Home / Crypto / Learn / 10 Cyber Attacks that Subverted 2FA – Is Your Crypto at Risk?
Learn 10 min read

10 Cyber Attacks that Subverted 2FA – Is Your Crypto at Risk?

endpoint cybersecurity

Key Takeaways

  • Attackers increasingly target 2FA workflows using phishing, SIM swaps, and API abuse to bypass security, affecting both users and employees.
  • High-profile crypto breaches show that human errors under pressure often undermine technical controls, emphasizing the need for staff vigilance.
  • Cloud backups and synced authenticator codes can inadvertently expose 2FA credentials, highlighting risks introduced by convenience-focused security features.
  • Firms must combine hardware keys, withdrawal delays, partner audits, and user education to strengthen resilience against evolving 2FA attacks.

Often called 2FA, two-factor authentication introduces an extra check when logging in to your online accounts, beyond simply entering a password. It’s a common security measure on crypto wallets and trading sites, where digital assets can change hands quickly and hold significant value. Providers of wallets, trading services, and accounts rely on 2FA as a crucial layer of protection.

The 2026 MetaMask-related phishing activity shows how attackers are using social engineering to increasingly target authentication flows rather than passwords alone. These campaigns reveal that attackers view 2FA as an interactive surface open to abuse. The sections below examine real incidents, explain how attackers subverted 2FA, and explore what these events reveal for crypto users.

10 Phishing Attacks that Subverted 2FA

Real incidents show consistent patterns across wallets, exchanges, and service providers. Each case below demonstrates how attackers manipulated people, systems, or recovery flows to pass through 2FA protections.

1. Crypto.com Account Withdrawal Exploit – 2022

In 2022, hackers targeted Crypto.com, a major exchange that holds user funds in Bitcoin and Ethereum. The centralized platform drew interest because customers secure vast crypto balances on company-controlled wallets, with the security data all logged in the Crypto.com database. Attackers found a flaw in the 2FA system that let them start withdrawals without user codes. They bypassed the check for 483 accounts through this logic error.

Attackers moved fast once inside the system, with the exploit stealing about $34 million in crypto assets before teams noticed. No group claimed responsibility, but the method showed deep knowledge of exchange setups. Crypto firms now audit 2FA paths more often. This incident pushed for stronger internal controls across platforms.

Crypto.com fixed the issue and returned funds to users quickly, however the reputational damage remains. The breach highlighted risks in 2FA setups for exchanges, with users becoming more wary of weaknesses in trusted platforms. Attackers adapt, so defenses evolve too.

2. Coinbase Employee MFA Fatigue Campaign – 2023

The 0ktapus campaign hit Coinbase employees who manage customer data. Attackers chose the exchange for its role in secure trades and storage. They started with SMS phishing to grab login details. Then they sent waves of 2FA push notifications until staff approved one. A fake IT call sealed access to systems. No customer crypto left, but the cyber attack exposed internal risks.

Phishing attacks like this rely on human responses under pressure. Employees see many alerts daily, so one slips through. Attackers timed pushes for busy hours. Coinbase trained staff on fatigue tactics after the event.

This incident showed how phishing can evolve with 2FA types. Push approvals work like SMS codes in scams. Users learn from employee stories. Platforms add approval delays now. Attackers from the 0ktapus group targeted tech leaders broadly.

3. IRA Financial Trust Gemini Master Key Theft – 2022

IRA Financial Trust managed retirement accounts connected to the Gemini exchange. These accounts aggregated large balances under institutional custody.

Attackers obtained an internal master API key that bypassed individual customer 2FA controls. The phishing component targeted internal access rather than end users.

Roughly $37,000,000 million in crypto assets left customer accounts. Attribution remained unclear, though legal filings described possible structural access risks.

4. Retool Okta Authenticator Sync Phishing – 2023

Hackers targeted Fortress Trust, a company that helps people store and manage cryptocurrency. The attackers focused on Retool, which the company uses to manage digital wallets. To gain access, the criminals sent fake text messages to employees to steal their login usernames and passwords.

The attack was successful because of how 2FA works. Many employees had their Google Authenticator security codes synced to their Google accounts for backup. When the hackers gained access to the employees’ accounts, they were also able to see these secret codes. This allowed the attackers to bypass security and enter the company’s private internal network. The hacker also used a deepfake of an IT employee’s voice during a phone call to trick a Retool employee into providing an additional MFA code.

Once the company discovered the hack, Fortress Trust had to stop its services immediately to fix the problem. While the company reported that no money was stolen, the event caused customers to lose trust. This situation shows that features designed for convenience, like cloud backups, can sometimes make it easier for hackers to steal information.

5. SEC X Account SIM Swap Incident – 2024

In early 2024, hackers took over the official X account of the US Securities and Exchange Commission (SEC) to manipulate the cryptocurrency market. They used a technique called SIM swapping to gain access to the phone number linked to the SEC’s account.

The SEC confirmed that MFA was disabled on their @SECgov account at the time of the attack. They had previously asked X Support to disable it due to technical issues and never turned it back on. Because the account only used basic SMS-based security, the attackers easily reset the password and posted a fake announcement claiming that Bitcoin ETFs had been approved.

The false reporting caused Bitcoin prices to increase, followed by a massive crash when the truth came out. Many traders lost significant money during this chaos. The incident highlighted a major security flaw: text message verification is not safe enough for high-stakes accounts.

6. Vitalik Buterin X Account Takeover – 2023

Vitalik Buterin maintained a high-profile social account linked to the Ethereum ecosystem. Attackers valued the trust placed in messages from the account, targeting his account via a SIM swap. This allowed them to bypass his security and log into his social media account.

Once inside, the hackers posted fake links for free digital art called NFTs. Because they trusted Buterin, many followers clicked the links and connected their digital wallets. Unfortunately, the hackers stole more than $690,000 from these users in a very short time.

After the attack, the crypto community began working together to identify and flag similar scams. Experts warn that even famous leaders are at risk of phone hacking. Always be extra careful and always double-check links before sharing any personal financial information online.

7. Friend.tech SMS Login Abuse – 2023

Many people on Friend.tech lost money when hackers stole their social tokens. The attackers used “SIM swapping” to take over phone numbers and intercept login codes sent by text. This allowed them to empty wallets without needing any passwords.

The platform’s simple login system made it easy for these phishing attacks to spread quickly. Because Friend.tech was designed for speed, security was bypassed. After many accounts were drained, the company finally added more safety features to protect users.

Traders are now more careful about phone security and avoid using SMS for logins. Most now use hardware keys or specialized apps for two-factor authentication (2FA). This shift helps prevent hackers from using mobile carriers to access private accounts.

8. Binance API Key Phishing Incident – 2019

Binance is one of the world’s biggest platforms for buying and selling cryptocurrency. It offers special tools that let users automate their trading and move money easily using computer programs.

However, hackers created fake websites to steal login details and security codes from users. They also used harmful software to take control of active accounts and bypass security measures.

During this attack, 7,000 Bitcoin were stolen from the company’s digital storage. Binance quickly identified the hackers and used its own funds to pay back every user who lost money.

9. Liquid Global Employee Compromise – 2021

In 2021, hackers attacked Liquid Global, a cryptocurrency exchange. They started by breaking into an employee’s email. Using social engineering, the attackers tricked staff into sharing their security codes. This allowed the hackers to reach the company’s internal network.

Once inside, the criminals accessed “hot wallets,” which are digital accounts connected to the internet. They quickly stole over $90 million. To stop the theft, Liquid Global had to freeze all trading activity immediately.

Today, firms use this lesson to improve security. They now train staff to spot scams and divide their networks to block intruders. For users, choosing a platform with strong protection is essential.

10. Twilio Supply Chain Phishing – 2022

Twilio, a text messaging service for crypto firms, was tricked by hackers (0ktapus group or Scatter Swine) using fake login pages. Attackers used phishing pages to collect employee credentials and 2FA codes. Employees accidentally shared their security codes, allowing the attackers to enter the system. Once inside, the criminals redirected private messages to themselves to steal user data.

This “supply chain” attack affected many companies at once. Twilio quickly warned its clients and fixed the problem. Now, firms use multiple service providers instead of just one to stay safe.

Companies audit their partners more strictly. This event taught everyone that even the tech backbone can be vulnerable to clever phishing scams. Investigators attributed the campaign to the 0ktapus group.

Our Methodology for the List

This list includes incidents that publicly demonstrated active 2FA subversion.

  • Selection criteria prioritize verified incident reports from the affected organizations, legal filings, and forensic analyses by reputable blockchain security firms.
  • The list encompasses various 2FA subversion techniques, including SIM swapping, real-time phishing, MFA fatigue, and technical logic exploits to show systemic breadth.
  • Incidents are chosen based on their significant financial loss, the high profile of the target, or the lasting influence the breach had on industry security standards.

Common 2FA Subversion Techniques

Many attacks share repeatable methods despite targeting different platforms.

Technique How It Works Example Use Case Why 2FA Fails
Real Time Phishing Fake sites relay login data instantly Binance phishing kits Codes remain valid during relay
SIM Swapping Carrier support transfers phone number Vitalik Buterin X takeover SMS codes route to the attacker
MFA Fatigue Push spam leads to approval Coinbase employee attack Human response overrides caution
API Key Abuse Master keys bypass user controls IRA Financial breach Centralized access skips 2FA
Authenticator Sync Abuse Cloud-synced codes copied Retool incident Device possession loses exclusivity

Why 2FA Phishing Attacks Matter for Crypto

Crypto wallets and exchanges rely on 2FA to slow down unauthorized access. These systems protect private keys, trading accounts, and custody services holding billions of dollars. Successful 2FA phishing attacks weaken confidence in account-level protection.

Each bypass demonstrates how human interaction intersects with technical controls. Large asset pools increase attacker motivation while fast transaction settlement limits recovery options. The combined effect influences platform trust and user behavior across the industry.

Closing Thoughts

Phishing attacks targeting 2FA continue to adapt alongside authentication technology. These incidents show that 2FA still provides protection when combined with awareness and layered controls. Hardware keys, withdrawal delays, and verified communication channels add resilience.

User education plays an essential role because many attacks rely on interaction rather than cryptography. Understanding past incidents helps users recognize patterns and make informed security choices within crypto platforms.

Was this Article helpful? Yes No
Thank you for your feedback. 0% 0%