Most teams still treat cryptocurrency theft as a wallet problem. Cold storage, hardware keys, maybe a fancy approval workflow on the treasury desk. That story lets cybersecurity programs keep crypto over in “finance owns it” and keep the firewall pointed at the usual suspects. This week punched a hole in that split. Cisco Talos tracked a ClickFix campaign that pulled command and control from a public Google Sheet. CrowdStrike tied a Brazil-based cluster, Slim Spider, to theft of crypto custody secrets inside financial institutions. Liquid Network watched hundreds of millions leave a federation wallet, then watched most of it come back with a lecture attached.

If your mental model of cyber security still starts at the chain and ends at the hardware wallet, you’re guarding the wrong door. The thefts that matter right now run through browsers, custody desks, and SaaS you already allow-listed.

Cybersecurity Still Stops at the Wallet Boundary

Walk a typical control review and you’ll hear the same inventory: seed phrases in steel, keys in HSMs, withdrawals behind two people. Fine as far as it goes. Slim Spider did not need you to drop a Ledger in a rideshare. CrowdStrike says the cluster has been hitting Brazilian financial institutions since at least March 2026, with working knowledge of local instant-payment rails and a taste for crypto custody secrets. That’s an attack on the people and systems that operate the vault, not on elliptic-curve math.

Illustration of financially motivated hacking activity tied to Brazilian targets
Slim Spider’s reported focus on custody secrets and instant-payment knowledge is an operations problem, not a whitepaper problem.

Custody is messy. Traders share screens. Back-office staff live in browsers. Hot wallets sit next to email. Instant-payment consoles and crypto dashboards share the same SSO as HR. You already know this pattern from SWIFT and card-processing rooms; crypto treasury inherited the same human wiring and almost none of the session discipline. Slim Spider’s reported depth in Brazilian financial infrastructure is the tell. They studied how money actually moves, then went looking for the secrets that let them move it.

Liquid Network made the same class of failure public at a louder volume. Alleged “white-hat” operators drained about $320 million from a federation wallet and demanded a bug fix. They later returned $263 million. Celebrate the refund if you want. You still had a privileged custody system emptied in production by someone who understood the wallet better than the people paid to watch it. Returned coins do not rewind logs, do not re-seal key ceremony records, and do not prove a second copy of the signing path is gone.

The real problem here is classification. If crypto lives under treasury and “the chain” lives under a vendor, your cybersecurity program never owns the browser that can spend. Incident response inherits that gap on the worst day of the quarter.

A Public Spreadsheet Now Issues Production Commands

ClickFix already trained users to paste “verification” commands into Run dialogs and terminals. Talos is now tracking a cryptocurrency-stealing turn that skips the desktop ritual and lives in the session you already authenticated. The campaign abuses the Google Visualization API as C2, pulls obfuscated JavaScript from a publicly published Google Sheet, and injects it into the victim’s browser. Your threat-protection stack sees HTTPS to Google. The wallet extension sees a normal tab. The thief sees a live, unlocked spending surface.

Threat research spotlight graphic for a browser-based cryptocurrency theft campaign
Talos’s ClickFix reporting puts command and control in a document type most allow-lists treat as homework, not hostile infrastructure.

Stop calling this clever. Call it policy. You spent years teaching the firewall that Google is home. Defense in depth was supposed to mean the next layer catches what the perimeter blesses. If that next layer is a content filter that cannot see a Sheet cell, or an EDR agent that does not inspect the browser’s DOM, you built a parade route and painted it “productivity.”

Allow-listed SaaS already has a pass on your network

Threat detection still loves a noisy brute-force against VPN or RDP. That alert fires, a ticket opens, someone feels useful. A treasury workstation quietly querying a Visualization endpoint looks like a dashboard refresh. Same user, same cookie, same approved identity provider. Security hardening that only tightens SSH and leaves the browser as a general-purpose OS is cosplay. The session is the vault once a hot wallet, exchange tab, or custody portal is open.

You do not need a new product category to see the failure. You need to admit that “trusted cloud docs” are executable content in 2026, and that crypto theft crews will keep hosting there until you treat those destinations with the same suspicion you already apply to random VPS hosts.

You Need a Custody Playbook, Not a Wallet Policy

Write controls for the desk, the browser, and the SaaS path. Do it in language operations can run this week, without waiting on a vendor roadmap.

  1. Immediate: name the humans who can spend. List every person, break-glass account, bot, and vendor with signing rights, hot-wallet access, exchange admin, or custody-portal admin. If that list lives in someone’s head, you do not have a control. Pull those identities into the same privileged-access process you use for domain admins. Disable standing access where a just-in-time grant will do.
  2. Immediate: split the browser that can move funds. Custody and treasury work happens in a dedicated, locked-down profile or workspace with no general web, no personal extensions, and no unsanctioned docs. Block or tightly proxy Google Sheets, Visualization endpoints, paste-to-console patterns, and unknown script CDNs from those identities. A user who needs Gmail on the same box as a hot wallet is a design error.
  3. Immediate: hunt like the sheet is already live. Look for Visualization API calls, published Sheet IDs fetched from unusual processes, new browser extensions, and sudden outbound Google traffic from finance subnets at odd hours. Pair that with session review on custody portals: new devices, new locations, new OAuth grants. Feed those findings into incident response as credential incidents, not “malware maybe.”
  4. Ongoing: rehearse an empty-wallet day. Your playbook should rotate keys and freeze withdrawals, and it should also invalidate IdP sessions, revoke OAuth, image the treasury workstation, and treat “we got the coins back” as an untrusted statement until you prove exclusive control of every signer. Liquid’s partial return is a useful tabletop: $320 million left, $263 million came home, and you still have to assume the federation path was understood well enough to drain it.
  5. Ongoing: instrument the allow-list. Defense in depth means logging and alerting on trusted destinations used by high-value roles, not exempting them. Baseline what a custody browser actually needs. Alert on new Sheet IDs, new Google projects, and new script sources. Keep brute-force coverage; stop letting it monopolize the SOC’s attention while quiet session theft walks out through HTTPS.
Law-enforcement style imagery associated with a large cryptocurrency theft investigation
A refund after a federation-wallet drain is a negotiation outcome. Closure is exclusive control of every remaining signer.

Vendor-neutral translation: reduce who can spend, shrink what their browser can talk to, and practice the hour after the balance hits zero. Security hardening on the chain without session control is a brochure. You already know how to do this for SWIFT rooms and card data. Crypto custody is the same job with worse memes.

Frequently Asked Questions

If we block Google Sheets, is ClickFix-style C2 dead?
You shrink this specific hosting trick; you do not retire the pattern. Crews will keep putting loaders in whatever cloud doc, form, or visualization API your users already trust. Block what treasury does not need, then watch the destinations you still allow with the same seriousness you give unknown VPS hosts.
Do hardware wallets make browser theft irrelevant?
They help when every spend requires a button on a device the malware cannot press, and when the user will not approve a surprise prompt. They do nothing for custody-portal credentials, exchange admin sessions, or hot wallets that live in extensions. Slim Spider’s reported interest in custody secrets is aimed at those operational layers.
If stolen coins come back, can we close the ticket?
No. Returned funds tell you the operator could drain you and chose a press cycle. Rotate signers, rebuild the treasury workstation, invalidate sessions, and keep threat detection on the old addresses and the old SaaS objects until you have a reason to stop.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.