Third-party risk has emerged as one of the most significant security challenges facing the cryptocurrency industry. While crypto firms have traditionally focused on protecting private keys, securing exchanges, and strengthening blockchain infrastructure, recent incidents suggest that the greatest vulnerabilities may lie beyond their own environments.
Over the past two years, some of the industry’s largest security events have been linked to trusted vendors, custody providers, contractors, and technology partners. The compromise of WazirX’s third-party custody environment resulted in losses of approximately $235 million, while the attack linked to Safe Wallet infrastructure led to an estimated $1.5 billion loss for Bybit. Together, these incidents represent nearly $1.74 billion in reported losses and underscore the growing importance of managing third-party dependencies across the crypto ecosystem.
Recent incidents involving Coinbase, Trezor, and Coldcard further demonstrate that third-party risk extends beyond custody providers and wallet infrastructure. Attackers are increasingly exploiting service providers, contractors, logistics partners, communications platforms, and software vendors as alternative pathways into the digital asset ecosystem.
How Third-Party Risk Became a Major Crypto Threat
The modern crypto industry relies on a complex network of external providers. Exchanges and Virtual Asset Service Providers (VASPs) routinely depend on custodians, wallet infrastructure vendors, cloud providers, customer support contractors, analytics platforms, identity verification services, and communications providers to deliver services at scale.
This interconnected model creates efficiencies but also expands the attack surface.
The incident involving Bybit illustrated how attackers can exploit a trusted technology provider rather than attempting to breach a major exchange directly. According to forensic investigations, attackers compromised infrastructure associated with Safe Wallet and manipulated the transaction approval process. Importantly, investigators found no evidence that Bybit’s core infrastructure had been compromised. The attack succeeded because threat actors targeted a trusted third-party dependency that sat within a critical transaction workflow.
A similar pattern emerged in the 2024 WazirX incident. Rather than attacking the exchange’s trading platform, attackers targeted a multi-signature wallet operating through a third-party custody arrangement. The compromise demonstrated that even sophisticated controls such as multi-signature wallets can become ineffective when all participants rely on the same external infrastructure or approval interface.
The industry has also witnessed the risks associated with third-party personnel. In 2025, Coinbase disclosed a breach involving overseas support contractors who allegedly provided customer information to attackers. While private keys, passwords, and customer funds were not compromised, the incident highlighted how outsourced operations can create access points that are difficult to monitor and control.
More recently, Trezor disclosed incidents involving third-party service providers, including customer data exposure through a logistics partner and a separate compromise involving an email communications provider that enabled phishing emails to be sent from an official company address. Although no wallet recovery seeds or private keys were reportedly exposed, the incidents demonstrated how customer data held by vendors can be weaponized in highly targeted social engineering campaigns.
Even self-custody has not been immune. Reports involving Coldcard linked a firmware flaw affecting seed generation to thefts that ultimately approached $89 million across thousands of Bitcoin wallet addresses. In this case, users were not compromised through an exchange or phishing campaign but through a technology dependency embedded within a trusted hardware wallet product.
What VASPs Should Be Watching
For VASPs, third-party risk is no longer limited to vendor onboarding questionnaires and annual reviews. Organizations need to understand where critical business processes depend on external providers and identify where a compromise could lead to operational disruption, financial loss, or customer harm.
Particular attention should be given to custody providers, wallet infrastructure vendors, outsourced support operations, cloud-service providers, communications platforms, and software suppliers involved in transaction processing or customer interactions.
Concentration risk is another growing concern. Many crypto firms rely on the same wallet providers, custody solutions, cloud platforms, and analytics vendors. A compromise affecting one major provider can quickly cascade across multiple organizations and jurisdictions.
VASPs should also pay close attention to privileged third-party access. Contractors and vendor personnel often possess legitimate access to sensitive systems and customer information. These individuals can become attractive targets for bribery, phishing, credential theft, or social engineering campaigns.
Data-retention practices deserve equal scrutiny. Several recent incidents demonstrate that customer records retained for years can significantly increase the impact of a breach. Organizations should understand not only how vendors protect customer information but also how long they retain it and whether retention aligns with business and regulatory requirements.
Controls That Can Reduce Third-Party Risk
Reducing third-party risk requires a combination of governance, technical controls, monitoring, and operational discipline.
Vendor due diligence should extend beyond compliance certifications and include an assessment of security governance, software-development practices, incident response maturity, privileged-access controls, data-retention policies, and subcontractor management.
Critical third parties should be subject to continuous monitoring rather than annual reviews. Security incidents, regulatory actions, ownership changes, operational disruptions, and changes to a provider’s control environment should trigger reassessments.
For high-value crypto transactions, organizations should implement independent verification procedures. Transaction details should be validated outside the primary interface, particularly when using third-party wallet infrastructure. Out-of-band verification, transaction simulation tools, and multi-channel approvals can help reduce the risk of interface manipulation.
Access management remains one of the most effective controls. Third-party users should receive only the minimum access required to perform their responsibilities. Multi-factor authentication, privileged-access monitoring, session logging, and regular access recertification should be standard practice for all critical providers.
Finally, incident-response planning must include key vendors. Many organizations invest heavily in internal response capabilities but fail to establish communication protocols and escalation procedures with critical third parties before an incident occurs. When a third-party compromise happens, response speed often determines the scale of the impact.
Conclusion
The incidents involving WazirX, Bybit, Coinbase, Trezor, and Coldcard may have involved different attack methods, but they reveal a common reality. Increasingly, attackers are targeting the trusted partners that support crypto businesses instead of attacking the businesses themselves.
For VASPs, third-party risk management is no longer simply a regulatory expectation or procurement exercise. It has become a core component of operational resilience and cybersecurity strategy. The organizations best positioned to withstand future attacks will be those that apply the same rigor to evaluating and monitoring their external dependencies as they do to securing their own systems.
In today’s digital asset ecosystem, security is only as strong as the weakest trusted partner.

