Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

101–110 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#101
post #99
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

Responding to escalations from customer support is a risk monitoring system, just not a very good one.

Worse, many companies can't even do that reliably.

Re: Crypto.com accounts had unauthorized withdrawals

#102

It seems to me that while banning crypto by western governments is politically untenable, a better way would be to have their security services keep hacking it to make it unattractive

Why would they not be doing both, if getting replaced as a money standard by an anarchist cybercurrency was an existential threat to these western governments?

Re: Crypto.com accounts had unauthorized withdrawals

#103

Reminder that cliches are cliche for a reason: not your keys, not your crypto

Its cliche, but it doesn’t really mean that crypto.com or any other crypto exchange isn’t on the hook for stolen funds. Crypto doesn’t mean regulation doesn’t apply or that companies are free from liability. Obviously you can’t squeeze blood from a stone if someone were to steal most of the funds from a crypto exchange (Mt. Gox comes to mind) But in the real world, if you use a crypto exchange in a reasonable locatio…

So in the real world when using a regulated crypto exchange, what's the point of a blockchain other than asset speculation (which can also be done through traditional trading instruments at this point)?

Re: Crypto.com accounts had unauthorized withdrawals

#104

Earlier quoted context omitted.

Time to play the classic crypto exchange game: hack or exit scam? Disabling 2FA in this scenario is dumb enough to raise the question of malfeasance of the part of this theft.

Somehow I doubt a fraudulent company on the verge of an exit scam would spend $700 million to rename an arena right before pulling the plug. Incompetent? Probably. Fraudulent? Unlikely. https://www.latimes.com/business/story/2021-11-16/crypto-sta...

Crypto.com is built on a huge marketing facade. Keeping that facade up until the moment the rug is pulled is the main part of the scam.

Re: Crypto.com accounts had unauthorized withdrawals

#105
post #94

I assume they have SMS as a 2FA option and that was the weak link?

> SMS as a 2FA option I hope not, if that is true. The year is 2022 and companies managing >$100B in assets are STILL using SMS 2FA for protecting their life savings, despite SIM hijacking and SIM swapping still about. Quite pathetic really.

These companies want more cash heavy users. Like those older than 50.

There is absolutely no way my parents could figure out 2fa in any way other than phone call/sms. They would be cutting out the less technical crowd, which is exactly who they're trying to convince to buy in

Re: Crypto.com accounts had unauthorized withdrawals

#106
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

> Which seems more likely, that these "risk monitoring systems" actually caught this, or that they were inundated by sudden urgent calls from the 483 users saying "DUDE WTF WHERE'S MY MONEY?".

For better or for worse, a lot of insight can be gained from a sudden influx of tickets from normally-quiet users, all with the same general story. This is definitely how many critical bugs in production are caught, because even a small number of disparate users that suddenly write in about the same issue is a huge red flag.

But, most likely, they have metrics on average withdrawal amounts, deposit amounts, etc., hooked up to something like datadog, with an off-the-shelf anomaly detection monitor.

Re: Crypto.com accounts had unauthorized withdrawals

#107

Earlier quoted context omitted.

They might be alluding to the removal of centralized authorities that would have otherwise been able to get that money back.

The allude from my naive point of view is that n_time thinks we're lucky the network is decentralized and that users are spread out over various wallet software and services, so the impact of the issue was only related to a sub-section of the network as a whole. But I might just misunderstand the sarcasm or something.

Well, traditional banking is much more decentralized in this sense, as there are many more banks than crypto exchanges, and the vast majority offer payment apps etc.

Re: Crypto.com accounts had unauthorized withdrawals

#109
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

Massive uptick in customer support tickets is technically a monitoring system. Just a highly reactionary one.
Post reply on HN