B2B Cross-border Payments · Crypto Custody · Singapore
A live custody security simulation run against the people, not just the systems. Five attack scenarios combining phishing campaigns and crypto dusting, aimed at the operations and custody teams under real-world conditions.
Custody changes an organization's threat model in a specific way. A payments business moves value between parties who each hold their own funds. A custody business holds the funds itself, which turns the operations team into the shortest path to something worth stealing.
Attackers respond to that by going around the software. Application security can be excellent and entirely beside the point if an operations analyst can be convinced to authenticate somewhere they should not. Phishing remains the dominant route to initial access precisely because it does not require a vulnerability to exist.
Testing that reality requires running the attack rather than describing it. This engagement put five scenarios against the live operations and custody teams, combining credential harvesting campaigns with on-chain reconnaissance, under conditions the teams were not rehearsing for.
Phishing and dusting campaigns run against live teams.
Stopped by security controls the team already had in place.
No credentials harvested, no wallet addresses traced.
All five simulated attack scenarios were blocked by existing security controls. The engagement produced evidence of resilience rather than a remediation backlog.
Five attack scenarios were designed and executed across the operations and custody functions. The scenarios combined two distinct techniques: phishing campaigns aimed at harvesting credentials from named personnel, and crypto dusting aimed at de-anonymizing wallet addresses and tracing transaction origins.
The scenarios were built to mirror the way a capable threat actor approaches a custody target, which means reconnaissance first and a pretext tailored to the role being targeted, rather than a generic campaign sent to everybody at once.
The measure of a simulation like this is not a click rate. It is whether existing controls, technical and human, actually stopped the scenario from reaching its objective. That is the result being reported here.
Five scenarios modelled on how advanced threat actors actually approach a custody operation.
Campaigns designed to harvest credentials from the custody operations team.
Phishing against an operations team is not a mass campaign. It is a small number of carefully built pretexts aimed at people whose day job is approving things, where a request to authenticate or confirm an action is entirely ordinary and therefore hard to distinguish from an attack.
Attempts to de-anonymize wallet addresses and trace transaction origins.
Dusting means sending a trivially small amount of cryptocurrency to a large number of addresses, then watching the blockchain to see which of those amounts later get combined with other funds. Those movements link addresses to one another, and enough links can connect a set of wallets to a single operator. It costs the attacker almost nothing and produces a map of who holds what.
Simulated spear-phishing aimed at key personnel with elevated access.
Spear phishing narrows the campaign to specific individuals whose access is worth the preparation. The message is written for one person's role, workflow, and current context, which removes most of the signals people are trained to look for.
Scenarios testing day-to-day information security hygiene across the team.
Internal communications are where the useful details sit: who approves what, which vendors are trusted, what is currently in progress. An attacker who can read that traffic gets the raw material for a pretext that will not look unusual to the person receiving it.
Wallet-level techniques simulated under real-world advanced threat actor conditions.
Wallet-level techniques test whether the mechanics of custody hold up under pressure from a capable adversary rather than under normal operating conditions, which is the only condition most controls are ever exercised in.
Five scenarios reached live personnel and were stopped. That is a materially different claim from a policy document asserting that they would be.
A simulation produces something a policy cannot: a record of what happened when the attack was actually attempted, which is the form of assurance regulators and counterparties respond to.
Teams change, pretexts evolve, and the tooling attackers use improves. A result like this is evidence that controls worked on the day they were tested.
Dusting sits upstream of the theft. Treating wallet-level privacy as an operational security problem rather than a blockchain curiosity is what makes the combined scenario realistic.
Payment companies launching custody or high-value financial products.
Regulated fintech needing to demonstrate security posture to regulators.
Organizations wanting to validate employee resilience against live attack conditions.
50 findings across authentication, cross-account access, and API authorization on a multi-tenant procurement platform.
Read the case study Fintech & Payments42 findings across a full AWS environment, from publicly readable buckets to a root account running without MFA.
Read the case studyBook a 30-minute walkthrough. We'll point CredShields at a scoped asset and show you live findings by the end of the call.
Get your comprehensive security audit from the team trusted by 200+ protocols and enterprises worldwide. Fast turnaround. Proven track record. Direct access to senior security engineers.