Crypto.com says hackers stole more than $30 million in bitcoin and ethereum (2024)

Crypto.com says hackers stole more than $30 million in bitcoin and ethereum (1)

By Anne Marie Lee

/ MoneyWatch

Crypto.com said Thursday that cybercriminals had breached its security systems earlier in the week and made off with more than $30 million in stolen bitcoin and ethereum.

The cryptocurrency exchange Crypto.com, known for its viral commercial starring Matt Damon as well as its recent $700 million deal to rename the Staples Center in Los Angeles as Crypto.com Arena, said the hackers managed to bypass its two-factor authentication system and withdraw the funds from 483 customer accounts, according to a statement the Singapore-based crypto exchange posted Thursday on its corporateblog.

"Unauthorized withdrawals totaled 4,836.26 ETH, 443.93 BTC and approximately US$66,200 in other currencies," the company said in the post.

That works out to around $15 million and $19 million in ethereum and bitcoin, respectively, based on current exchange rates. All customers have been "fully reimbursed" for any lost funds as a result of the hack, Crypto.com said.

The blog statement serves as a postmortem of the hack, which the company said happened Monday. It provides details of the event and the company's detection and response to the cyber breach, as well as its "next steps," but it does not offer information on the identity of the hackers behind the breach.

The timing of Crypto.com's public statement, a full three days after the hack, is viewed by many as belated confirmation. According to an article from CoinDesk on Wednesday, about 4,600 etherium that was reportedly stolen from Crypto.com was "currently being laundered via Tornado Cash — an Etherium Mixer." Thursday's blog post also followed a Bloomberg interview Wednesday with Crypto.com Chief Executive Kris Marszalek, in which the CEO acknowledged that approximately 400 customer accounts were hacked.

"Given the scale of the business, these numbers are not particularly material and customer funds were not at risk," the CEO told Bloomberg.

Reports of "suspicious activity"

The company first acknowledged something unusual was up in a January 16tweetin which it announced the temporary suspension of withdrawals following user reports of "suspicious activity on their accounts."

"We will be pausing withdrawals shortly, as our team is investigating. All funds are safe," the company said.

We have a small number of users reporting suspicious activity on their accounts.

We will be pausing withdrawals shortly, as our team is investigating. All funds are safe.

— Crypto.com (@cryptocom) January 17, 2022

The company's claim that "All funds are safe" was quickly challenged by customers, most notably Los Angeles-based jeweler Ben Baller, who immediately tweeted back, "I messaged yah guys hours ago about my account having 4.28ETH stolen out of nowhere and I'm also wondering how they got passed the 2FA?"

2FA called into question

Two-factor authentication, or 2FA, is the multistep security system that requires users to provide two distinct forms of identification, such as a one-time passcode in addition to a password, when logging into an online account. The commonly used security measure provides an extra layer of protection against weak passwords such as, say, a surname followed by "123." While used by industries across the board, 2FA is considered a must for digital currency accounts. Monday's breach, however, brings into question the reliability of 2FA in keeping digital assets safe from hackers.

For now, Crypto.com says it is sticking with 2FA, but not for long.

Upon discovery of the breach, the company "revoked all customer 2FA tokens" and used the 14 hours of downtime from withdrawal activity to "revamp," according to the statement. Customers were then "migrated to a completely new 2FA infrastructure," as an additional security measure.

That is only temporary, however, as the company says it plans to ditch 2FA for "true Multi-Factor Authentication (MFA), providing added strength for our global user base."

Shares of Crypto.com have fallen more than 6% since news of the security breach, closing Thursday at 46 cents a share.

Anne Marie Lee

Anne Marie D. Lee is an editor for CBS MoneyWatch. She writes about topics including personal finance, the workplace, travel and social media.

Crypto.com says hackers stole more than $30 million in bitcoin and ethereum (2024)
Top Articles
Buying Bitcoin With Cash
This Is How to Clear Your Cache—and Why You Should
Somboun Asian Market
Cold Air Intake - High-flow, Roto-mold Tube - TOYOTA TACOMA V6-4.0
Ffxiv Shelfeye Reaver
Craftsman M230 Lawn Mower Oil Change
Wisconsin Women's Volleyball Team Leaked Pictures
Cad Calls Meriden Ct
Wmu Course Offerings
Top Financial Advisors in the U.S.
Corpse Bride Soap2Day
Optum Medicare Support
Pbr Wisconsin Baseball
Espn Expert Picks Week 2
454 Cu In Liters
4156303136
Painting Jobs Craigslist
Kamzz Llc
EASYfelt Plafondeiland
At&T Outage Today 2022 Map
Jordan Poyer Wiki
kvoa.com | News 4 Tucson
Cornedbeefapproved
Aes Salt Lake City Showdown
Stockton (California) – Travel guide at Wikivoyage
Primerica Shareholder Account
Kelley Fliehler Wikipedia
Willys Pickup For Sale Craigslist
County Cricket Championship, day one - scores, radio commentary & live text
Otis Offender Michigan
Stolen Touches Neva Altaj Read Online Free
Www Craigslist Com Shreveport Louisiana
How to Watch the X Trilogy Starring Mia Goth in Chronological Order
Seymour Johnson AFB | MilitaryINSTALLATIONS
Junee Warehouse | Imamother
Tds Wifi Outage
Elgin Il Building Department
Hindilinks4U Bollywood Action Movies
Ticket To Paradise Showtimes Near Marshall 6 Theatre
Pokemon Reborn Locations
Craigslist Tulsa Ok Farm And Garden
Cranston Sewer Tax
412Doctors
Timothy Warren Cobb Obituary
Professors Helpers Abbreviation
Dontrell Nelson - 2016 - Football - University of Memphis Athletics
Copd Active Learning Template
Bonecrusher Upgrade Rs3
The 13 best home gym equipment and machines of 2023
Kidcheck Login
Guidance | GreenStar™ 3 2630 Display
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6052

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.