The Employee With Access: Insider Loss and How It Actually Happens
Most insider crypto losses are not dramatic thefts. They are unrevoked access, shared credentials and a departure nobody processed.
Priya Raman · 2 min read
Companies plan for external attackers and lose money to former employees whose access was never removed. The second is far more common and much less discussed. The contrast worth drawing is with an institutional crypto wallet, where this is a requirement rather than a courtesy.
The realistic scenarios
Access not revoked on departure. Someone leaves, their wallet access remains, and months later funds move. Usually the departure was amicable and nobody thought about it.
Shared credentials. One login used by several people, so there is no attribution and no way to revoke one person’s access without disrupting everyone.
A personal device with keys. Someone kept a copy for convenience. The device is later sold, compromised, or simply out of the company’s control.
Legitimate access used illegitimately. Someone with genuine authority makes a payment they should not. Not preventable by access control, only by approval requirements.
The controls
Individual accounts, never shared. Every person has their own credentials. Attribution and revocation both become possible.
Approval separate from initiation. Nobody can both create and release a payment. This is the only control that addresses the fourth scenario.
A written departure procedure. Revoke access first. Then review addresses added by that person. Then read the log for the previous period. Fifteen minutes.
Periodic access review. Quarterly, list who has access to what and confirm each is still appropriate. This catches the accumulation that happens as people change roles.
The departure procedure in detail
Revoke wallet and exchange access before the conversation, if the departure is not amicable.
Rotate any credential that person knew, including anything in a shared password manager they had access to.
Review the address allowlist for entries they added, and confirm each against a real supplier relationship.
Read the transaction log for the previous ninety days, looking at approvals as well as payments.
If they held a key in a multi-signature arrangement, rotate the key set. This is the step most often skipped because it is the most work, and leaving it means a former employee retains a share of control. The same attack targets businesses harder, which is what a corporate crypto wallet with segregated accounts is built to resist.
Where small companies go wrong
Believing controls are unnecessary because everyone is trusted.
Trust is not the issue. The controls exist for compromised accounts and for the situation where someone trusted is under pressure, and they protect the honest majority from suspicion when something goes wrong.
A company where one person can move funds alone has no way to demonstrate that person did not, which is a poor position for them as much as for the company.
The audit trail
Every action, with who, what, when and from where, including failed and rejected attempts.
The rejected attempts are the signal. A run of rejected withdrawals is the clearest early sign that an account is compromised, and a log recording only successes will never show it. If you want to see these protections operating rather than described, a support channel with a named contact is bound by them.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.