
The irony is so thick, I don't know where to begin. Right after I published a column on Monday decrying the sorry state of crypto security, The Block reported that Ripple's latest acquisition came with an unusual twist—namely that the firm in question had been hacked. The name of the firm? Fortress. Seriously, the satire just writes itself some days.
The details are still trickling out, but it looks as though hackers robbed Fortress, a firm that promises to securely handle your crypto operations, by compromising one of its third-party vendors. This is a popular tactic with cybercriminals—instead of hacking a target directly, they target one of its business partners with weaker security and then use the partner's access to burrow into the target's operations. While this means Fortress can try and blame a third party for the incident, any firm that's serious about security knows to guard against this type of vulnernability—especially when its names is Fortress and its business includes custody, or protecting assets on behalf of its customers.