Security at the Human Layer

One attacker. Three outcomes. Loss size did not decide who survived

An operational frame for CSOs, CISOs, and Heads of Security at regulated crypto, fintech, and iGaming operators.

9 min read · September 2026
Toeshee — Bybit, WazirX and DMM Bitcoin held side by side: one attacker, three outcomes, and the person at the workstation
$1.5B
Absorbed by Bybit in under twelve hours without market contagion (February 2025)
60%
Of breaches involve the human element across 12,195 confirmed cases (Verizon DBIR, 2025)
$180–400M
Coinbase's estimated remediation after contractors in support roles were paid for their access

The largest single-event crypto theft on record, roughly $1.5 billion, was absorbed in under a day without market contagion. Losses a fraction of that size ended their companies. What separated survival from collapse was not the loss, and not the system-layer controls. It was operational discipline at the layer most architectures never audit: the human operating a workstation with legitimate access — rehearsed before the incident, not improvised after it.

The control stack you audit is not the one these incidents defeated

Role-based access control, mandatory MFA, encryption in transit and at rest, endpoint detection and response, a clean SOC 2 report — all of it can be operating exactly as designed while a contractor photographs the screen with a personal phone, or a vendor session cookie is replayed to impersonate a legitimate employee. Verizon's 2025 Data Breach Investigations Report puts the human element in 60% of breaches across 12,195 confirmed cases. The crypto record narrows that to one specific place: the boundary where a person, a customer's data, and a device intersect.

That boundary is where these incidents were won or lost. Nothing on the console points to it.

One North Korea-linked threat ecosystem, held side by side

$1.5B — contained. Bybit, 21 February 2025

Traced to a Safe{Wallet} developer machine, not Bybit's own infrastructure. Solvent within hours, withdrawals resumed in under twelve, forensics published within days, 1:1 client asset backing verified.

$235M — collapsed. WazirX, 18 July 2024

Nearly half its reserves drained through a multisig breach altering contract logic between what signers saw and what they signed. Indefinite freeze, High Court restructuring, recovery through socialized loss.

$308M — collapsed. DMM Bitcoin, May 2024

4,502.9 BTC taken after a vendor employee at Ginco was socially engineered, then a session cookie replayed to impersonate them. Attributed to TraderTraitor. Wound down by early 2025.

One threat ecosystem, three outcomes. The technical compromise was only the trigger. What differed was the operational architecture around it — the part a competitor or a regulator cannot see from the outside.

The blind spot: the human at the workstation

Coinbase's Form 8-K, filed with the SEC on 14 May 2025, documents that the actor obtained data by paying contractors and employees in support roles outside the United States who already held legitimate access. The breach reached 69,461 customers, with remediation estimated at $180 million to $400 million. Reuters reported an outsourcing-firm employee photographing her work screen with a personal phone, reportedly selling records at around $200 an image. More than 200 people were terminated in the aftermath.

The exfiltration was invisible to the system layer. The access was legitimate; the capture happened on a personal device the network never sees. The parallel blind spot is the help desk: the FBI and CISA advisory of 29 July 2025 and Mandiant's research on Scattered Spider document a group whose primary initial-access technique is a phone call arriving with last-four SSN, date of birth, manager names, and co-worker titles already in hand to defeat identity verification.

Four patterns separated the operations that held

The four work as one system, not a checklist: the workstation defended, the verification hardened, the continuity capitalized, the disclosure rehearsed.

1. Defend the workstation, not just the system

The operations that held extended control to the agent desktop and the third-party session: the personal device in proximity, the vendor cookie, the observer behind the screen. RBAC and EDR operating as designed is not the same as the desktop being in scope.

2. Verify as if the credential is already stolen

Where the help desk held, the workflow assumed the caller's PII was already in the adversary's hands and did not rely on knowledge-based checks alone. Where it failed, the verification step was exactly the knowledge the attacker had pre-collected.

3. Capitalize continuity before the incident

What let Bybit absorb $1.5 billion was verified 1:1 backing and financing available within hours — capacity in place before 21 February, not assembled in response to it. The loss was survivable; the absence of pre-existing capacity was not.

4. Rehearse disclosure and forensic transparency

The contained events published forensics within days and named the third-party surface openly; the terminal ones went dark. Speed and transparency under a live incident are the visible output of a response architecture rehearsed in advance.

Why the security stack does not close it

None of this argues against the stack. RBAC, MFA, EDR, segmentation, and a SOC 2 attestation confirm a control framework exists. What they do not do is reach the layer these incidents used. A SOC 2 report attests the control environment; it does not put a control between a personal phone and the screen it is photographing.

And the regulatory boundary is moving toward exactly that layer: the EU's Digital Operational Resilience Act, in force since January 2025 with the first critical third-party providers designated in November 2025, and NYDFS's 2025 guidance on sub-custodian and third-party operational controls both extend supervision through the outsourced operations a regulated entity depends on. The audit that today stops at the system architecture will not stop there for long.

The control that answers the workstation gap operates at the agent desktop, not the network: presence and observer detection confirming the representative is alone and flagging others behind the screen, unauthorized device detection for phones or smart glasses present at the workstation, and geographic restriction limiting sessions to approved locations only.

Where you stand: a thirty-minute benchmark

Five questions for the support and help desk layer serving your operation — internal or partner-operated. An answer you cannot evidence is a gap the survivors had closed before their incident arrived.

  1. Is the agent workstation in scope for your security monitoring — personal device presence, observer detection, location — or does control stop at the system layer?
  2. Does your help desk verification assume the caller's PII is already compromised, or does it still rely on knowledge-based checks an adversary can pre-collect?
  3. Are third-party and contractor sessions monitored to the same standard as employee sessions, including the vendor's own attack surface?
  4. Is continuity capacity — solvency, financing, 1:1 backing — verified and available before an incident, or assembled in response to one?
  5. Is your incident disclosure and forensic transparency process rehearsed, with named owners, or improvised when the event is live?

Count the ones you can evidence today. Three or fewer, and you are behind the operations that contained their incidents.

Common questions

What actually determined survival across the 2024–2026 crypto incidents?

Not the magnitude of the loss, and not the system-layer controls. The largest single-event theft on record was absorbed without contagion while far smaller losses were terminal. The determinant was operational discipline at the human layer, in place before the incident rather than improvised after.

Does a strong security stack plus SOC 2 already cover this?

They cover the system layer and confirm a control framework exists, which is necessary. They do not reach the boundary these incidents used: a personal phone photographing a screen, a help desk call with pre-collected PII, a replayed vendor session. Those vectors are operationally invisible to the console.

Where does a specialized operation fit for a team already consolidating tools?

Not as another tool. The gap the record exposes is closed by an operational layer that owns the workstation, the verification step, and the third-party session as one accountable surface.

Toeshee is the specialized customer-support partner for iGaming, fintech, and digital-asset platforms, operating the support layer with risk management and compliance as the design principle of every workflow — SOC 2-compliant operations, risk-tiered escalation discipline, and Multi-Dimensional Security at every agent desktop: Rep (presence and observer detection), Items (unauthorized device detection), and Geo-Fenced (geographic restriction).

We've got your back. Crypto-native.

Close the gap the record exposes

The workstation, the verification step, and the third-party session as one accountable surface — rehearsed before the incident, not improvised during it. We operate that layer for regulated crypto, fintech, and iGaming platforms.

Request Information