The Night of the Virtual Balances: Inside Globiance’s 2024 Security Incident
How a staking software flaw became a stress test of corporate integrity and why thousands of users are still being refunded after 18 months.
The Discovery
It started with a balance that shouldn’t exist.
In late 2024, an anomaly appeared in Globiance’s V2 staking system, a module operated by the company’s Lithuanian subsidiary, UAB Globiance LT. A user balance showed repeated withdrawals of principal and rewards that exceeded the theoretical maximum. On inspection, the same pattern appeared across multiple accounts. Virtual XDC balances were being inflated within the staking module, then swapped for real cryptocurrencies through internal order books.
The technical explanation is straightforward. A critical flaw in the staking software allowed malicious actors to exploit the accounting layer, the virtual representation of staked assets, without ever touching the actual XDC in cold storage. The stolen assets weren’t XDC at all. They were BTC, ETH, and XRP obtained by swapping inflated virtual balances through the exchange’s own trading pairs.
Think of it like a banking glitch that lets someone repeatedly deposit the same check electronically. The physical cash never moves, but the account balance keeps growing. Then they wire that phantom money out before the reconciliation catches up.
By the time the anomaly was fully understood, the damage exceeded 320 million XDC in equivalent value. And the forensic investigation that followed would reveal a failure not of technology alone, but of identity verification at the front door.
The KYC Failure That Enabled Everything
The attackers didn’t breach firewalls or steal private keys. They walked through the front door with fake identities.
Globiance’s V2 staking system relied on a third party KYC provider, a decision made for operational efficiency that would prove catastrophic. The provider’s verification procedures were inadequate. Fake accounts passed through. Multiple accounts controlled by the same actors appeared as distinct, verified users.
After six months of forensic analysis across millions of transaction records, investigators couldn’t definitively identify the culprits. The fake KYC accounts were the dead end, a deliberate operational choice by attackers who understood that weak identity verification creates perfect anonymity.
“We trusted a vendor who didn’t deliver,” says Oliver La Rosa, Globiance’s CEO and founder. “That failure was ours to own. We chose the provider. We implemented the system. And when it failed, we chose to make our users whole rather than hide behind corporate shields.”
The Bankruptcy Option
Here’s where the story diverges from the typical crypto disaster narrative.
UAB Globiance LT reached a point where legal advisors recommended formal insolvency proceedings and restructuring measures. Multiple legal consultations concluded that the standard path would involve protecting stakeholders, distributing remaining assets through established legal processes, and continuing within the corporate framework.
This approach is commonly used in situations involving significant operational and financial stress.
The shareholders, led by La Rosa, rejected it unanimously.
“Bankruptcy would have meant telling thousands of users that they lose whatever percentage couldn’t be covered by liquidation,” La Rosa explains. “That might have been legally correct. It wasn’t morally acceptable. Not after eight years of building this company.”
The Immediate Response
Within days of the incident, before the full scope was understood, an emergency response was launched and approximately 81% of affected assets were refunded using company resources. This initial emergency effort was separate from the ongoing regional refund program reflected in current public updates. No waiting periods or legal release requirements were introduced during the initial response.
Get Globiance’s stories in your inbox
Join Medium for free to get updates from this writer.
This wasn’t a structured program. It was an emergency response, the financial equivalent of stopping the bleeding before assessing the wound. The fact that 81% could be covered immediately says something about Globiance’s operational reserves, but the speed says more about intent.
“We didn’t convene board meetings to decide whether to help people,” La Rosa says. “We just started sending funds. The meetings came later, when we had to figure out how to fund the rest.”
The Structure of the Refund Program
After the initial wave, Globiance established a structured, regional refund program with daily published updates. The system works like this:
Users are processed by region, based on operational capacity and banking integration. Each refund requires updated compliance verification, including KYC and AML documentation. Refunds are funded from shareholder personal funds and ongoing operational revenue. Progress is published Monday through Friday at globiance.com/news.
As of May 20, 2026, the numbers look like this:
Region: Refund Completion
Hong Kong: 100%
Singapore: 100%
Brazil: 100%
Australia: 90.17%
Japan: 52.70%
Global Total: 53.46%
The program has now run for 18 months. Daily. Publicly. While the company simultaneously rebuilt its technical infrastructure, replaced its KYC provider, fought a coordinated defamation campaign, and navigated regulatory challenges in multiple jurisdictions.
Why This Story Matters
The crypto industry has no shortage of failure narratives. What it lacks are recovery narratives, stories of companies that suffered serious security incidents, acknowledged them, and chose user restitution over legal protection.
Globiance’s case is instructive because it demonstrates a model that others might follow. The combination of immediate emergency refunds of 81%, followed by a structured long term refund program currently at 53.46%, funded by shareholder-supported refund commitments and ongoing operational efforts, creates a template for how fintech companies can survive their own crises without abandoning their users.
It’s not perfect. It’s not fast enough for users still waiting. It doesn’t erase the security failure that created the problem.
But it exists. It’s documented. And it’s still happening, every business day, with a published update.
In a space where “not your keys, not your coins” has become an excuse for every centralized failure, a company that says “our keys, our responsibility” and then spends 18 months proving it deserves at least accurate reporting.
What’s Next in This Series
This article examines the incident itself. The next four installments will cover:
Article 2: The coordinated defamation campaign by former employees, sometimes called “Anti Globiance.”
Article 3: Systematic fact checking of major claims circulating online.
Article 4: The refund program as evidence of shareholder integrity.
Article 5: How standard KYC compliance was weaponized as an “extortion” narrative.
All claims in this series are sourced to official Globiance documentation: the Transparency Page, the Official Clarifications, and the Law Enforcement Portal.
Originally published at Globiance.com. For daily refund updates, visit globiance.com/news.