Connect with us
DAPA Banner

Crypto World

Figure Blockchain Lender Confirms Customer Data Breach Following Social Engineering Attack

Published

on

21Shares Introduces JitoSOL ETP to Offer Staking Rewards via Solana

TLDR:

  • Figure Technology employee tricked in social engineering attack enabling unauthorized data access 
  • ShinyHunters published 2.5GB of customer data including names, addresses, and phone numbers 
  • Attack part of broader campaign targeting companies using Okta single sign-on authentication 
  • Figure offers free credit monitoring and maintains customer funds remain secure despite breach

 

Figure Technology disclosed a customer data breach on Friday after an employee fell victim to a social engineering attack.

The blockchain lender confirmed that hackers accessed limited customer files through the compromised account. Hacking group ShinyHunters claimed responsibility for the incident and published approximately 2.5 gigabytes of stolen data. The company has launched a forensic investigation and implemented additional security measures.

Attack Details and Compromised Information

Figure explained the breach in a statement, noting that attackers manipulated an employee through deceptive tactics to gain unauthorized system access.

“We recently identified that an employee was socially engineered, and that allowed an actor to download a limited number of files through their account,” the company said. Figure identified the incident quickly and responded to contain the threat.

Advertisement

The lender emphasized its swift response to the security incident. “We acted quickly to block the activity and retained a forensic firm to investigate what files were affected,” Figure stated. The company worked to determine the full scope of compromised data following the discovery.

ShinyHunters stated that Figure refused to pay a ransom demand before publishing the stolen data. TechCrunch reviewed portions of the leaked files and confirmed they contained sensitive customer information.

The exposed data includes full names, home addresses, dates of birth, and phone numbers of affected individuals.

Advertisement

The New York-based lender specializes in home equity lines of credit using its Provenance blockchain platform. Founded in 2018, Figure went public in September 2025 under ticker symbol FIGR.

The initial public offering raised $787.5 million and valued the company at approximately $5.3 billion.

Broader Campaign and Company Response

A ShinyHunters member told TechCrunch the attack was part of a larger campaign targeting organizations using Okta single sign-on services.

Harvard University and the University of Pennsylvania were among other alleged victims in this widespread operation. The connection suggests a coordinated effort exploiting vulnerabilities in shared authentication systems.

Advertisement

Figure is communicating with partners and affected customers about the breach. “We are offering complimentary credit monitoring to all individuals who receive a notice,” the company said. These protective measures aim to help customers guard against potential identity theft or fraud.

The lender reassured customers about account security despite the data exposure. “We continuously monitor accounts and have strong safeguards in place to protect customers’ funds and accounts,” Figure stated. The company maintains that customer funds remain secure throughout the incident.

Data breaches have become increasingly common across industries in recent years. Privacy Rights Clearinghouse reported over 8,000 notification filings in 2025 tied to more than 4,000 separate incidents. These breaches affected at least 374 million people throughout the year.

Figure announced a secondary public offering on the same day as the breach disclosure. The company plans to offer up to 4.23 million shares of Series A Blockchain Common Stock.

Advertisement

The stock closed Friday up 3.57% at $35.29, though it has declined 37% over the past month.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Zcash patches critical bug affecting the Sprout shielded pool

Published

on

IoTeX confirms $2M hack, rejects $4.3M theft claims

Zcash has patched a major vulnerability that would have allowed bad actors to drain funds from the protocol’s deprecated Sprout shielded pool.

Summary

  • Zcash patched a critical flaw in zcashd nodes that skipped proof verification in the legacy Sprout pool, a bug that could have exposed more than 25,000 ZEC to potential draining.
  • The vulnerability remained present from July 2020 until the release of v6.12.0, with no exploitation detected and all user funds confirmed safe.

A disclosure report from security researcher Alex “Scalar” Sol, published on Tuesday, claims that a critical flaw was discovered in zcashd nodes that resulted in skipping proof verification for transactions involving the legacy Sprout pool.

Zcash’s Sprout pool is the original “shielded pool” that launched with the network in 2016. It was the first implementation of zero-knowledge proofs (zk-SNARKs) in a production cryptocurrency, allowing users to send and receive ZEC privately.

Advertisement

Although the pool was closed to new deposits in November 2020, it still holds approximately 25,424 ZEC, which are yet to be migrated to newer shielded pool versions.

According to the disclosure, the vulnerability spanned releases from July 2020 onward but was fixed through v6.12.0, which was released on Tuesday. So far, the flaw has not been exploited, and user funds remain safe.

Major mining pools, including Luxor, F2Pool, ViaBTC, and AntPool, have already deployed the fix by March 26, the report added.

Advertisement

The report added that the Zebra full node implementation was not affected. In the event of an attempted exploit, it would have resulted in a chain fork, acting as an additional safeguard.

Despite the severity of the issue, the Zcash Open Development Team has clarified that the network’s “turnstile” mechanism, which enforces that any coins exiting the Sprout pool must have previously entered it, would have prevented broader supply inflation.

For the Zcash network, this marks the second time a critical, systemic vulnerability has been uncovered within its shielded pools. In 2019, the Zcash team disclosed a “counterfeiting” bug, a flaw in the underlying cryptography that could have allowed an attacker to create an infinite amount of ZEC without detection.

Advertisement

Source link

Continue Reading

Crypto World

Crypto selloff deepens with $400 million liquidations and rising short interest

Published

on

Crypto selloff deepens with $400 million liquidations and rising short interest

Bitcoin gave back a large portion of its recent gains on Thursday, now trading at $66,700 having lost 2.4% of its value since midnight UTC.

Ether (ETH) performed even worse, tumbling by 4.4% as the broader crypto market struggles to deal with continued risk-off sentiment.

The latest plunge was spurred by U.S. president Donald Trump, who said on Wednesday evening that the war in Iran would continue with extensive strikes on Iran.

“Over the next two to three weeks, we’re going to bring them back to the stone ages where they belong,” he said.

Advertisement

The comments led to an immediate spike in oil prices, with brent crude rising by around 10% to $108 per barrel as U.S. equities diverged.

Nasdaq 100 and S&P 500 futures lost 1.5% and 1.1% respectively while the U.S. dollar increased by 0.5% to above 100 points.

Derivatives positioning

  • BTC’s price has dropped over 2% since midnight UTC hours alongside a slightly uptick in open interest in major USD- and USDT-denominated futures. Plus, perpetual funding rates have dropped to their most negative since March 12. This combination suggests that traders are bearish and shorting the falling market.
  • In ether’s case, funding rates are most negative since October last year, a sign of strong bias for bearish bets. Meanwhile, bearishness in solana (SOL) is surprisingly more measured despite the overnight hack.
  • Privacy-focused zcash (ZEC) and have seen a notable decline in open interest (OI) in 24 hours, a sign of capital outflows.
  • Nearly $400 million in futures positions have been liquidated due to margin shortfalls. That’s a 17% increase in losses compared to the previous day.
  • Despite renewed risk-off tone, bitcoin and ether’s 30-day implied volatility indices remain flat in recent ranges. It points to orderly selling in the spot market rather than panic.
  • There is little scope for panic because traders are already positioned for market swoon. They have been consistently chasing bitcoin and ether put options (downside hedges) since the start of the year. As of writing, bitcoin and ether puts remained pricier than calls across all tenors on Deribit.
  • Block flows featured demand for ether straddles, a volatility strategy, and put spreads and bitcoin call spreads.

Token talk

  • The worst performing benchmark on Thursday was CoinDesk’s DeFi Select Index (DFX), which lost 5.9% since midnight UTC, closely followed by the CoinDesk Computing Select Index (CPUS) that tumbled by 5%.
  • Ethena (ENA) led the downside move as it fell by more than 10% on Thursday, there was also a heavy drawdown among DeFi tokens UNI, LDO, SKY and AAVE – all shedding between 4.2% and 6.5% during Asian and European hours on Thursday.
  • Algorand (ALGO) bucked the bearish market trend, rising by around 0.8% on Thursday as it continues its rich vein of form having rallied by 22% in the past week.
  • CoinMarketCap’s “altcoin season” index is down from 50/100 to 42/100 since March 30, highlighting relative weakness across the sector.

Source link

Continue Reading

Crypto World

CLARITY Act Nearing Senate Markup, Floor Vote

Published

on

CLARITY Act Nearing Senate Markup, Floor Vote

Coinbase chief legal officer Paul Grewal said the US Digital Asset Market Clarity Act is “moving toward” a markup hearing in the US Senate Banking Committee and could eventually move to a floor vote if senators resolve the stablecoin yield dispute and schedule a markup.

Speaking in a Wednesday interview on Fox Business, Grewal said lawmakers are nearing agreement on core elements of the crypto market structure bill, even as debate continues over stablecoin yield. “I think we’re very close to a deal,” he said.

The remarks point to possible movement on one of the last major sticking points in Senate talks over crypto market structure legislation: whether stablecoin issuers or platforms should be allowed to offer yield or similar rewards. The dispute has helped delay a Senate Banking Committee markup, leaving the broader effort to set federal rules for digital asset oversight still unresolved.

US banks have pushed for restrictions, arguing that such incentives could draw deposits away from traditional institutions and disrupt the banking system. Grewal pushed back on that claim, saying there is no evidence to support fears of deposit flight.

Advertisement

The US House of Representatives passed the CLARITY Act on July 17, 2025. In January, Senate Banking Committee Chair Tim Scott delayed a planned markup, which has yet to be rescheduled.

Related: Crypto investor sentiment will rise once CLARITY Act is passed: Bessent

Trump blames banks for stalling crypto bill

Last month, US President Donald Trump accused banks of undermining efforts to pass crypto market structure legislation, saying they are blocking progress over disagreements on stablecoin yield payments. “The Banks should not be trying to undercut The Genius Act, or hold The Clarity Act hostage,” he wrote.

It was later reported that Trump met privately with Coinbase CEO Brian Armstrong just hours before issuing the statement.

Advertisement
Coinbase shares are down 23% YTD. Source: Yahoo! Finance

In January, Armstrong said Coinbase could not back the market structure bill “as written,” pointing to draft amendments that would eliminate stablecoin rewards and let banks restrict competition.

Related: CLARITY Act 2026 odds ‘extremely low’ if not passed before April: Exec

CLARITY delay could expose crypto to crackdowns

Last week, Coin Center executive director Peter Van Valkenburgh warned that failure to pass the CLARITY Act could leave the crypto industry vulnerable to a future US administration taking a tougher stance. He argued that rejecting developer protections in favor of short-term business interests risks creating a system shaped by political shifts rather than clear law.

“The point of passing CLARITY is not to trust this administration. It is to bind the next one,” he said.

Magazine: Bitcoin may take 7 years to upgrade to post-quantum — BIP-360 co-author

Advertisement