The native STEP token collapsed immediately. Reports from the day of the hack record a 93.3% drop to $0.001578 . Later reports put the decline at 96% or more
. By late February, the token was trading near $0.000608 — a 99.12% collapse from pre-hack levels
.
Recovery efforts retrieved approximately $4.7 million of the stolen funds — a small fraction of the total — using Solana's Token22 freeze capabilities and coordination with partners . The team spent roughly four weeks unsuccessfully seeking bridge financing, acquisition offers, or outside capital to continue operations
.
On February 23-24, 2026, Step Finance — together with its affiliated projects SolanaFloor (analytics) and Remora Markets (derivatives) — announced the immediate cessation of all operations . The team stated they had "explored every possible path forward, including financing and acquisition opportunities" but could not secure a viable outcome
. A buyback plan for STEP token holders based on a pre-incident snapshot was announced separately
.
After five months of inactivity, the Step Finance hacker wallet suddenly became active in early July 2026. According to on-chain monitoring by Lookonchain, the following sequence occurred :
This playbook — selling on Solana, bridging to Ethereum, and depositing into a mixer — illustrates a core law enforcement difficulty in 2026: cross-chain laundering. Once funds move across chains and enter a mixer, attribution and freezing become far more difficult .
The Step Finance hack is emblematic of several painful trends that defined DeFi security in 2026:
In the first half of 2026, attackers carried out 207 separate hacks — the highest count TRM Labs has recorded in any six-month period — with total losses reaching $972 million . Other reports put the January-May losses at over $840 million, a 70% year-over-year increase over the same period in 2025
.
A striking 72% of losses in 2026 came from stolen private keys and credential theft — not smart contract bugs . The Step Finance attack (compromised laptops, not buggy code) is the textbook example. This makes security harder because it shifts the attack surface from auditable code to endpoint security
.
Total value locked across DeFi protocols dropped by 39% in 2026, from roughly $115 billion in January to about $70 billion by June, erasing approximately $45 billion in locked capital . The decline was attributed to a broad market downturn compounded by the record wave of exploits
.
The Step Finance case and the broader 2026 data make clear that DeFi's worst vulnerability is no longer in the smart contracts — it is in the operational security of the teams who hold the keys. For every protocol builder and DeFi user, the lesson is stark: endpoint security and private key management are now the front lines of defense .