Earlier quoted context omitted.
I'd love to read more about these money laundering operations like Tornado Cash. Are they just straight up 100% fraud companies? Do they have any pretense of a legitimate use case or does everyone just understand they're used for criminal activity? Are they regulated at all? I assume you have to trust your magic beans to them at some point; do the money launderers sometimes just steal them? What do they charge for th…
tornado.cash is a legitimate service, that happens to be used by hackers that steal ethereum. Check out their code on github.
Crypto.com accounts had unauthorized withdrawals
161–170 of 321 posts
Re: Crypto.com accounts had unauthorized withdrawals
#162The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…
> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…
Re: Crypto.com accounts had unauthorized withdrawals
#163Earlier quoted context omitted.
This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol
Calling crypto.com anything near "apex of the cryptocurrency industry" is a very broad lie. Crypto.com is for people who just "wanna invest in crypto and get rich", others who are actually involved in the space (developers, companies and others) are nowhere near crypto.com as they have proven time and time again they are not serious about anything, even the basics like security.
EDIT: They're #3 (bigger than Coinbase). Only OKX and Binance are bigger[1].
Re: Crypto.com accounts had unauthorized withdrawals
#164Thank goodness it's decentralized and there are no single points of failure.
How is this a single point of failure? The issue was limited to a subset of users keeping funds in a Crypto.com wallet. Unless by "it" you mean crypto.com and not Ethereum. Crypto.com is not decentralized.
Re: Crypto.com accounts had unauthorized withdrawals
#165Earlier quoted context omitted.
This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol
Calling crypto.com anything near "apex of the cryptocurrency industry" is a very broad lie. Crypto.com is for people who just "wanna invest in crypto and get rich", others who are actually involved in the space (developers, companies and others) are nowhere near crypto.com as they have proven time and time again they are not serious about anything, even the basics like security.
Re: Crypto.com accounts had unauthorized withdrawals
#166Earlier quoted context omitted.
Wouldn't this also allow an attacker to add his own 2FA?
This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol
Re: Crypto.com accounts had unauthorized withdrawals
#167Re: Crypto.com accounts had unauthorized withdrawals
#168Earlier quoted context omitted.
> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…
Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.
It s not each of the user individually seeing their balance go down, it s the company lying even more about its ability to liquidate all accounts.
Your number on their html page they graciously present to you will go unchanged. It s not a new phenomenon, every bank does it, except crypto.com does it to pay losses for a theft while banks would do it to lend to a baker buying a bakery on mortgage. If said baker screws up and cant repay, and many more others as well, clients cant all withdraw the pretty number.
Another interesting difference is that a bank pays you for lending to them with your savings account, at market rate (very low these days), while I dont think crypto ponzis do because you re suppose to just wait and moon.
Re: Crypto.com accounts had unauthorized withdrawals
#169Earlier quoted context omitted.
I do a bit of the same and this seems to be a silly thing to communicate as part of a security audit. Ok, step 1 SMB insurance company paying me to audit - by not being in Afghanistan, you have a severely reduced risk of business invasion and extortion. Seems like a really wonky way to communicate a risk profile and first-exposure to security professionals by a SMB. Plenty of SMBs with janky POS systems get pretty na…
I'm advising people at the executive level. They do not care about the details of hashing PII, they want to know how likely it is that they will be targeted and how likely that attack is to succeed. And the fact is that an insurance company gets targeted far less often than crypto companies.
Edit: For the downvotes, if this is such an obvious question then be proactive and share the metrics - I'm skeptical this is the case but happy to be proved wrong.