UPDATED 22:30 EST / JANUARY 20 2022

SECURITY

Crypto.com admits more than $34M was stolen from customer accounts

Fast-growing cryptocurrency exchange Crypto.com has admitted that over $34 million in cryptocurrency was stolen following unknown attackers successfully accessing user accounts.

In a blog post today, Crypto.com said that the hack affected 483 users. Unauthorized withdrawals totaled 4,836.26 Ethereum, 443.93 bitcoin and about $66,200 in other cryptocurrencies.

The attack started on Jan. 17 and involved unauthorized activity on a small number of user accounts where transactions were being approved without two-factor authentication by users. Crypto.com noted that the activity triggered an immediate response, with all withdrawals on the platform suspended for the duration of the investigation.

Any accounts found to have been affected by the theft of funds have had their holdings immediately restored.

Crypto.com revoked all customer 2FA and added additional security hardening measures as a precaution. Those included requiring all customers to log in again and set up their 2FA token to ensure only authorized activity would occur.

Additional security measures include a mandatory 24-hour delay between registration of a new whitelisted withdrawal address and first withdrawal. Crypto.com users will receive notifications that a withdrawal address has been added, to give them time to react and respond.

The company also undertook a full audit of its entire infrastructure, with several improvements implemented to harden their security posture further. As is typical when a hack has occurred, Crypto.com also hired third-party security firms to perform additional security checks.

Crypto.com didn’t stop there. The company has also introduced what it calls the “Worldwide Account Protection Program,” which offers additional protection and security for user funds held by Crypto.com. WAPP is designed to protect user funds in cases where a third party gains unauthorized access to their account and withdraws funds without the user’s permission. WAPP restores funds up to $250,000 for qualified users.

The response by Crypto.com to the seeming hack is positive. It ticks every conceivable box and then some more, such as with the WAPP program. But that said, what’s still missing is the how the funds were stolen.

It’s one thing to respond proactively to a hack, but without transparency on how it occurred, it could be suggested that Crypto.com is hiding something.

“Infamous bank robber Willie Sutton is frequently quoted as saying, ‘I rob banks because that’s where the money is,'” Neil Jones, cybersecurity evangelist at enterprise file synchronizing and sharing company Egnyte Inc., told SiliconANGLE. “In 2022, the technical environment has evolved to, ‘I rob cryptocurrency exchanges because that’s where the money is.'”

“I’m actually more surprised by the number of users who had their money pilfered, nearly 500 according to published reports, rather than the $30 million+ that was stolen,” Jones noted.

Jones said that the major lessons from this security breach include the importance of 2FA, the need for a current and road-tested incident response plan, and the need for end-users to be notified promptly and accurately when cyberattacks take place to help protect brand reputation.

Image: Crypto.com

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU