FINTECH & PAYMENTS
Client confidential

Cross-Border Payments Platform

B2B Cross-border Payments · Crypto Custody · Singapore

A live custody security simulation run against the people, not just the systems. Five attack scenarios combining phishing campaigns and crypto dusting, aimed at the operations and custody teams under real-world conditions.

Engagement type
Custody Security Simulation. Phishing attack and crypto dusting attack.
Scope
Five attack scenarios covering phishing campaigns and dusting attacks across the operations and custody teams.
/ context

When you hold the assets, the attack moves to the people.

Custody changes an organization's threat model in a specific way. A payments business moves value between parties who each hold their own funds. A custody business holds the funds itself, which turns the operations team into the shortest path to something worth stealing.

Attackers respond to that by going around the software. Application security can be excellent and entirely beside the point if an operations analyst can be convinced to authenticate somewhere they should not. Phishing remains the dominant route to initial access precisely because it does not require a vulnerability to exist.

Testing that reality requires running the attack rather than describing it. This engagement put five scenarios against the live operations and custody teams, combining credential harvesting campaigns with on-chain reconnaissance, under conditions the teams were not rehearsing for.

/ findings overview

Five scenarios. Zero got through.

5
Attack scenarios

Phishing and dusting campaigns run against live teams.

5 / 5
Blocked

Stopped by security controls the team already had in place.

0
Successful compromises

No credentials harvested, no wallet addresses traced.

Result

All five simulated attack scenarios were blocked by existing security controls. The engagement produced evidence of resilience rather than a remediation backlog.

/ approach

How the simulation ran

Five attack scenarios were designed and executed across the operations and custody functions. The scenarios combined two distinct techniques: phishing campaigns aimed at harvesting credentials from named personnel, and crypto dusting aimed at de-anonymizing wallet addresses and tracing transaction origins.

The scenarios were built to mirror the way a capable threat actor approaches a custody target, which means reconnaissance first and a pretext tailored to the role being targeted, rather than a generic campaign sent to everybody at once.

The measure of a simulation like this is not a click rate. It is whether existing controls, technical and human, actually stopped the scenario from reaching its objective. That is the result being reported here.

/ what we found

Key risk areas tested

Five scenarios modelled on how advanced threat actors actually approach a custody operation.

01

Social engineering and phishing

Campaigns designed to harvest credentials from the custody operations team.

Phishing against an operations team is not a mass campaign. It is a small number of carefully built pretexts aimed at people whose day job is approving things, where a request to authenticate or confirm an action is entirely ordinary and therefore hard to distinguish from an attack.

02

Crypto dusting

Attempts to de-anonymize wallet addresses and trace transaction origins.

Dusting means sending a trivially small amount of cryptocurrency to a large number of addresses, then watching the blockchain to see which of those amounts later get combined with other funds. Those movements link addresses to one another, and enough links can connect a set of wallets to a single operator. It costs the attacker almost nothing and produces a map of who holds what.

03

Targeted credential harvesting

Simulated spear-phishing aimed at key personnel with elevated access.

Spear phishing narrows the campaign to specific individuals whose access is worth the preparation. The message is written for one person's role, workflow, and current context, which removes most of the signals people are trained to look for.

04

Internal communication interception

Scenarios testing day-to-day information security hygiene across the team.

Internal communications are where the useful details sit: who approves what, which vendors are trusted, what is currently in progress. An attacker who can read that traffic gets the raw material for a pretext that will not look unusual to the person receiving it.

05

Crypto wallet attack vectors

Wallet-level techniques simulated under real-world advanced threat actor conditions.

Wallet-level techniques test whether the mechanics of custody hold up under pressure from a capable adversary rather than under normal operating conditions, which is the only condition most controls are ever exercised in.

/ takeaways

What a clean result does and does not prove

01

Controls were tested under load, not on paper

Five scenarios reached live personnel and were stopped. That is a materially different claim from a policy document asserting that they would be.

02

Evidence beats assertion in a regulated conversation

A simulation produces something a policy cannot: a record of what happened when the attack was actually attempted, which is the form of assurance regulators and counterparties respond to.

03

A clean result is a point in time, not a permanent state

Teams change, pretexts evolve, and the tooling attackers use improves. A result like this is evidence that controls worked on the day they were tested.

04

On-chain reconnaissance is part of the attack, not a separate concern

Dusting sits upstream of the theft. Treating wallet-level privacy as an operational security problem rather than a blockchain curiosity is what makes the combined scenario realistic.

/ relevant for

If this looks like your environment, it probably behaves like it too.

Payment companies launching custody or high-value financial products.

Regulated fintech needing to demonstrate security posture to regulators.

Organizations wanting to validate employee resilience against live attack conditions.

/ common questions

Questions this engagement usually raises.

What is a crypto dusting attack?
An attacker sends negligible amounts of cryptocurrency to many wallet addresses, then monitors the blockchain for when those amounts are spent alongside other funds. Combining them in a transaction links the addresses together, gradually revealing which wallets belong to the same operator. The goal is de-anonymization and mapping, not theft.
What is a custody security simulation?
A controlled exercise in which realistic attack scenarios are executed against the people and processes protecting custodied assets, rather than against the application alone. It measures whether existing controls stop a real attempt.
How is this different from phishing awareness training?
Awareness training teaches people to recognize an attack. A simulation runs the attack against them without warning and records what the whole system did in response, including detection, escalation, and technical controls, not just individual behaviour.
What does it mean that all five scenarios were blocked?
That existing security controls stopped each scenario from achieving its objective. No credentials were harvested and no wallet addresses were successfully traced back through the dusting activity.
Why target the operations team specifically?
Because in a custody business the operations and custody functions hold the access that matters. Attackers target the people closest to the assets, which is why a simulation that avoids them is not testing the real threat.
How often should simulations like this be repeated?
Two different clocks apply. Lightweight phishing simulations across the general workforce commonly run monthly or quarterly, because the goal is maintaining recognition and the exercise is inexpensive to run. Full scenario-based simulations of the kind described here, targeting specific teams with tailored pretexts and measuring the response of the whole control stack, typically run once or twice a year. Regulated threat-led testing frameworks such as TIBER-EU and DORA in the EU, or CBEST in the UK, work on multi-year cycles by design. Beyond cadence, specific events justify a fresh exercise regardless of timing: launching a custody or high-value product, meaningful turnover among staff holding privileged access, or a visible shift in the tactics being used against comparable firms.
/ more engagements

Other work.

Start here

Think like them.
Before they do

Book a 30-minute walkthrough. We'll point CredShields at a scoped asset and show you live findings by the end of the call.

Secure your protocol today

Don't wait for a
security incident.

Get your comprehensive security audit from the team trusted by 200+ protocols and enterprises worldwide. Fast turnaround. Proven track record. Direct access to senior security engineers.

Fixed-Fee Pricing
No engineer-hour billing
Audit-Ready by Default
SOC 2, ISO, PCI, HIPAA
Engineer-Validated
Not scanner output