Step Finance, a Solana-based DeFi portfolio management platform, announced it is ceasing operations after a January 31 theft that drained roughly $40 million from its treasury and fee wallets. The company attributed the incident to the compromise of devices belonging to members of its executive team, and said subsequent efforts to recover—via fundraising, external liquidity, or acquisition talks—failed to produce a viable path forward.
The shutdown impacts Step Finance and affiliated projects including SolanaFloor (which will stop publishing new content but keep an archive) and Remora Markets (reported as isolated from the breach). Step Finance said it is pursuing a buyback/reimbursement process for STEP holders based on a pre-hack snapshot and a redemption process for Remora token holders; it reported partial recoveries including about $3.7M in stolen Remora assets and about $1M in other coins.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Alongside the shutdown announcement, Step Finance said it would pursue a buyback program for STEP coin holders and a redemption process for Remora token holders. The company said reimbursements would use a pre-theft snapshot to support affected holders.
Step Finance announced it would cease operations immediately after failing to secure financing or find an acquisition path following the January 31 theft. The company also said associated projects SolanaFloor and Remora Markets would shut down.
Following the theft, Step Finance reported recovering about $3.7 million in stolen Remora assets and roughly $1 million in other coins. The partial recovery was disclosed as part of the company’s response to the January attack.
On January 31, Step Finance said executive team members’ devices were compromised, leading to the theft of roughly $40 million from the company’s treasury and fee wallets. The incident affected the Solana-based platform’s finances and triggered its subsequent crisis response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.