Hackers breached a crypto firm through unpatched security gaps in widely-used VPN equipment, stealing $23.7M in digital assets.
A significant cryptocurrency platform called Ostium became the target of a sophisticated theft that resulted in the loss of $23.7 million in digital currency. The attackers didn't break into the company's main defenses head-on. Instead, they found a hidden weakness in the company's network infrastructure—specifically in equipment made by SonicWall that connects remote workers to company systems.
Security researchers discovered that hackers had been quietly exploiting previously unknown flaws in SonicWall's SMA1000 appliance for several weeks. Think of these devices like digital security gates that companies use to let employees work from home safely. The attackers found a way to slip past these gates undetected, install malicious software, and gain deep access to the network. Once inside, they were able to steal the cryptocurrency holdings.
The two security gaps that were exploited hadn't been publicly known before. This made them particularly dangerous because companies couldn't protect against threats they didn't know existed. It's similar to discovering that a lock on your front door has a design flaw that thieves have known about—but you haven't, so you kept using it anyway.
The malware that attackers installed allowed them to maintain ongoing access to Ostium's systems. Rather than a quick smash-and-grab theft, this appears to have been a methodical operation where criminals had time to explore, plan, and execute their theft carefully.
This incident highlights a critical gap in modern cybersecurity: the time between when a vulnerability exists and when companies can patch it. During this window, attackers can operate freely. Large companies and platforms that handle valuable assets are prime targets because the payoff justifies the effort.
For the broader cryptocurrency industry, this demonstrates that digital asset theft isn't always about cracking complex encryption. Often, the easiest path involves finding conventional network weaknesses—the same tools and systems that protect thousands of businesses worldwide.
If you use cryptocurrency platforms: Enable all available security features, including two-factor authentication and withdrawal restrictions. Consider whether you really need to keep large amounts on exchange platforms.
If you manage company IT: Audit which vendors provide your network access tools. Prioritize security patches for remote access equipment as critical, not optional. Check whether your systems are vulnerable.
For everyone: This reinforces that security isn't just about passwords. Companies need multiple layers of protection, and delays in fixing known problems create unnecessary risk.
The Ostium theft serves as a reminder that even in a digital-first world, some of the most damaging attacks still come through conventional network infrastructure.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →