance through open-source repositories, Discord communities, and Telegram channels. Front-end attacks are particularly significant because successful manipulation of developers or infrastructure providers can expose large amounts of total value locked without requiring direct exploitation of the underlying smart contracts.
Structural vulnerabilities:
- DAO governance commonly places authority over protocol upgrades and treasury transfers in the hands of a relatively small group of wallet signers or multisignature holders. Each member of that group therefore becomes a highly valuable social-engineering target.
- Publicly visible developer activity, including GitHub contributions, Discord discussions, and conference participation, provides attackers with extensive material for profiling individuals and creating highly convincing spear-phishing identities.
- Contractor-heavy software development increases exposure to supply-chain compromise at the code and development-tool level.
- Traditional HR and compliance functions may be absent. As a consequence, formal and recurring security-awareness training is often limited or nonexistent.
What Are the Real Threat Risks for DeFi Protocols?
- Manipulation of smart-contract upgrades: social engineers may deceive developers or administrators into approving malicious upgrades or treasury transactions. The Drift DeFi incident in 2026 represents a notable example. North Korean operatives reportedly maintained fabricated identities for several months. They attended conferences, personally met contributors in several countries, and deposited $1 million to strengthen their credibility before delivering the malicious payload. ENS Labs CISO Alexander Urbelis characterized the operation as professional intelligence-style tradecraft more commonly associated with case officers than conventional hackers.
- Governance compromise through insider impersonation: control of contributor accounts can allow attackers to influence governance votes or manipulate multisignature approvals for treasury activity.
- Front-end interface compromise: attackers may socially engineer a developer or hosting provider into introducing malicious code into a protocol’s user interface. This can drain user wallets at scale without modifying or directly exploiting the underlying smart contracts.
- Contagion across connected protocols: DeFi ecosystems are highly interconnected. A social-engineering compromise affecting one protocol may also expose liquidity providers, integrated platforms, and downstream users.
What Compliance Requirements Apply to DeFi Platforms?
- MiCA: when a DeFi platform meets the applicable VASP or CASP threshold because it has sufficient centralization, fiat on/off-ramp functionality, or custody capabilities, it can become subject to full AML requirements and transparent incident-reporting obligations.
- FATF Guidance: decentralized platforms with identifiable controlling parties are increasingly subject to Travel Rule and AML obligations across multiple jurisdictions.
- Practical baseline: even where formal regulatory requirements are absent, institutional liquidity providers and DAO token holders increasingly expect documented security-awareness programs before participating.
- Developer-specific requirements: zero-trust monitoring should cover internal personnel and contractors, while security-awareness training should be mandatory for administrators and transaction signers.
Cross-Segment Attack Patterns to Know
The following attack techniques are repeatedly observed across all five crypto segments:
| Attack Type | Description | Primary Targets |
| AI-generated spear phishing | Highly personalized phishing content created from information gathered through LinkedIn, GitHub, Discord, and similar sources | All segments |
| Vishing/voice-cloning fraud | Synthetic or deepfake audio used to impersonate executives, IT personnel, or banking representatives | Treasury teams, support desks, custodians |
| Stitched hybrid attacks | Multi-stage campaigns combining an email lure, a deepfake voicemail, and subsequent credential submission | High-value authorization workflows across all segments |
| Helpdesk/support desk takeover | Scattered Spider-style identity compromise achieved through manipulation of support personnel | Exchanges, custodians |
| Long-horizon persona operations | Fake identities and relationships developed over weeks or months before delivery of the malicious payload | DeFi, RWA, institutional sales |
| Insider recruitment | Employees or contractors offered financial incentives to cooperate with attackers | Exchanges, stablecoin issuers |
| BEC (Business Email Compromise) | Executive or trusted-party impersonation designed to redirect payments | Stablecoin treasury functions, RWA issuers |
| Supply-chain social engineering | Manipulation of external software vendors, service providers, developers, or code signers | Exchanges, DeFi platforms, custodians |
Conclusion
Crypto firms remain especially attractive targets for social engineering because they manage high-value digital assets that can be transferred almost instantly and are difficult to recover. Many major incidents in the sector begin with manipulation of employees, contractors, or trusted third parties through phishing, impersonation, voice scams, or insider recruitment. Attackers are also increasingly using AI-powered spear phishing, deepfakes, and business email compromise to bypass traditional technical defenses.
These human-related risks affect every part of the crypto ecosystem, including exchanges, custodians, stablecoin issuers, DeFi protocols, and RWA platforms. Reducing this exposure requires a strong security-awareness program supported by phishing-resistant MFA and robust transaction-verification controls.
Arsen platform helps reinforce one of the most vulnerable elements of any cybersecurity system – its employees. The human factor continues to be a major security challenge, particularly as social engineering techniques become more sophisticated and AI-driven attacks continue to evolve.







