Fortress Trust Hack
What happened
The August 2023 Fortress Trust incident involved its third-party portal provider, Retool. Contemporary reporting put the theft at $12 million to $15 million. A Ripple spokesperson said customers were made whole within a week, with Ripple covering the remaining shortfall.
That reimbursement does not establish recovery from the attacker.
Phished credentials and synchronized authentication codes undermined the independence of Retool's authentication checks. Fortress's vendor permissions then determined what actions could reach its wallet infrastructure.
How it happened
- Retool reported that an August 27 phishing attack captured an employee's login and an additional MFA code.
- The attacker enrolled a device in Okta, obtained a Google session and accessed synchronized authenticator codes.
- Access to internal admin tools enabled account takeovers affecting 27 Retool cloud customers. Retool later restored those accounts.
- Fireblocks said Fortress's compromised vendor had preconfigured authorization to interact with its platform, and transactions were stopped when the configured limit was reached.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.