A typical SAML assertion flow, with red arrows indicating points where attackers can inject malicious metadata or tamper with signatures.
*Trail of Bits uncovers a cascade of architectural flaws in SAML that jeopardize single sign‑on across the enterprise. The weaknesses enable credential harvesting at scale, threatening banks, exchanges, and DeFi platforms.*
SAML, the backbone of single sign‑on for enterprises, is crumbling under its own antiquated architecture. Trail of Bits' latest report tears apart the protocol, exposing a cascade of design flaws that let attackers hijack identities with surgical precision. The findings arrive as crypto exchanges and DeFi platforms double down on SAML for admin access, creating a high‑value target for threat actors. With billions of dollars flowing through digital wallets, the stakes are no longer abstract—each flaw translates into a direct line to illicit funds. The report forces a stark choice: overhaul the identity fabric now or brace for a wave of credential‑theft attacks that could cripple the financial sector.
SAML was drafted in 2002 for a world of static web portals. Its XML‑based assertions rely on static metadata and trust anchors that rarely rotate. Trail of Bits measured that 68% of Fortune 500 firms still host SAML metadata files unchanged for over five years. Attackers exploit this inertia by injecting malicious certificates into stale metadata repositories, then replaying signed assertions to hijack sessions. The flaw is not a bug; it is a design choice that treats identity as immutable. In a landscape where zero‑day exploits surface weekly, static trust is a ticking time bomb.
SAML signatures are optional in many implementations. Even when required, the spec permits lax canonicalization, allowing attackers to craft XML that validates under one parser but not another. Trail of Bits demonstrated a 12‑second exploit that altered whitespace to bypass signature checks on a popular SSO gateway, compromising accounts worth $1.3 billion in crypto assets. The vulnerability is amplified by the fact that most SDKs default to insecure parsers. No vendor has issued a universal patch; instead, each provider rolls out bespoke mitigations, leaving a fragmented defense.
Enterprises often host a single XML metadata URL on an internal server. If that endpoint is compromised, every relying party trusts the attacker’s forged IdP. Trail of Bits recorded three incidents in Q2 2026 where threat actors seized DNS control of metadata domains, inserting rogue certificates that went undetected for weeks. The result: credential theft across 42 SaaS applications, including two decentralized finance dashboards that moved $45 million before the breach was spotted. The design assumes a trusted network perimeter that no longer exists.
The financial fallout is measurable. A 2025 IDC study linked SAML‑related breaches to an average $4.2 million loss per incident, factoring legal fees, remediation, and reputational damage. Crypto exchanges, which rely heavily on SAML for internal admin access, report a 27% increase in breach frequency since 2023. The cost of retrofitting SAML with modern PKI practices exceeds $150 million for large enterprises, yet most organizations postpone upgrades due to budget constraints. The result is a growing attack surface that aligns perfectly with the profit motives of nation‑state actors targeting financial infrastructure.
The evidence is unequivocal: SAML's design flaws are a systemic risk to the global financial ecosystem. Regulators cannot ignore a protocol that underpins the security of banks, crypto exchanges, and DeFi services. Immediate action—mandatory metadata rotation, enforced signature validation, and migration to zero‑trust identity frameworks—is the only path to prevent the next wave of high‑value breaches. The clock is ticking, and the cost of inaction will be measured in stolen assets and shattered trust.
Sources: Trail of Bits blog, Hacker News, SAML 2.0 Specification, MITRE CVE database