Investigators traced a $95 million cryptocurrency exchange theft to a single employee laptop compromised months earlier through a fake job-recruitment lure.

The attackers, exhibiting patience characteristic of state-sponsored operations, quietly escalated privileges over weeks, mapping internal systems until they reached hot wallet signing infrastructure.

The theft was executed in minutes, with funds fragmented across mixers and cross-chain bridges. Blockchain analysts have frozen a portion at cooperative exchanges, but most remains in motion.

The exchange has covered customer balances from reserves and rebuilt its signing architecture with hardware isolation and multi-party approval. The recruitment-lure vector has now been documented in over a dozen exchange intrusions.