1 article with this tag
The entry point was reported to be spear-phishing / malware aimed at employees, which stole the private key of an internet-connected hot wallet; ~523 million XEM (~$530M at the time) was then moved out in one sweep. The core failure was keeping a huge, instantly-spendable balance 'hot' and with no multisig — a single stolen key moved almost everything. Defend by keeping important keys cold / in a dedicated vault, minimizing the hot balance, removing single points of failure (multi-approval), and detecting and stopping abnormal bulk operations.