Crypto markets have barely moved this week even though several major Wall Street hedge funds were targeted in a wave of attempted cyberattacks. Point72, Citadel, Two Sigma and Millennium were reportedly among the firms hit. The attackers apparently used voice phishing, also called vishing, to trick employees into giving up credentials or allowing access to internal systems.
That kind of social engineering is getting harder to spot. AI tools are making fake voices and video look more convincing. For financial institutions, this is a growing problem, not a hypothetical one.
Markets shrug off the headlines
Bitcoin was trading around $64,500 on Glassnode, up roughly 1% over the past week. Ether was near $1,900, down about 0.5%. The total crypto market cap stayed around $2.3 trillion. No panic, no sudden sell-off.
The CBOE Volatility Index, often called Wall Street’s fear gauge, sat near 15.8. That was up 2.7% in 24 hours but still below where it stood five sessions ago. So investors in traditional markets are also staying calm.
Part of that calm may come from the fact that the attacks did not seem to succeed. Point72 told Reuters that no client data had been compromised. Citadel said it had not experienced a successful breach. But investigations are still ongoing, and it remains unclear whether any crypto exchanges, custodians, or blockchain infrastructure providers were affected.
Why this matters for crypto
Hedge funds are more involved in digital assets than they used to be. Some run crypto strategies, and firms like Citadel Securities provide liquidity across markets. If a cyberattack disrupted a fund’s internal operations, that could spill over into trading across stocks, bonds, derivatives, and crypto even if no exchange was directly hit.
That is the scenario crypto traders are watching. Cybercrime and crypto often overlap. In a report from FS-ISAC, a nonprofit focused on cyber resilience for banks, researchers noted that criminals use real-time payment systems and crypto to move stolen money quickly. That makes recovery difficult, if not impossible.
The same report highlighted how generative AI is changing phishing. Attackers can create deepfake versions of top executives that look and sound real. That makes a simple call or video message much harder to dismiss.
The wider insurance and disclosure problem
The attack also raised questions about how much investors actually know. Since 2023, the SEC has required public companies to report material cyber incidents within four business days. But the rules only cover public firms, and there is often a lag in determining how serious an event is.
Research from the Swiss Finance Institute found that portfolios tilted toward companies with high cyber risk earned excess annual returns of 18.72%. That suggests investors are already demanding a premium for taking on that risk.
Meanwhile, cyber insurance is becoming less available. Mario Greco, CEO of Zurich Insurance Group, warned that sophisticated breaches have become effectively uninsurable. For crypto firms, the situation is even harder because fewer insurance options exist.
So far, the market reaction has been muted. But if new disclosures show that trading infrastructure or assets were actually affected, the calm could fade quickly. For now, traders seem to treat this as an operational issue, not a market-moving event.
