DeFi Intel

Step Finance Treasury Drain and Shutdown (January 31, 2026)

Date
2026-01-31
Loss
$27M
Category
Treasury key compromise / protocol shutdown
Attack vector
Targeted phishing / social-engineering compromise of executive-team devices yielded control of the private keys behind Step Finance's treasury and fee wallets; the attacker reassigned stake authority over the protocol's staked SOL to a fresh wallet, unstaked the positions, and withdrew 261,854 SOL (~$27M) during APAC hours, with the team's later all-asset accounting putting losses near $40M. No smart contract was exploited.
Attribution
Unattributed as of mid-2026. Step Finance confirmed executive-device compromise as the root cause; QuillAudits assessed a likely social-engineering attack; CertiK tracked the on-chain flow in near real time; law enforcement was notified but no public identification followed, and the team's early euphemistic disclosure fueled unverified insider speculation.

Overview

On January 31, 2026, Step Finance, the Solana portfolio-management dashboard that had operated since 2021 as one of the ecosystem's longest-running DeFi tools, disclosed that several of its treasury and fee wallets had been drained by what it initially called a sophisticated actor during APAC hours. Blockchain security firm CertiK tracked the core flow within hours: stake authority over the protocol's staked SOL had been reassigned to a fresh attacker wallet, the positions were unstaked, and roughly 261,854 SOL, worth approximately $27 million at the time (CertiK's contemporaneous estimate was $28.9 million), was withdrawn to attacker-controlled addresses. On February 2 the team confirmed the root cause was not a smart-contract exploit but the compromise of executive-team devices, most likely via targeted phishing or social engineering, which handed the attacker the private keys controlling the protocol's operational wallets. Later accounting placed total losses across all assets near $40 million, of which roughly $4.7 million was recovered, including $3.7 million of Remora tokenized-stock assets clawed back using Solana Token-2022 issuer protections. The STEP governance token collapsed more than 80% within 24 hours and roughly 96% from pre-incident levels. On February 24, after failing to secure financing or an acquisition, the team announced the immediate shutdown of Step Finance and its affiliated properties, the media outlet SolanaFloor and the tokenization platform Remora Markets, promising a STEP buyback referenced to a pre-hack snapshot and a 1:1 USDC redemption for fully-backed Remora rTokens. No attribution has been made public and, beyond the issuer-side clawbacks, none of the stolen funds have been recovered. The incident was January 2026's largest single protocol hack in a month CertiK measured at $370.3 million of losses, and it stands as a canonical demonstration that a DeFi protocol's operational key custody, not its audited contracts, is often the binding security constraint, and that a mid-sized protocol without deep reserves or an external backstop may simply not survive the loss of its treasury.

Timeline of events

The drain executed during APAC hours on January 31, 2026. On-chain data reconstructed by CertiK showed the attack proceeding in a tight sequence: stake authorization over Step Finance's staked SOL treasury was transferred to a freshly created wallet (LEP1uHXcWbFEPwQgkeFzdhW2ykgZY6e9Dz8Yro6SdNu), the stake accounts were deactivated and unstaked, and approximately 261,854 SOL worth roughly $27 million (CertiK's contemporaneous estimate was $28.9 million) was withdrawn from treasury and fee wallets to attacker-controlled addresses, with a second wallet (7raxiejD8hDUH1wyYWFDPrEuHiLUjJ4RiZi2z1u2udNh) observed downstream. Within hours the team disclosed on X that several of its treasury wallets had been compromised by a sophisticated actor, publicly requesting help from cybersecurity firms via direct messages, an improvised incident-response posture that itself drew criticism. STEP collapsed more than 80% within 24 hours, from roughly $0.023 to under $0.0016. On February 2 the team dropped the euphemisms and confirmed the root cause: the compromise of the executive team's devices. Users were advised not to trade STEP pending investigation, and the team committed to a pre-exploit snapshot of holdings for any future compensation. Over the following three weeks the team's accounting expanded the total loss across all asset types to approximately $40 million while roughly $4.7 million was recovered. On February 24, having failed to close financing or an acquisition, Step announced the immediate shutdown of Step Finance, SolanaFloor, and Remora Markets; STEP fell a further 36% to about $0.00057, against an April 2021 all-time high of $10.20.

Attack mechanism

The attack contained no smart-contract exploit. Step Finance's on-chain programs and the third-party protocols its dashboard aggregated behaved normally throughout; what failed was the custody of the private keys controlling the project's own wallets. According to the team's February 2 statement, devices belonging to members of the executive team were compromised, most likely through targeted phishing or social engineering, the assessment offered by QuillAudits, while CertiK initially described only a well-known attack vector. Halborn's analysis outlined the two plausible mechanics of such a compromise: direct extraction of private keys stored or entered on the infected devices, or malware capable of manipulating the transaction-approval flow so that executives signed operations they did not intend. Whichever variant applied, the on-chain evidence shows the attacker obtained full signing control rather than a one-off malicious approval: they were able to reassign stake authority over the protocol's staked SOL positions to a wallet they controlled, an operation that on Solana requires the stake account's authority key. With stake authority rotated, the attacker deactivated and unstaked the positions, converting the treasury's long-duration validator stake, the same stake whose earnings had historically funded STEP buybacks, into liquid SOL, and withdrew approximately 261,854 SOL in a consolidated flow alongside the contents of the protocol's fee wallets. Additional assets across other wallets brought the team's claimed total toward $40 million. The unstaking step is the signature of the incident: it demonstrates patient, complete key control rather than an opportunistic approval hijack.

Root cause analysis

Three failures compound. First, endpoint security: the devices of the executive team were the effective perimeter, and a phishing or social-engineering compromise of those devices was sufficient to reach protocol-critical key material. Nothing about the treasury's protection exceeded the security of a personal laptop or phone. Second, custody architecture: keys able to reassign stake authority and drain both treasury and fee wallets were usable from those compromised devices. There is no public evidence that hardware-isolated signing, MPC key sharding, or a multi-party authorization scheme with independent signers stood between an infected endpoint and the full treasury; whatever multisig arrangements existed, a single compromise chain proved sufficient to execute authority rotation, unstaking, and withdrawal end to end. This is the same class of failure as Radiant Capital's signer-device compromise and DMM Bitcoin's key-management breach: audited on-chain code rendered irrelevant by the off-chain signing environment. Third, treasury concentration and business fragility: essentially all of the project's runway, its validator stake, its fee income, and the reserves behind its buyback program were reachable through one custody chain, with no segregation between hot operating funds and long-term cold reserves, so a device compromise became an extinction event rather than a survivable loss. A secondary root cause was communicative: early reliance on phrases like sophisticated actor and well-known attack vector before the February 2 admission created an information vacuum that unverified insider-involvement speculation filled, deepening the collapse of confidence in STEP.

Initial response and wind-down decision

Disclosure was fast even if the substance lagged: the team posted within hours of the APAC-hours drain and openly solicited cybersecurity firms, and CertiK was documenting the flows in near real time. Users were told not to engage with the STEP token until the investigation concluded, and the team committed to a pre-exploit snapshot so that any eventual remedy would reference holdings and values before the crash. The concrete recovery inside the first days was approximately $4.7 million: about $3.7 million of tokenized-stock assets on Remora Markets were clawed back using the issuer-side protections of Solana's Token-2022 standard, and roughly $1 million of other positions was secured with partner help. Law enforcement was notified. For three weeks the company pursued survival: co-founder George Harrap acknowledged acquisition interest, saying some parties had reached out about acquiring various businesses but that the company was on a time crunch, while the team sought external financing. Neither path closed. On February 24 the company announced it was ceasing operations effective immediately, stating it had explored every possible path forward, including financing and acquisition opportunities, but was unable to secure a viable outcome. The shutdown swept in the affiliated properties: SolanaFloor, the ecosystem media outlet, and Remora Markets, the tokenized-equities platform built from the Moose Capital acquisition. Harrap called it a difficult day and said his immediate priority was finding roles for the team. Immunefi CEO Mitchell Amador's observation that nearly 80% of crypto projects suffering a major hack never fully recover became the incident's epitaph.

Funds tracking and laundering

CertiK identified and tracked the stolen funds from the first hours, publishing the figure of 261,854 SOL that most outlets adopted (independent trackers logged marginally different totals, such as 261,932 SOL, reflecting how the multi-wallet flow was counted). The primary destination wallet, LEP1uHXcWbFEPwQgkeFzdhW2ykgZY6e9Dz8Yro6SdNu, received the consolidated withdrawal after the stake-authority rotation, with 7raxiejD8hDUH1wyYWFDPrEuHiLUjJ4RiZi2z1u2udNh observed as a secondary attacker address. In the initial reporting window the behavior was notably patient: the funds sat parked in attacker-controlled wallets with no observed bridge hops, no mixer deposits, and no Tornado Cash-style obfuscation, a posture that distinguished the operation from the rapid fan-out laundering typical of DPRK-attributed thefts. Subsequent coverage through February described the bulk of the SOL being dispersed to unknown addresses and sold, contributing to pressure on both SOL and STEP, but no exchange freezes, seizures, or negotiated returns were announced publicly. No on-chain message, bounty negotiation, or white-hat overture from the attacker is on record, and no security firm or agency has published an attribution; the operation's tradecraft, device compromise followed by stake-authority rotation and patient consolidation, is consistent with an experienced, crypto-native actor but does not by itself identify one. As of mid-2026 the stolen funds beyond the roughly $4.7 million recovered through issuer-side controls remain unrecovered, and the investigation opened with law enforcement has produced no public progress reports.

Recovery and remediation

Because Step Finance was a non-custodial dashboard, the theft hit the project's own treasury rather than user deposits held in Step contracts: user positions lived on the third-party protocols the dashboard aggregated. The direct victims were therefore the company, its token holders, and the users of its affiliated products, and the remediation program was shaped accordingly. The most technically interesting recovery was the Remora clawback: because Remora Markets issued its tokenized stocks (rStocks) using Solana's Token-2022 extensions, issuer-side controls allowed roughly $3.7 million of stolen rStocks to be recovered or neutralized in attacker wallets, a rare demonstration that permissioned token standards can convert theft of the token into theft of nothing. A further $1 million or so of other positions was secured, capping total recovery near $4.7 million against approximately $40 million of claimed losses. For holders, the wind-down plan promised two mechanisms: a buyback of STEP referenced to a snapshot of holdings and prices taken before the incident, funded from what remained of company assets, and a redemption process converting Remora rTokens, which remained fully backed at a 1:1 ratio and isolated from the incident, into USDC. The Solana Crossroads conference brand and SolanaFloor ceased operations alongside the main platform. The remediation is best characterized as an orderly liquidation rather than a recovery: no white-hat return, insurance payout, ecosystem bailout, or law-enforcement seizure materialized, and the buyback's economics were bounded by a treasury that had just lost the majority of its value.

Industry implications

The incident anchored the worst month for crypto security in nearly a year. CertiK measured $370.3 million lost to exploits and scams in January 2026, the highest in 11 months and almost quadruple January 2025, with phishing and social engineering accounting for $311.3 million of it, including a single $284 million individual-victim scam; Step Finance was the month's largest protocol hack, ahead of Truebit's $26.4 million contract exploit. The composition tells the story of the era: attacker effort has migrated from smart-contract bugs to people and their devices, a trajectory running from Ronin's compromised validator keys through Radiant Capital's infected signer devices and Bybit's manipulated signing flow to Step's phished executives. For DeFi treasuries specifically, the incident hardened several expectations: protocol-critical keys should live in hardware-isolated or MPC custody that no single endpoint compromise can defeat; staked treasuries need multi-party stake authority and alerting on authority rotation, which on Solana is the fast path from long-duration stake to liquid loot; and operating funds should be segregated from reserves so one custody chain cannot be existential. The Token-2022 clawback also entered the industry playbook, sharpening the debate over permissioned token standards: the same issuer controls that rescued $3.7 million are centralization levers in normal times. Finally, the shutdown demonstrated protocol mortality: unlike Bybit or KelpDAO, whose nine-figure holes were bridged by balance sheets and consortia, a mid-cap protocol with a drained treasury and no backstop simply died, taking a media outlet and a tokenization platform with it.

Verdict and lessons

Step Finance is the cleanest 2026 illustration that a protocol is its keys. Five years of operation, an established product suite, a validator business, a media arm, and a conference brand were extinguished in 24 days by a phishing compromise of executive devices, with not one line of on-chain code at fault. The verdict on the attack is that it was competent and patient rather than novel: device compromise, full key control, stake-authority rotation, unstake, withdraw. The verdict on the victim is harsher. Keys able to move the entire treasury were reachable from personal devices; the staked reserve that funded the token's buyback mechanism could be redirected by a single authority rotation; and there was no segregation that would have left the company a survivable core. The lessons are correspondingly operational. Treasury custody must assume endpoint compromise: hardware isolation, MPC sharding, or genuinely independent multi-party authorization, with no single device able to complete the kill chain. Stake authority deserves the same protection and monitoring as withdrawal keys, because rotation is silent and unstaking is fast. Segregate: a protocol that keeps runway, reserves, and fee flow behind one custody chain has chosen extinction as its failure mode. Communicate precisely: euphemism created the vacuum that insider speculation filled, and trust in STEP died faster than the treasury did. And plan for mortality: the industry's improvised backstops rescue systemically important venues, not mid-cap dashboards; for everyone else, survival is a pre-arranged property, insurance, reserves, and rehearsed response, or it is luck.

Recovery

Approximately $4.7M of ~$40M in claimed losses was recovered: about $3.7M of Remora rStocks clawed back or neutralized via Solana Token-2022 issuer-side protections, plus roughly $1M of other positions secured with partner help. None of the stolen SOL was recovered, and no white-hat return, insurance payout, or seizure materialized. The wind-down plan announced February 24, 2026 promised a STEP buyback referenced to a pre-incident snapshot of holdings and prices, funded from remaining company assets, and a 1:1 USDC redemption for fully-backed Remora rTokens. Step Finance, SolanaFloor, and Remora Markets all ceased operations.

Key lessons

  • Treasury keys must never be usable from executive laptops or phones: assume endpoint compromise and require hardware-isolated signing, MPC sharding, or genuinely independent multi-party authorization for every treasury operation
  • Stake authority is an attack surface equal to withdrawal keys: staked treasuries need multi-party authority and real-time alerting on authority rotation, which is silent and converts cold stake to liquid funds quickly
  • Segregate operating funds from long-term reserves so that no single custody chain can be existential; a drained treasury killed the protocol, not the exploit itself
  • Incident communications shape survival: euphemisms like sophisticated actor create information vacuums that insider speculation fills, destroying token and counterparty confidence faster than the theft
  • Mid-cap protocols need pre-arranged survival mechanisms (insurance, segregated reserves, rehearsed response); improvised backstops rescue systemically important venues only, and nearly 80% of majorly hacked projects never fully recover (Immunefi)

Frequently asked questions

What happened in the Step Finance Treasury Drain and Shutdown?

Step Finance, Solana's longest-running portfolio dashboard, lost 261,854 SOL (~$27M, with ~$40M claimed across all assets) on January 31, 2026 after attackers phished executive-team devices, stole the keys to its treasury and fee wallets, reassigned stake authority to a fresh wallet, unstaked, and withdrew the funds during APAC hours. No contract was exploited. STEP crashed more than 80% in a day and ~96% overall. The team recovered ~$4.7M, including $3.7M of Remora tokenized stocks clawed back via Token-2022 issuer controls, but could not close financing or an acquisition and shut down Step Finance, SolanaFloor, and Remora Markets on February 24, promising a snapshot-based STEP buyback and 1:1 USDC rToken redemption. The attacker remains unidentified. January 2026's largest protocol hack in a $370.3M month (CertiK): audited contracts do not matter if treasury keys live on a phishable laptop.

How much was lost?

Approximately $27M was lost on 2026-01-31.

How did the attack work?

Targeted phishing / social-engineering compromise of executive-team devices yielded control of the private keys behind Step Finance's treasury and fee wallets; the attacker reassigned stake authority over the protocol's staked SOL to a fresh wallet, unstaked the positions, and withdrew 261,854 SOL (~$27M) during APAC hours, with the team's later all-asset accounting putting losses near $40M. No smart contract was exploited.

Who was responsible?

Unattributed as of mid-2026. Step Finance confirmed executive-device compromise as the root cause; QuillAudits assessed a likely social-engineering attack; CertiK tracked the on-chain flow in near real time; law enforcement was notified but no public identification followed, and the team's early euphemistic disclosure fueled unverified insider speculation.

Were the funds recovered?

Approximately $4.7M of ~$40M in claimed losses was recovered: about $3.7M of Remora rStocks clawed back or neutralized via Solana Token-2022 issuer-side protections, plus roughly $1M of other positions secured with partner help. None of the stolen SOL was recovered, and no white-hat return, insurance payout, or seizure materialized. The wind-down plan announced February 24, 2026 promised a STEP buyback referenced to a pre-incident snapshot of holdings and prices, funded from remaining company assets, and a 1:1 USDC redemption for fully-backed Remora rTokens. Step Finance, SolanaFloor, and Remora Markets all ceased operations.

Related