Crypto.com says hackers stole more than $30 million in bitcoin and ethereum (2024)

Crypto.com says hackers stole more than $30 million in bitcoin and ethereum (1)

By Anne Marie Lee

/ MoneyWatch

Crypto.com said Thursday that cybercriminals had breached its security systems earlier in the week and made off with more than $30 million in stolen bitcoin and ethereum.

The cryptocurrency exchange Crypto.com, known for its viral commercial starring Matt Damon as well as its recent $700 million deal to rename the Staples Center in Los Angeles as Crypto.com Arena, said the hackers managed to bypass its two-factor authentication system and withdraw the funds from 483 customer accounts, according to a statement the Singapore-based crypto exchange posted Thursday on its corporateblog.

"Unauthorized withdrawals totaled 4,836.26 ETH, 443.93 BTC and approximately US$66,200 in other currencies," the company said in the post.

That works out to around $15 million and $19 million in ethereum and bitcoin, respectively, based on current exchange rates. All customers have been "fully reimbursed" for any lost funds as a result of the hack, Crypto.com said.

The blog statement serves as a postmortem of the hack, which the company said happened Monday. It provides details of the event and the company's detection and response to the cyber breach, as well as its "next steps," but it does not offer information on the identity of the hackers behind the breach.

The timing of Crypto.com's public statement, a full three days after the hack, is viewed by many as belated confirmation. According to an article from CoinDesk on Wednesday, about 4,600 etherium that was reportedly stolen from Crypto.com was "currently being laundered via Tornado Cash — an Etherium Mixer." Thursday's blog post also followed a Bloomberg interview Wednesday with Crypto.com Chief Executive Kris Marszalek, in which the CEO acknowledged that approximately 400 customer accounts were hacked.

"Given the scale of the business, these numbers are not particularly material and customer funds were not at risk," the CEO told Bloomberg.

Reports of "suspicious activity"

The company first acknowledged something unusual was up in a January 16tweetin which it announced the temporary suspension of withdrawals following user reports of "suspicious activity on their accounts."

"We will be pausing withdrawals shortly, as our team is investigating. All funds are safe," the company said.

We have a small number of users reporting suspicious activity on their accounts.

We will be pausing withdrawals shortly, as our team is investigating. All funds are safe.

— Crypto.com (@cryptocom) January 17, 2022

The company's claim that "All funds are safe" was quickly challenged by customers, most notably Los Angeles-based jeweler Ben Baller, who immediately tweeted back, "I messaged yah guys hours ago about my account having 4.28ETH stolen out of nowhere and I'm also wondering how they got passed the 2FA?"

2FA called into question

Two-factor authentication, or 2FA, is the multistep security system that requires users to provide two distinct forms of identification, such as a one-time passcode in addition to a password, when logging into an online account. The commonly used security measure provides an extra layer of protection against weak passwords such as, say, a surname followed by "123." While used by industries across the board, 2FA is considered a must for digital currency accounts. Monday's breach, however, brings into question the reliability of 2FA in keeping digital assets safe from hackers.

For now, Crypto.com says it is sticking with 2FA, but not for long.

Upon discovery of the breach, the company "revoked all customer 2FA tokens" and used the 14 hours of downtime from withdrawal activity to "revamp," according to the statement. Customers were then "migrated to a completely new 2FA infrastructure," as an additional security measure.

That is only temporary, however, as the company says it plans to ditch 2FA for "true Multi-Factor Authentication (MFA), providing added strength for our global user base."

Shares of Crypto.com have fallen more than 6% since news of the security breach, closing Thursday at 46 cents a share.

Anne Marie Lee

Anne Marie D. Lee is an editor for CBS MoneyWatch. She writes about topics including personal finance, the workplace, travel and social media.

Crypto.com says hackers stole more than $30 million in bitcoin and ethereum (2024)
Top Articles
Forex vs Stocks - main differences and similarities
Code monkey definition – Glossary
Chs.mywork
NYT Mini Crossword today: puzzle answers for Tuesday, September 17 | Digital Trends
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
4-Hour Private ATV Riding Experience in Adirondacks 2024 on Cool Destinations
Http://N14.Ultipro.com
Phone Number For Walmart Automotive Department
Chalupp's Pizza Taos Menu
Zitobox 5000 Free Coins 2023
Www Thechristhospital Billpay
Mivf Mdcalc
Ktbs Payroll Login
4Chan Louisville
Obituary | Shawn Alexander | Russell Funeral Home, Inc.
Yesteryear Autos Slang
Rosemary Beach, Panama City Beach, FL Real Estate & Homes for Sale | realtor.com®
Premier Reward Token Rs3
Salem Oregon Costco Gas Prices
Shopmonsterus Reviews
Shiftselect Carolinas
Maxpreps Field Hockey
A Person That Creates Movie Basis Figgerits
Papa Johns Mear Me
Goodwill Of Central Iowa Outlet Des Moines Photos
Wku Lpn To Rn
Craigslist Fort Smith Ar Personals
The Collective - Upscale Downtown Milwaukee Hair Salon
Cfv Mychart
LG UN90 65" 4K Smart UHD TV - 65UN9000AUJ | LG CA
Downloahub
Housing Assistance Rental Assistance Program RAP
Forager How-to Get Archaeology Items - Dino Egg, Anchor, Fossil, Frozen Relic, Frozen Squid, Kapala, Lava Eel, and More!
Save on Games, Flamingo, Toys Games & Novelties
Nacho Libre Baptized Gif
Whitehall Preparatory And Fitness Academy Calendar
20+ Best Things To Do In Oceanside California
Frcp 47
Daly City Building Division
Citibank Branch Locations In Orlando Florida
888-822-3743
Pathfinder Wrath Of The Righteous Tiefling Traitor
Petra Gorski Obituary (2024)
Elven Steel Ore Sun Haven
CrossFit 101
The Sports Academy - 101 Glenwest Drive, Glen Carbon, Illinois 62034 - Guide
Dicks Mear Me
House For Sale On Trulia
La Fitness Oxford Valley Class Schedule
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6052

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.