Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

131–140 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#131
post #123
post #114

The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…

Didn't they say that 443 BTC was stolen? Isn't that around $200MM all by itself? Or did I miss a part of this?

$20MM

Re: Crypto.com accounts had unauthorized withdrawals

#132
post #103

Earlier quoted context omitted.

Its cliche, but it doesn’t really mean that crypto.com or any other crypto exchange isn’t on the hook for stolen funds. Crypto doesn’t mean regulation doesn’t apply or that companies are free from liability. Obviously you can’t squeeze blood from a stone if someone were to steal most of the funds from a crypto exchange (Mt. Gox comes to mind) But in the real world, if you use a crypto exchange in a reasonable locatio…

So in the real world when using a regulated crypto exchange, what's the point of a blockchain other than asset speculation (which can also be done through traditional trading instruments at this point)?

Good question. I only wanna add that traditional trading instruments suck and are not fun to scale. Highly centralized points of failure with truly mind numbing consequences that are difficult to predict and respond to. I've worked on forex systems and when the feeds get iffy things get real uncomfortable, real fast.

Blockchains could, maybe, provide an interesting global platform for fintech to migrate cross-border stuff to. That stuff is not reliable, the engineers are just hella talented

Re: Crypto.com accounts had unauthorized withdrawals

#133

Reminder that cliches are cliche for a reason: not your keys, not your crypto

They also said they've reimbursed all funds. So if you were hacked personally, you would be out money here, vs keeping it on their exchange where you would be made whole again.

That's not a fair comparison though. An exchange is a fat, juicy target. I am not

Re: Crypto.com accounts had unauthorized withdrawals

#134

Earlier quoted context omitted.

I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.

Based on them saying they migrated to a new 2FA system, I think it's the latter - they disabled the current 2FA option and required everyone to register a new 2FA method. > In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure.

What are the odds they migrated to a new 2FA system in a few days without introducing new, serious bugs?

Re: Crypto.com accounts had unauthorized withdrawals

#135

I am a cyber security consultant for startups. The first thing that I communicate is that just by not being in crypto you have drastically lowered your risk profile. Attackers care a lot about what they can get to if they are able to breach your security.

I do a bit of the same and this seems to be a silly thing to communicate as part of a security audit. Ok, step 1 SMB insurance company paying me to audit - by not being in Afghanistan, you have a severely reduced risk of business invasion and extortion. Seems like a really wonky way to communicate a risk profile and first-exposure to security professionals by a SMB. Plenty of SMBs with janky POS systems get pretty na…

I'm advising people at the executive level. They do not care about the details of hashing PII, they want to know how likely it is that they will be targeted and how likely that attack is to succeed. And the fact is that an insurance company gets targeted far less often than crypto companies.

Re: Crypto.com accounts had unauthorized withdrawals

#136
post #114

The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…

>From the announcement, it looks like Crypto.com is making the users whole again;

>> No customers experienced a loss of funds.

Let's believe that when we hear someone other than the company saying it.

> File a police report and provide a copy of it to Crypto.com

Yeah, I'm sure tons of crypto holders will get right on that.

Re: Crypto.com accounts had unauthorized withdrawals

#137
post #106
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

> Which seems more likely, that these "risk monitoring systems" actually caught this, or that they were inundated by sudden urgent calls from the 483 users saying "DUDE WTF WHERE'S MY MONEY?". For better or for worse, a lot of insight can be gained from a sudden influx of tickets from normally-quiet users, all with the same general story. This is definitely how many critical bugs in production are caught, because eve…

> But, most likely, they have metrics on average withdrawal amounts, deposit amounts, etc., hooked up to something like datadog, with an off-the-shelf anomaly detection monitor.

How are we estimating the likelihood here? I agree that would be desirable. I agree a very together company might have something like that. But given the average level of competence and professionalism in the cryptocurrency sector [1], I would not bet against EMM_386's theory in this case.

[1] See, e.g., https://web3isgoinggreat.com/ or https://bravenewcoin.com/insights/36-bitcoin-exchanges-that-...

Re: Crypto.com accounts had unauthorized withdrawals

#138
post #121
post #114

The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…

And so what are we going to do as a society with these stolen funds? Playing a wallet mixing tracking game is a rat race and a waste of energy, otherwise we need a centralized system [on an immutable blockchain] to keep track of stolen funds, to then cross-reference every transaction with at point of sale/transfer - to then prevent it, no? If not a centralized solution like above then what? We just allow stolen funds…

There's no centralized system to track stolen dollars (at least not in the sense you're talking about), so I don't know why crypto would necessarily need one.

Re: Crypto.com accounts had unauthorized withdrawals

#139
post #99
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

Responding to escalations from customer support is a risk monitoring system, just not a very good one.

[deleted]

Re: Crypto.com accounts had unauthorized withdrawals

#140
post #43

Earlier quoted context omitted.

I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.

yes, they literally logged everyone out, removed 2FA, and on the new login, users had to re-add 2FA

> users had to re-add 2FA

And you are not asked to do this while logging in again. It is assumed you know why you have to reauthenticate and that you have to re-add 2FA in your app settings…

Post reply on HN