Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

81–90 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#81

Reminder that cliches are cliche for a reason: not your keys, not your crypto

They also said they've reimbursed all funds. So if you were hacked personally, you would be out money here, vs keeping it on their exchange where you would be made whole again.

Re: Crypto.com accounts had unauthorized withdrawals

#82
post #51

Earlier quoted context omitted.

Maybe, but I think you can make a case for the opposite too. Without exchanges, there'd be no crypto. Exchanges are the only reason 99% of people who have crypto can figure out how.

Especially with mobile devices taking over. An increasing number of people don't even have a laptop or desktop to hold a whole blockchain on. Even an iPhone 13 Pro with 1TB of storage would lose 10-20% of its space to that. That isn't going to improve. The more popular it gets, the faster it grows, and it would compete with all the other storage needs that also grow. Get someone to load up and maintain a whole blockc…

Not everyone needs a full copy of the blockchain to run a node.

A pruned full node downloads and validated all blocks, then discard everything not relevant to its own wallet.

A variety of “light clients” are also available for most chains, which fetch transaction data from peers as needed (usually using something like bloom filters to increase privacy).

Most ethereum apps just go through Infura. That’s a horrible centralized single point of failure that I’m not advocating, but the point is there are many ways a wallet app can connect to a remote full node.

Re: Crypto.com accounts had unauthorized withdrawals

#84
post #43

Earlier quoted context omitted.

yes, they literally logged everyone out, removed 2FA, and on the new login, users had to re-add 2FA

Wouldn't this also allow an attacker to add his own 2FA?

Doesn’t really matter if your 2FA keygen algo got completely compromised.

Re: Crypto.com accounts had unauthorized withdrawals

#85

Earlier quoted context omitted.

Time to play the classic crypto exchange game: hack or exit scam? Disabling 2FA in this scenario is dumb enough to raise the question of malfeasance of the part of this theft.

Somehow I doubt a fraudulent company on the verge of an exit scam would spend $700 million to rename an arena right before pulling the plug. Incompetent? Probably. Fraudulent? Unlikely. https://www.latimes.com/business/story/2021-11-16/crypto-sta...

The Houston Astros played at Enron Field until Enron was revealed to be a criminal enterprise and several of its leaders went to prison. The world has a short memory, it seems.

Re: Crypto.com accounts had unauthorized withdrawals

#86
post #10

Earlier quoted context omitted.

> For context, this is the startup that has been using Matt Damon as it’s face. They're also notable lately for getting the naming rights to the (former) Staples Center. > https://en.wikipedia.org/wiki/Crypto.com_Arena

They took out huge ads in Vegas for re:invent. Personally that set my alarm bells off pretty badly.

Yeah, seeing huge marketing spend by an organisation that's not a massive brand with deep pockets always makes me wonder where the money is coming from

Re: Crypto.com accounts had unauthorized withdrawals

#88
post #21
post #12

> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…

That was exactly my question when I read this. How do they establish trust, when 2FA is revoked? How they prevent that the bad guy enables now 2FA and the god guy is locked out of his account? May the god guy didn't get the message that Crypto.com had an issue, because s/he is unavailable.

My thought is maybe they didn’t really do 2FA, but exploited a password reset mechanism that only required 2FA?

IE: single factor resets, so a compromised “2FA” was actually keys to the kingdom?

But you’d think the attacker would need access to a user’s email or some such then.

Re: Crypto.com accounts had unauthorized withdrawals

#90
post #12

> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…

I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.

crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it.

But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it.

Anyone know how the do auth on the app?

For users in the US there is no way to change the password, because the webapp (which might have that feature) is not allowed to be used from US.

Once I asked how to change password and support said I can change the PIN on phone and dont worry your funds are safe.

Post reply on HN