← All news
AI AgentsLeast PrivilegeIncident Response

A $40M Lesson in AI Agent Permissions: What the Step Finance Breach Teaches About Least Privilege

Obiguard Research Team·August 8, 2026·3 min read

In January 2026, Solana DeFi portfolio manager Step Finance lost roughly $40 million after attackers compromised executive devices and used that access to direct the platform's AI trading agents to drain its treasury, according to reporting from BleepingComputer. The initial breach was ordinary — compromised endpoints, a story security teams have handled for decades. What turned it into a nine-figure incident was what happened next.

The permissions did the damage, not the intrusion

Step Finance's AI trading agents were configured to execute large transfers without requiring human approval. Once attackers had a foothold via the compromised devices, the agents moved more than 261,000 SOL tokens — worth an estimated $27–30 million at the time — because nothing in the system was positioned to stop them. The agents weren't compromised directly; they simply did what they were authorized to do, for whoever was in control of the session. The platform ultimately shut down operations, and recovery efforts clawed back only a fraction of what was taken.

This is quickly becoming the default failure pattern for agentic AI incidents: the attacker doesn't need to break the model or trick it into misbehaving. They just need to reach an account, a session, or a device that already has standing authorization, because the agent behind it was never scoped down to what it actually needed.

The uncomfortable part

Every one of these permissions was granted deliberately, at some point, presumably because it made the agent faster or more autonomous. That's the trade-off agentic AI keeps forcing on organizations: broader permissions make agents more useful and, without a compensating control, proportionally more dangerous the moment any single credential in the chain is compromised. A trading agent that can move seven figures without a second signature isn't a bug — it's a policy decision that nobody stress-tested against a compromised laptop.

Where Obiguard fits

This is the exact failure mode Obiguard's Allow-lists and Policy layers exist to prevent — scoping what any given AI agent is actually authorized to do (which actions, up to what thresholds, against which systems) independently of whatever the agent's own logic or a compromised session tries to tell it. High-value actions can be routed through human-approval gates instead of executing silently, and every attempted action — approved or blocked — lands in the audit ledger so a pattern like "unusual transfer volume from a new session" is visible before it's a headline.

If your organization has AI agents with standing access to money, infrastructure, or sensitive systems, the question worth asking today is the one Step Finance answered the hard way: what's the actual ceiling on what this agent can do if the account behind it is compromised? Talk to us about putting real limits in place.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →