← Step Finance — AI Agent Over-Permission Exploit (January 2026)1 decision on this page
Audit log
Every state-changing event for Step Finance — AI Agent Over-Permission Exploit (January 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-03 17:12:40ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
6eHmwquz3yVZ…j38Jacs6sha256 → base58
verifying row…canonical bytes (16921 B) ▸
{"actor":"system:backfill","investigation_id":"bb0f5270-464b-4b29-bfc6-0040fd189172","kind":"publish","page_slug":"step-finance-ai-agent-over-permission-exploit-january-2026","published_at":"2026-08-03T17:12:40.184Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Step Finance — AI Agent Over-Permission Exploit (January 2026)","sections":[{"content":"On January 31, 2026, Step Finance disclosed a security breach in which 261,854 SOL — valued at approximately $27–30 million at the time of extraction — was unstaked and transferred out of the protocol's treasury and fee wallets within roughly 90 minutes. The platform initially characterized total losses as 'approximately $40 million,' a figure that may include secondary asset valuations and fee accounts beyond the primary SOL withdrawal. Blockchain security firm CertiK confirmed the on-chain data, identifying a single dominant withdrawal transaction of 261,932 SOL to a secondary wallet (address: 7raxiejD8hDUH1wyYWFDPrEuHiLUjJ4RiZi2z1u2udNh). The governance token STEP fell over 80% in the 24 hours following disclosure.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":1,"name":"CoinDesk: Solana-Based Step Finance Hit by $30 Million Treasury Hack as Token Price Craters","type":"news_article","url":"https://www.coindesk.com/business/2026/01/31/solana-based-defi-platform-step-finance-hit-by-usd30-million-treasury-hack-as-token-price-craters"},{"credibility":2,"name":"Rekt News: Step Finance — On-Chain Analysis","type":"research","url":"https://rekt.news/step-finance-rekt"},{"credibility":2,"name":"CryptoNews: $30M Stolen as Step Finance Treasury Wallets Compromised","type":"news_article","url":"https://cryptonews.com/news/30m-stolen-as-step-finance-treasury-wallets-compromised/"}]},{"content":"Step Finance confirmed on February 2, 2026, that the breach originated from the compromise of devices belonging to members of the executive team. The likely method was social engineering or phishing targeting executive endpoints, which exposed private keys and signing authority over treasury multisig wallets. This gave attackers the ability to transfer stake authorization to an attacker-controlled address (receiving wallet: LEP1uHXcWbFEPwQgkeFzdhW2ykgZY6e9Dz8Yro6SdNu), after which the stake was unstaked and the SOL transferred in a single on-chain transaction. Security researchers including QuillAudits described the method as a 'well-known attack vector' consistent with targeted spear-phishing. No smart contract vulnerability was identified; the exploit was entirely operational in nature, relying on stolen signing credentials.","heading":"Attack Vector: Executive Device Compromise","severity":"critical","sources":[{"credibility":2,"name":"Rekt News: Step Finance — On-Chain Analysis","type":"research","url":"https://rekt.news/step-finance-rekt"},{"credibility":2,"name":"Tom's Hardware: $40 Million Worth of Crypto Stolen from Step Finance","type":"news_article","url":"https://www.tomshardware.com/tech-industry/cyber-security/usd40-million-worth-of-crypto-stolen-from-step-finance-hackers-compromise-executives-devices-to-gain-illicit-access"},{"credibility":2,"name":"Halborn: Explained — The Step Finance Hack (January 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-step-finance-hack-january-2026"}]},{"content":"Secondary analysis by security researchers identified AI trading agents integrated into Step Finance's platform as a significant factor that amplified the scale of the theft. According to Beam AI and KuCoin research published in 2026, Step Finance had deployed autonomous AI agents authorized to execute large SOL transfers without any human approval gate or value threshold. Once attackers obtained executive-level credentials, these agents executed the bulk transfers because their permission model granted unconstrained authority over high-value on-chain transactions. Researchers described the failure architecture as textbook over-permission: the agents 'did exactly what they were designed to do,' but their design included the ability to move tens of millions of dollars in a single session without triggering any pause or review mechanism. No isolation boundary separated the compromised user context from the agents' signing authority. The agents lacked per-agent credentials, transaction value ceilings, or human-in-the-loop requirements for large transfers. This case is frequently cited as the most significant documented instance of AI agent over-permission enabling a major crypto theft. It is important to note that the AI agent angle is documented primarily by Tier 2 and Tier 3 sources; Step Finance's own public statements focused on device compromise and did not specifically attribute losses to AI agent architecture.","heading":"AI Agent Over-Permission: The Amplifying Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"Beam AI: 5 Real AI Agent Security Breaches in 2026 and Their Lessons","type":"research","url":"https://beam.ai/agentic-insights/ai-agent-security-breaches-2026-lessons"},{"credibility":2,"name":"KuCoin: AI Trading Agent Vulnerability 2026 — How a $45M Crypto Security Breach Exposed Protocol Risks","type":"research","url":"https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks"},{"credibility":2,"name":"AssureDefi: Step Finance Hack Explained — How $40M Vanished in Minutes","type":"research","url":"https://www.assuredefi.com/blog/step-finance-hack-explained-40m-executive-device-breach"}]},{"content":"Following the initial theft on January 31, 2026, stolen SOL remained in on-chain wallets visible on Solscan for a period before movement began. Post-February, Arkham Intelligence tracking revealed the exploiter sold a significant portion of stolen SOL and bridged approximately $21.4 million to the Ethereum network, converting proceeds into ETH. The funds were subsequently routed through Tornado Cash, the OFAC-sanctioned cryptocurrency mixing protocol, significantly diminishing prospects for on-chain recovery. Approximately $4.7 million was ultimately recovered by Step Finance through Token22 security protections, primarily attributable to Remora Markets-related assets and approximately $1 million in other positions. The remaining losses of roughly $35 million are considered unrecoverable absent law enforcement intervention.","heading":"Fund Movement and Laundering","severity":"high","sources":[{"credibility":2,"name":"Crypto Briefing: Step Finance Exploiter Sells $21M in SOL, Buys ETH and Launders Funds Through Tornado Cash","type":"on_chain","url":"https://cryptobriefing.com/step-finance-exploiter-launders-funds-tornado-cash/"},{"credibility":1,"name":"CoinDesk: Step Finance Shuts Operations After $27 Million January Hack","type":"news_article","url":"https://www.coindesk.com/business/2026/02/24/step-finance-shuts-operations-after-usd27-million-january-hack"}]},{"content":"On February 24, 2026, Step Finance co-founder George Harrap announced via X (Twitter) that the platform was immediately ceasing all operations. Harrap stated the team had explored 'every possible path forward, including financing and acquisition opportunities' but was 'unable to secure a viable outcome.' Harrap also noted, 'A difficult day and my core priority right now is finding good roles for our excellent team.' The shutdown extended to two affiliated platforms: SolanaFloor, a Solana-focused NFT analytics and media outlet, and Remora Markets, a tokenization and lending protocol. A buyback program for STEP token holders was announced based on a pre-hack snapshot of holdings, and a redemption process for Remora rToken holders was initiated. The STEP token had lost approximately 96% of its value from pre-hack levels and fell a further 36% on the day of the shutdown announcement, reaching $0.00057 against an all-time high of $10.20 in August 2021.","heading":"Platform Shutdown and Affiliated Projects","severity":"high","sources":[{"credibility":1,"name":"CoinTelegraph: Step Finance Shuts Down After $40 Million Hack","type":"news_article","url":"https://cointelegraph.com/news/step-finance-solanafloor-remora-markets-wind-down-operations"},{"credibility":2,"name":"Decrypt: Solana DeFi Project Step Finance to Wind Down Weeks After $29M Hack","type":"news_article","url":"https://decrypt.co/358970/solana-defi-project-step-finance-to-wind-down-weeks-after-29m-hack"},{"credibility":1,"name":"CoinDesk: Step Finance Shuts Operations After $27 Million January Hack","type":"news_article","url":"https://www.coindesk.com/business/2026/02/24/step-finance-shuts-operations-after-usd27-million-january-hack"}]},{"content":"The Step Finance incident occurred during a broader period of elevated DeFi exploit activity. January 2026 recorded approximately $370 million in total crypto losses, of which phishing-related attacks accounted for roughly $311 million. Security researchers cite Step Finance as a landmark case illustrating how AI agent over-permission transforms a bounded operational security failure into a catastrophic total loss. Recommended mitigations identified in post-incident analyses include: implementing per-agent credentials isolated from executive signing authority; enforcing transaction value thresholds that trigger human-in-the-loop approval for large transfers; applying zero-trust architecture between agent systems and treasury wallets; and maintaining strict isolation boundaries so that a single compromised context cannot propagate to autonomous execution agents. Step Finance's permanent shutdown, affecting a platform that had been described as the 'front page of Solana' since its 2021 founding, represented a significant blow to the Solana DeFi ecosystem.","heading":"Industry Context and Security Implications","severity":"high","sources":[{"credibility":2,"name":"Beam AI: 5 Real AI Agent Security Breaches in 2026 and Their Lessons","type":"research","url":"https://beam.ai/agentic-insights/ai-agent-security-breaches-2026-lessons"},{"credibility":2,"name":"CCN: 400M+ Lost to DeFi Exploits in 2026","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-2026-137m-lost-step-finance-truebit-resolv-exploits/"},{"credibility":2,"name":"GovInfoSecurity: Cryptohack Roundup — Step Finance Shuts Down After Exploit","type":"news_article","url":"https://www.govinfosecurity.com/cryptohack-roundup-step-finance-shuts-down-after-exploit-a-30855"}]}],"sources_used":[{"credibility":1,"name":"CoinDesk: Solana-Based Step Finance Hit by $30 Million Treasury Hack","type":"news_article","url":"https://www.coindesk.com/business/2026/01/31/solana-based-defi-platform-step-finance-hit-by-usd30-million-treasury-hack-as-token-price-craters"},{"credibility":1,"name":"CoinDesk: Step Finance Shuts Operations After $27 Million January Hack","type":"news_article","url":"https://www.coindesk.com/business/2026/02/24/step-finance-shuts-operations-after-usd27-million-january-hack"},{"credibility":1,"name":"CoinTelegraph: Step Finance Shuts Down After $40 Million Hack","type":"news_article","url":"https://cointelegraph.com/news/step-finance-solanafloor-remora-markets-wind-down-operations"},{"credibility":2,"name":"Halborn: Explained — The Step Finance Hack (January 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-step-finance-hack-january-2026"},{"credibility":2,"name":"Rekt News: Step Finance","type":"research","url":"https://rekt.news/step-finance-rekt"},{"credibility":2,"name":"Decrypt: Solana DeFi Project Step Finance to Wind Down Weeks After $29M Hack","type":"news_article","url":"https://decrypt.co/358970/solana-defi-project-step-finance-to-wind-down-weeks-after-29m-hack"},{"credibility":2,"name":"Crypto Briefing: Step Finance Exploiter Sells $21M in SOL, Buys ETH and Launders Funds Through Tornado Cash","type":"on_chain","url":"https://cryptobriefing.com/step-finance-exploiter-launders-funds-tornado-cash/"},{"credibility":2,"name":"Beam AI: 5 Real AI Agent Security Breaches in 2026 and Their Lessons","type":"research","url":"https://beam.ai/agentic-insights/ai-agent-security-breaches-2026-lessons"},{"credibility":2,"name":"KuCoin: AI Trading Agent Vulnerability 2026","type":"research","url":"https://www.kucoin.com/blog/en-ai-trading-agent-vulnerability-2026-how-a-45m-crypto-security-breach-exposed-protocol-risks"},{"credibility":2,"name":"AssureDefi: Step Finance Hack Explained — How $40M Vanished in Minutes","type":"research","url":"https://www.assuredefi.com/blog/step-finance-hack-explained-40m-executive-device-breach"},{"credibility":2,"name":"GovInfoSecurity: Cryptohack Roundup — Step Finance Shuts Down After Exploit","type":"news_article","url":"https://www.govinfosecurity.com/cryptohack-roundup-step-finance-shuts-down-after-exploit-a-30855"},{"credibility":2,"name":"Tom's Hardware: $40 Million Worth of Crypto Stolen from Step Finance","type":"news_article","url":"https://www.tomshardware.com/tech-industry/cyber-security/usd40-million-worth-of-crypto-stolen-from-step-finance-hackers-compromise-executives-devices-to-gain-illicit-access"},{"credibility":2,"name":"CCN: 400M+ Lost to DeFi Exploits in 2026","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-2026-137m-lost-step-finance-truebit-resolv-exploits/"},{"credibility":2,"name":"Yahoo Finance: Step Finance and SolanaFloor Shut Down After Devastating Hack","type":"news_article","url":"https://finance.yahoo.com/news/step-finance-solanafloor-shut-down-021611434.html"}],"summary":"Step Finance, a Solana DeFi portfolio manager and aggregator founded in 2021, suffered a treasury breach on January 31, 2026, in which attackers compromised executive devices and exploited AI trading agents with unconstrained transfer authority to drain an estimated $27–40 million in SOL. Unable to secure refinancing or an acquisition, the project permanently shut down on February 24, 2026, along with affiliated platforms SolanaFloor and Remora Markets, with only $4.7 million recovered.","timeline":[{"date":"2021-01-01","event":"Step Finance launched on Solana as a DeFi portfolio aggregator and yield management platform, later described as the 'front page of Solana.'","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/01/31/solana-based-defi-platform-step-finance-hit-by-usd30-million-treasury-hack-as-token-price-craters"},{"date":"2021-08-01","event":"STEP token reached its all-time high of $10.20.","source":"Decrypt","source_url":"https://decrypt.co/358970/solana-defi-project-step-finance-to-wind-down-weeks-after-29m-hack"},{"date":"2026-01-31","event":"Attackers compromised executive devices, transferred stake authorization to an attacker-controlled wallet, and drained 261,854 SOL (approximately $27–30 million) from treasury wallets within roughly 90 minutes. Step Finance disclosed the breach the same day.","source":"CoinDesk / Rekt News","source_url":"https://www.coindesk.com/business/2026/01/31/solana-based-defi-platform-step-finance-hit-by-usd30-million-treasury-hack-as-token-price-craters"},{"date":"2026-02-02","event":"Step Finance confirmed that the root cause was the compromise of executive team devices, consistent with a phishing or social engineering attack. Total claimed losses revised to approximately $40 million.","source":"Rekt News / Tom's Hardware","source_url":"https://rekt.news/step-finance-rekt"},{"date":"2026-02-05","event":"Approximately $4.7 million recovered through Token22 security protections and partner coordination, primarily from Remora Markets-related assets.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/02/24/step-finance-shuts-operations-after-usd27-million-january-hack"},{"date":"2026-02-23","event":"Step Finance co-founder George Harrap announced via X (Twitter) that the project was immediately shutting down all operations after failing to secure financing or an acquisition. SolanaFloor and Remora Markets also announced closure.","source":"CoinTelegraph / Decrypt","source_url":"https://cointelegraph.com/news/step-finance-solanafloor-remora-markets-wind-down-operations"},{"date":"2026-02-24","event":"Shutdown formalized. STEP token fell an additional 36% on the announcement day, reaching $0.00057. Buyback program for STEP holders and rToken redemption process announced.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/02/24/step-finance-shuts-operations-after-usd27-million-january-hack"},{"date":"2026-03-01","event":"Post-incident on-chain tracking by Arkham Intelligence revealed the exploiter sold stolen SOL and bridged approximately $21.4 million to Ethereum before routing funds through Tornado Cash.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/step-finance-exploiter-launders-funds-tornado-cash/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 2a81251b-65fd-4668-b195-7474f1d4c64f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.