Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

Brazilian financial institution, Banco Santander, has fallen victim to a sophisticated cyber attack that compromised its crypto custody secrets. The attackers, believed to be part of an organized group known as “Slim Spider”, used a complex technique called cross-domain privilege escalation to breach the bank’s security systems.

This heist is particularly notable because it targeted one of the most critical areas in modern finance: digital asset management. Crypto custody refers to the secure storage and handling of cryptocurrencies, which are becoming increasingly popular among investors. The hackers’ goal was likely to steal sensitive information about Banco Santander’s crypto holdings and exploit these assets for their own gain.

To understand how Slim Spider pulled off this daring heist, let’s dive into some technical basics. Cross-domain privilege escalation is a type of attack that takes advantage of the way different systems and applications interact with each other on a network. Normally, when an organization uses multiple systems to manage its operations, these systems operate within their own “domains”, which are essentially isolated areas of the network. However, if attackers can find vulnerabilities in one system and use them to infiltrate another domain, they can gain far greater access to sensitive data.

Banco Santander’s breach was likely facilitated by a combination of social engineering tactics and technical exploits. The bank’s systems were compromised through phishing emails or other forms of initial compromise, which allowed the attackers to establish a foothold on the network. From there, they used cross-domain privilege escalation techniques to navigate between different systems and domains, eventually reaching the crypto custody management system.

The implications of this breach are significant. Crypto custody is one of the most sensitive areas in modern finance, as it involves handling large sums of value that are often decentralized and difficult to track. If Slim Spider or other attackers can gain access to this information, they may be able to manipulate markets, launder money, or even steal valuable assets outright.

For readers who manage crypto holdings or operate within the financial sector, this breach serves as a sobering reminder of the importance of robust security measures. In particular, organizations should prioritize implementing strict access controls and monitoring systems that can detect unusual activity across different domains and applications. By recognizing the potential for cross-domain privilege escalation attacks and taking proactive steps to prevent them, businesses can minimize their vulnerability to these types of breaches.


Source: The Hacker News — 2026-09-08