
Voice-phishing attacks hit Point72, Citadel, Two Sigma and Millennium. Crypto markets held steady at $2.3T cap. Bitcoin flat near $64,500. No breach data confirmed. The SEC's 4-day cyber disclosure rule applies. Watch for spillover into crypto infrastructure and prime broker disruption.
A wave of voice-phishing attacks hit several of Wall Street's largest hedge funds this week, including Point72 Asset Management, Citadel, Two Sigma Investments and Millennium Management. Attackers used vishing – voice-based social engineering – to trick employees into handing over login credentials, according to reports.
Despite the headlines, crypto markets barely moved. Bitcoin (BTC) traded around $64,500, up roughly 1% over the past week. Ether (ETH) sat near $1,900, down 0.5%. Total crypto market capitalization held at about $2.3 trillion.
The CBOE Volatility Index – Wall Street's fear gauge – ticked up 2.7% in the past 24 hours to roughly 15.8. That level remains below where it stood five sessions ago, suggesting investors have not priced in systemic disruption.
The muted reaction matters because several of the targeted firms have expanded into digital assets. Some run dedicated crypto trading desks. Citadel Securities provides liquidity across both traditional and crypto markets. A breach at a prime brokerage that serves equities, derivatives and crypto could disrupt trading without directly hitting any exchange, traders said.
Point72 told Reuters that no client data was compromised. Citadel said it had not suffered a successful breach. There has been no indication that crypto exchanges, custodians or blockchain infrastructure providers were affected.
Crypto investors are watching anyway. Cybercriminals routinely exploit real-time payment rails and crypto rails to move stolen funds, making recovery near-impossible, according to the FS-ISAC's "Navigating Cyber 2025" report. The report warned that generative AI is making attacks cheaper and more convincing, with deepfake impersonations of executives now common.
"Reliance on interconnected technology providers and external suppliers has increased," said FS-ISAC CEO Steven Silberstein.
Large multi-strategy funds generate enormous trade volumes across stocks, bonds, derivatives and crypto. Even a contained incident that compromises employee accounts could slow execution across markets, even if no exchange itself is hit.
Since 2023, the SEC has required public companies to report material cybersecurity incidents within four business days. The rule covers disclosure but does not prevent the underlying disruption.
A Swiss Finance Institute study found that portfolios tilted toward companies with high cyber risk delivered excess annual returns of 18.72%, a sign that investors already price in those risks. For crypto firms, the situation is harder: cyber insurance options are thin. Zurich Insurance Group CEO Mario Greco has called sophisticated cyber breaches "uninsurable" and urged government-backed backstops.
The question now is whether the attack wave stays inside traditional finance or crosses into crypto infrastructure. Investigations are ongoing at multiple firms, the Financial Times reported, but no trading infrastructure or assets have been hit so far.
Mastercard Tests Single-Audit Stablecoin Compliance With Borderless.xyz
Tokenized QQQ drove 288% of July volume; Robinhood Chain bets on it
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.