2FA compromise led to Crypto.com hack


More details have emerged about the recent Crypto.com hack that left almost 500 customers without their hard-earned cryptocurrencies.
The company has published a post mortem on its website in which it says that whoever was behind the theft, managed to withdraw millions of dollars in cryptocurrencies from hundreds of accounts, without inputting two-factor authentication.
In total, 483 accounts were compromised, with more than $31 million taken – made up of 4,836.26 ETH, 443.93 BTC, and approximately $66,200 in “other cryptocurrencies” stolen.
Security breaches and fraud
Crypto.com did not provide more details on how it was possible to withdraw the tokens without inputting 2FA, and whether or not an endpoint was compromised, but it did say what it did at the moment – and what it plans on doing, going forward.
Once it discovered the incident, the company first suspended all withdrawals from the platform, reimbursed the affected accounts, revoked all customer 2FA tokens, and added “additional security hardening measures”.
Now, after a new withdrawal address is added to the account, the owner needs to wait for 24 hours before it is approved, giving legitimate owners enough time to report a potential issue.
Furthermore, Crypto.com said it plans to move away from 2FA into “true multi-factor authentication,” although it did not specify what that meant, or when it might happen.
Finally, the customers were required to re-login and set up their 2FA tokens again.
An actual security breach on a cryptocurrency exchange rarely happens. In most cases, cryptocurrency theft happens through fraud, in which owners are either tricked into sending their tokens elsewhere, or tricked into giving away personally identifiable information. That information can later be used in identity theft, allowing criminals to easily withdraw funds from wallets and exchanges.
In more recent times, with the emergence of DeFi (Decentralized Finance), a scam method known as a “rugpull” has risen in popularity.
In the most simplest of explanations, a rugpull happens when a blockchain project’s owners decide to remove all liquidity from the project, dropping the value of the token they’ve created virtually to zero.
Audio player loading… More details have emerged about the recent Crypto.com hack that left almost 500 customers without their hard-earned cryptocurrencies. The company has published a post mortem on its website in which it says that whoever was behind the theft, managed to withdraw millions of dollars in cryptocurrencies from…
Recent Posts
- How Claude’s 3.7’s new ‘extended’ thinking compares to ChatGPT o1’s reasoning
- ‘We’re nowhere near done with Framework Laptop 16’ says Framework CEO
- Razer’s new Blade 18 offers Nvidia RTX 50-series GPUs and a dual mode display
- Samsung’s first Pro series Gen 5 PCIe SSD arrives in March
- I tried adding audio to videos in Dream Machine, and Sora’s silence sounds deafening in comparison
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010