Entry_point: Hot wallets accessed post-bankruptcy filing
Exploit_vector: Attackers used SIM-swap to gain access to multi-factor authentication (MFA), retrieved private keys, and transferred funds from wallets
Severity: Critical
Attack_steps:
Attackers performed SIM-swap on FTX executives
Used intercepted MFA codes to access backend systems