{"id":16838,"date":"2022-01-20T14:33:28","date_gmt":"2022-01-20T13:33:28","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=16838"},"modified":"2022-01-20T14:33:36","modified_gmt":"2022-01-20T13:33:36","slug":"400-accounts-were-compromised-cryptocom-ceo","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/400-accounts-were-compromised-cryptocom-ceo\/","title":{"rendered":"400 user accounts were compromised &#8211; Crypto.com CEO"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\"><a href=\"https:\/\/coinscreed.com\/staging\/cryptocom-reportedly-loses-15-million-due-to-the-recent-compromise.html\" data-type=\"URL\" data-id=\"https:\/\/coinscreed.com\/staging\/cryptocom-reportedly-loses-15-million-due-to-the-recent-compromise.html\">Kris Marszalek  CEO of Crypto.com<\/a> confirmed on Bloomberg TV on Wednesday that 400 accounts were hacked earlier this week after several layers of the firm\u2019s security were breached. <\/h5>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"877\" height=\"544\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-151.png\" alt=\" 400 user accounts were compromised - Crypto.com CEO\" class=\"wp-image-16854\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-151.png 877w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-151-300x186.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-151-768x476.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-151-750x465.png 750w\" sizes=\"(max-width: 877px) 100vw, 877px\" \/><\/figure><\/div>\n\n\n\n<p>Crypto.com announced on Thursday that &#8220;4,836.26 ETH, 443.93 BTC, and about US$66,200 in other currencies&#8221; had been taken without permission from clients' accounts. According to the<a href=\"https:\/\/www.google.com\/search?q=400+user+accounts+were+compromised+-+Crypto.com+CEO&rlz=1C1SQJL_enNG889NG889&oq=400+user+accounts+were+compromised+-+Crypto.com+CEO&aqs=chrome..69i57.709j0j9&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=400+user+accounts+were+compromised+-+Crypto.com+CEO&rlz=1C1SQJL_enNG889NG889&oq=400+user+accounts+were+compromised+-+Crypto.com+CEO&aqs=chrome..69i57.709j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\"> current market value<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, the total loss is estimated to be roughly $33.8 million.<\/p>\n\n\n\n<p>Several Crypto.com users have complained that their money has been taken as a result of a security vulnerability. The company's past comments, however, have failed to allay fears.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"503\" height=\"582\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-152.png\" alt=\"\" class=\"wp-image-16855\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-152.png 503w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-152-259x300.png 259w\" sizes=\"(max-width: 503px) 100vw, 503px\" \/><\/figure>\n\n\n\n<p>According to the official statement, Crypto.com's risk monitoring systems discovered &#8220;unauthorized activity on a small number of user accounts&#8221; on Jan. 17, 2022, around 12:46 AM UTC, where transactions were authorized without the user entering the<a href=\"https:\/\/coinscreed.com\/staging\/opera-launches-the-first-blockchain-inclined-internet-browser.html\" data-type=\"post\" data-id=\"16837\"> 2FA authentication control<\/a>.<\/p>\n\n\n\n<p>As mentioned in the announcement, the exchange halted withdrawals and revoked all client 2FA tokens, as well as installing even more security hardening measures that required everyone to re-login and reactivate their 2FA token before enabling only approved action. For a total of 14 hours, the withdrawal infrastructure was unavailable.<\/p>\n\n\n\n<p>To prevent such an occurrence in the future, Crypto.com claims to have added an extra layer of safety, requiring a new whitelisted withdrawal address to be registered within 24 hours of the first withdrawal.<\/p>\n\n\n\n<p>Users will be notified when<a href=\"https:\/\/coinscreed.com\/staging\/binance-now-allows-direct-ethereum-layer-2-withdrawals.html\" data-type=\"post\" data-id=\"16598\"> withdrawal addresses <\/a>have been added, giving them enough time to react and respond, according to the statement.<\/p>\n\n\n\n<p>According to Bloomberg, Crypto.com CEO Kris Marszalek stated on Wednesday that the exchange has not received any communication from regulators regarding the incident. In addition to that, he said, <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cObviously, it\u2019s a great lesson, and we are continuously strengthening our infrastructure.\u201d<\/p><\/blockquote>\n\n\n\n<p>Over $15 million in ETH has been stolen, according to<a href=\"https:\/\/coinscreed.com\/staging\/3-2-million-eth-stolen-via-metadao-defi-protocol-rugpull.html\" data-type=\"post\" data-id=\"15690\"> PeckShield<\/a>. Half of the cash had been delivered to Tornado Cash &#8220;to be washed,&#8221; according to the blockchain security firm's tweet on Monday.<\/p>\n\n\n\n<p>The heist could have cost the exchange $33 million in stolen funds, according to another researcher from blockchain data firm OXT Research.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kris Marszalek CEO of Crypto.com confirmed on Bloomberg TV on Wednesday that 400 accounts were hacked earlier this week after several layers of the firm\u2019s security were breached. Crypto.com announced on Thursday that &#8220;4,836.26 ETH, 443.93 BTC, and about US$66,200 in other currencies&#8221; had been taken without permission from clients&#8217; accounts. According to the current [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":16854,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[6712,6711,5644,5817,6115],"class_list":["post-16838","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-breach-2","tag-ceo-2","tag-crypto-com-2","tag-hack-2","tag-hackers-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-151.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/16838","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=16838"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/16838\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/16854"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=16838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=16838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=16838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}