Hackers used social-engineering phone calls to target several of the largest firms on Wall Street, including Point72, Two Sigma, and Citadel, according to a Reuters report circulated on August 6, 2026. The campaign relied on voice manipulation rather than code, with attackers calling employees and talking their way toward access instead of breaking through any technical defense.
The detail that matters is the method. These are firms that spend heavily on security infrastructure, run their own threat teams, and treat data protection as a core function. None of that stops a phone call. A person picks up, hears a plausible story from someone claiming to be IT support or a colleague, and hands over a credential or approves a login request. The most fortified perimeter in finance has a door that opens when someone knocks politely enough.
The attack skipped the firewall entirely
Social engineering is not new, but the targeting here is pointed. Point72, run by Steve Cohen, Ken Griffin's Citadel, and the quant shop Two Sigma sit among the most sophisticated trading operations in the world. Attackers going after them with phone calls rather than exploits is a statement about where the soft spot actually is.
The playbook is consistent across these campaigns. A caller poses as a help-desk technician, references a fake ticket or a "security issue," and creates enough urgency that the target stops thinking and starts complying. Some versions push the employee to read out a one-time passcode. Others walk them into approving a multi-factor prompt on their phone. The credential is the prize, and the human is the delivery mechanism.
For hedge funds, the exposure runs to positions, counterparties, and client data. Reuters did not confirm what, if anything, the attackers obtained, and the firms have not detailed the outcome. The significance is in the attempt itself: the same crews that hit crypto users are now dialing into institutional finance.
Crypto learned this lesson the hard way
Anyone who has spent time around digital assets recognizes this pattern immediately. The largest losses in crypto rarely come from cracked cryptography. They come from someone convincing a person to click, sign, or approve. Support-desk impersonation, fake wallet-recovery calls, and spoofed exchange notifications have drained more value than most protocol exploits.
The Boltz service halt after an AI-assisted attack wave and the Coldcard exploit that pushed $90M out of cold storage show two different failure modes, but the through-line for everyday users is the same: the attacker wants you to take an action, and the request always arrives wrapped in urgency and authority.
That is why self-custody options shift the security question rather than answer it. Holding your own keys removes exchange counterparty risk, but it puts the full weight of the human layer on you. A seed phrase read aloud to a "support agent" is gone the same way a hedge-fund credential is gone. Custody design changes who you trust, not whether you can be talked into a mistake.
Practical defenses that actually hold
The countermeasures are unglamorous and effective. Treat any inbound call claiming to be support as hostile until proven otherwise, and call back on a number you already trust rather than one the caller supplies. No legitimate IT team, exchange, or crypto card issuer needs you to read a one-time code over the phone. Ever.
Hardware-based authentication that cannot be relayed by voice, such as a physical security key, closes the gap that push-notification approvals leave open. For crypto specifically, keeping a hardware wallet's confirmation on the device screen, and reading the destination address there rather than trusting what an app or a caller tells you, defeats most of these scripts.
The pattern is worth internalizing because it scales down as easily as it scales up. The same technique aimed at Citadel this week is aimed at retail wallet holders every day, with cheaper tooling and higher volume. The defense does not change with the size of the target.
Overview
Attackers reportedly used social-engineering phone calls to target Point72, Two Sigma, and Citadel, per an August 6, 2026 Reuters report, bypassing technical security by manipulating people directly. The episode is a reminder that the human layer is the real attack surface in finance and in crypto alike. Verify inbound support requests independently, never share one-time codes or seed phrases by voice, and confirm sensitive actions on hardware you control.



