Crypto platform Step Finance shutting down after $40 million theft

A crypto heist in January has led to the shutdown of the decentralized finance platform Step Finance, the company announced Monday. 

Earlier this month, Step Finance said about $40 million had been stolen from its treasury on January 31 after devices owned by members of its executive team were compromised. The DeFi platform said it is winding down operations as a direct result of the theft. 

“Following the hack at the end of January we explored every possible path forward, including financing and acquisition opportunities. Unfortunately, we were unable to secure a viable outcome and have made the difficult decision to end all operations effective immediately,” the company said this week.

Two associated projects, the news outlet SolanaFloor and trading platform Remora Markets, will also be shut down. Step Finance was founded in 2021 and later acquired Remora Markets.

The platform allowed users to manage their crypto assets and positions with visualizations and trackers. 

The company explained that it is working on a buyback program for people holding STEP coins and a redemption process for people who held Remora tokens. 

It was able to recover about $3.7 million in stolen Remora assets and about $1 million in other coins. A snapshot was taken from before the theft so that Step token holders could be reimbursed. 

The shutdown comes days after two security incidents that saw crypto platforms lose $10 million and more than $4 million, respectively. 

More than $3 billion worth of cryptocurrency was stolen in attacks on platforms and personal wallets last year.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

UAE claims it stopped ‘terrorist’ ransomware attack

Next Post

US ‘committed’ to fighting transnational gangs behind Southeast Asian scam compounds: FBI

Related Posts

China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines

Chinese-speaking threat actors are suspected to have leveraged a compromised SonicWall VPN appliance as an initial access vector to deploy a VMware ESXi exploit that may have been developed as far back as February 2024. Cybersecurity firm Huntress, which observed the activity in December 2025 and stopped it before it could progress to the final stage, said it may have resulted in a ransomware
Read More

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

Multiple security vendors are sounding the alarm about a second wave of attacks targeting the npm registry in a manner that's reminiscent of the Shai-Hulud attack. The new supply chain campaign, dubbed Sha1-Hulud, has compromised hundreds of npm packages, according to reports from Aikido, HelixGuard, JFrog, Koi Security, ReversingLabs, SafeDep, Socket, Step Security, and Wiz. The trojanized
Read More