Figure Technology and Solana-based DeFi platform Step Finance have both disclosed security incidents, putting the spotlight on attacks that target people as much as systems. Figure said an employee was tricked in a social engineering scam that led to unauthorized file access, while ShinyHunters claimed responsibility and said 2.5GB of sensitive data was leaked. In a separate case, onchain activity tied to Step Finance showed roughly 261,854 SOL moved out of treasury-related wallets, worth nearly $29 million using the article’s cited price of $110 per SOL.
Figure says login credentials were handed over in a scam
Figure explained that it recently discovered an individual had been deceived into giving up login credentials, which allowed someone to download a small number of files through that account. The company said it moved quickly to stop the access and brought in a forensic firm to determine which files were compromised. Based on its own description, the company classified the incident as a social engineering attack built on psychological manipulation rather than a conventional software exploit.
Figure also said it notified affected partners and offered free credit monitoring services. The report added that the company spokesperson did not answer several specific questions about the breach. At the same time, ShinyHunters posted on its dark web platform that it was behind the intrusion and claimed the leak of 2.5GB of data followed after its demands were not met.
Report links the case to a wider campaign involving single sign-on users
Anonymous sources cited in the report said the Figure breach may be part of a broader campaign targeting organizations that use Okta’s single sign-on service. Other alleged victims named in the material were the University of Pennsylvania and Harvard University. No additional technical evidence was included in the source, and the material did not mention any response from Okta or the other institutions.
The concern around these incidents is not limited to code-level weaknesses. Identity workflows, account access, and internal controls can become the entry point. The source cited Chainalysis as saying scammers stole $17 billion in cryptocurrency over the last year while using AI to improve impersonation and social engineering tactics. It also referenced a report from December 2025 saying regulators had filed more than 8,000 filings affecting at least 374 million people.
Step Finance confirms treasury wallet breach as community asks about user exposure
Step Finance, described in the source as a major DeFi platform on Solana, confirmed a breach involving several treasury and fee wallets. Onchain data showed hackers unstaking about 261,854 SOL and sending the funds to unknown addresses. Using the cited market price of $110 per token, the transfers came to nearly $29 million.
In a post on X, Step Finance said it had experienced a security breach in some treasury wallets a few hours earlier and was investigating the matter, with more details to come later. The company did not identify the root cause. That left room for speculation around smart contract issues or access control failures, though the source did not present evidence confirming either explanation.
Because the affected wallets were described as treasury and fee wallets, community attention shifted to whether user funds outside those wallets might also be at risk. According to the report, Step Finance declined to comment beyond its initial statement despite repeated media questions. For now, the public record remains limited to the confirmed breach, the type of wallets involved, and the scale of the onchain transfers.

