Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

91–100 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#91
post #12

> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…

I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.

Based on them saying they migrated to a new 2FA system, I think it's the latter - they disabled the current 2FA option and required everyone to register a new 2FA method.

> In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure.

Re: Crypto.com accounts had unauthorized withdrawals

#92
post #51

Earlier quoted context omitted.

Maybe, but I think you can make a case for the opposite too. Without exchanges, there'd be no crypto. Exchanges are the only reason 99% of people who have crypto can figure out how.

Especially with mobile devices taking over. An increasing number of people don't even have a laptop or desktop to hold a whole blockchain on. Even an iPhone 13 Pro with 1TB of storage would lose 10-20% of its space to that. That isn't going to improve. The more popular it gets, the faster it grows, and it would compete with all the other storage needs that also grow. Get someone to load up and maintain a whole blockc…

Agreed. And even if the storage issue isn't the main blocker, there's also energy usage, bandwidth, security and usability issues when it comes to phones.

Re: Crypto.com accounts had unauthorized withdrawals

#94

I assume they have SMS as a 2FA option and that was the weak link?

> SMS as a 2FA option

I hope not, if that is true.

The year is 2022 and companies managing >$100B in assets are STILL using SMS 2FA for protecting their life savings, despite SIM hijacking and SIM swapping still about.

Quite pathetic really.

Re: Crypto.com accounts had unauthorized withdrawals

#95

Earlier quoted context omitted.

Time to play the classic crypto exchange game: hack or exit scam? Disabling 2FA in this scenario is dumb enough to raise the question of malfeasance of the part of this theft.

Somehow I doubt a fraudulent company on the verge of an exit scam would spend $700 million to rename an arena right before pulling the plug. Incompetent? Probably. Fraudulent? Unlikely. https://www.latimes.com/business/story/2021-11-16/crypto-sta...

No, that's normal pyramid scam behavior. I would say it was more likely that they were fraudulent if they were escalating their meaningless promo gestures to keep anybody from cracking as their scam gets too big to keep together. The bigger the risk, the bigger the colorful gesture.

I'm imagining it as '$700 million IN CRYPTO, which is of course better than money'. For a name: which could easily be restored if it turns out the payment is worthless. But that's just my fantasy of how this might have gone on.

If it's $700 million in real money that only underscores how desperate they are to make some colorful gesture.

Re: Crypto.com accounts had unauthorized withdrawals

#96
> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact.

I sometimes find it hard to believe these statements, but I guess I can only take them at face value.

Which seems more likely, that these "risk monitoring systems" actually caught this, or that they were inundated by sudden urgent calls from the 483 users saying "DUDE WTF WHERE'S MY MONEY?".

Re: Crypto.com accounts had unauthorized withdrawals

#97
post #75

Earlier quoted context omitted.

Technically, they agreed to pay $700M over 20 years for arena naming rights -- no idea what the deal actually looks like but if you flat-line it, they're "only" paying $35M/year. Which is still a ton of money but much more reasonable in terms of cash out the door for a startup.

I hope this doesn't mean we have to endure 20 years of this name on the nba court. With all this gambling (sports betting) sponsoring of the NBA and now these crypto sponsors, it really does look like the NBA has sold out (also new trikot sponsor deals). It's a shame how much they feast on hooking impressionable men on gambling. Actually, thinking about it, there should be more ads for f2p/mobile games, would fit per…

You'll have to endure it if you believe that Crypto.com will exist 20 years from now. I'd bet even money they won't exist in 5 years and the court is renamed in ~3 years.

I mostly agree on the gambling front too - gambling was bad enough when you had to lure people to a casino but at least that gave them the excuse of "It's my form of entertainment, it's like going to a nightclub."

"The best minds of my generation are thinking about how to make people click ads" -- not any more! Now they're trying to find the shortest distance between users' wallets and their RSUs. On the plus side, they can use all of the targeting and persuasion techniques that have been used to make TikTok/Instagram so addictive on directly separating users from their money. Forget selling a product!

Re: Crypto.com accounts had unauthorized withdrawals

#98
post #21
post #12

> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…

That was exactly my question when I read this. How do they establish trust, when 2FA is revoked? How they prevent that the bad guy enables now 2FA and the god guy is locked out of his account? May the god guy didn't get the message that Crypto.com had an issue, because s/he is unavailable.

Given that apparently their previous system simply allowed login/payments without the configured mandatory 2FA, per their statements about the root cause of the issue, this may have been a move of desperation...

Re: Crypto.com accounts had unauthorized withdrawals

#99
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

Responding to escalations from customer support is a risk monitoring system, just not a very good one.

Re: Crypto.com accounts had unauthorized withdrawals

#100

Earlier quoted context omitted.

Wouldn't this also allow an attacker to add his own 2FA?

Doesn’t really matter if your 2FA keygen algo got completely compromised.

Of course it matters. Even if we assume someone figured out how to own the 2FA system, that knowledge doesn't magically make its way into the brain of every script kiddy capable of credential stuffing a login form. They're two totally different vectors with different surface area.
Post reply on HN