Crypto.com accounts had unauthorized withdrawals
111–120 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#112Earlier quoted context omitted.
They might be alluding to the removal of centralized authorities that would have otherwise been able to get that money back.
The allude from my naive point of view is that n_time thinks we're lucky the network is decentralized and that users are spread out over various wallet software and services, so the impact of the issue was only related to a sub-section of the network as a whole. But I might just misunderstand the sarcasm or something.
Re: Crypto.com accounts had unauthorized withdrawals
#113Earlier quoted context omitted.
I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.
crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it. Anyone know how the do auth on the app? For users in the US there is no way to…
If you're speaking from experience as a user of their service, I strongly suggest that you use a different exchange. Gemini + Coinbase both have very easy-to-understand authentication systems. If you don't understand the authentication system, that's a good red-flag that you should take as a reason to move to a more trustable platform.
(Just my two cents, as someone who works on authentication system architecture design.)
Re: Crypto.com accounts had unauthorized withdrawals
#114Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less.
From the announcement, it looks like Crypto.com is making the users whole again;
> No customers experienced a loss of funds.
This means that (in some cases) Crypto.com was on the hook for much more than $71k / user. The WAPP appears to put a series of conditions on the user, and introduce an upper limit to the amount that Crypto.com will return in the future.
> WAPP restores funds up to USD$250,000 for qualified users; terms & conditions apply.
> Enable Multi-Factor Authentication (MFA) on all transaction types where MFA is currently available,
> Set up an anti-phishing code at least 21 days prior to the reported unauthorized transaction,
> Not be using jailbroken devices,
> File a police report and provide a copy of it to Crypto.com; and
> Complete a questionnaire to support a forensic investigation.
This looks more like a mechanism to limit Crypto.com's exposure to future events than it does a policy to protect users.
Re: Crypto.com accounts had unauthorized withdrawals
#115Reminder that cliches are cliche for a reason: not your keys, not your crypto
Re: Crypto.com accounts had unauthorized withdrawals
#116Thank goodness it's decentralized and there are no single points of failure.
How is this a single point of failure? The issue was limited to a subset of users keeping funds in a Crypto.com wallet. Unless by "it" you mean crypto.com and not Ethereum. Crypto.com is not decentralized.
I believe in bitcoin, works well and I don't blame the consumer for the producer's problems when it comes to power.
But exchanges have become a key part of the implementation.
That's not the real issue though. The issue is the _need_ for exchanges. They provide a host of services, mostly all of which are antithetical to the loftier ideals espoused by bitcoin.
Too many crypto fans waltz passed this glaringly obvious issue and these kinds of stories will never go away as a result.
If banks get hacked, nobody blames the internet. "a small sub section of the system" applies as aptly to the blockchain as it does the global financial system, and I'm pretty confident being a locally popular trading commodity amongst edge communities is not the central goal for bitcoin
Re: Crypto.com accounts had unauthorized withdrawals
#117> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…
How am I supposed to read it: is it a 2FA compromise (attacker replaced 2FA codes with their own) or 2FA bypass (attacker found a way to conduct a transaction bypassing a need for 2FA)? These are two very different scenarios.
Re: Crypto.com accounts had unauthorized withdrawals
#118By the numbers, around $34 million in funds is affected, mostly Ethereum. They say in the press release that they prevented most of the unauthorized withdrawals and reimbursed the remainder, but it’s unclear how much they had to pay for reimbursements. For context, this is the startup that has been using Matt Damon as it’s face.
> For context, this is the startup that has been using Matt Damon as it’s face. They're also notable lately for getting the naming rights to the (former) Staples Center. > https://en.wikipedia.org/wiki/Crypto.com_Arena
I doubt it's very cheap to advertise in F1. You need to outbid large competitors.
Re: Crypto.com accounts had unauthorized withdrawals
#119By the numbers, around $34 million in funds is affected, mostly Ethereum. They say in the press release that they prevented most of the unauthorized withdrawals and reimbursed the remainder, but it’s unclear how much they had to pay for reimbursements. For context, this is the startup that has been using Matt Damon as it’s face.
Presumably they mostly stole ETH because tornado cash is the best mixer around to launder stolen funds
Re: Crypto.com accounts had unauthorized withdrawals
#120> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…
I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.