Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

181–190 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#183

Earlier quoted context omitted.

tornado.cash is a legitimate service, that happens to be used by hackers that steal ethereum. Check out their code on github.

I wonder what percentage of their total volume it is that “happens” to be used by hackers.

People who are not criminals deserve transaction privacy, as well.

Re: Crypto.com accounts had unauthorized withdrawals

#184

Earlier quoted context omitted.

Time to play the classic crypto exchange game: hack or exit scam? Disabling 2FA in this scenario is dumb enough to raise the question of malfeasance of the part of this theft.

Somehow I doubt a fraudulent company on the verge of an exit scam would spend $700 million to rename an arena right before pulling the plug. Incompetent? Probably. Fraudulent? Unlikely. https://www.latimes.com/business/story/2021-11-16/crypto-sta...

Not quite the same scale but the whole Color World 76ers thing is kind of in the same bucket?

Re: Crypto.com accounts had unauthorized withdrawals

#185
post #90

Earlier quoted context omitted.

I'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.

crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it. Anyone know how the do auth on the app? For users in the US there is no way to…

From my experience as a user, you don't have a password. They log you in via an email link, you have a PIN, and you have 2FA.

Re: Crypto.com accounts had unauthorized withdrawals

#186
post #114

The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…

> Not be using jailbroken devices

So does a normal PC count as a jailbroken device? If not, what makes having root access on a phone any different?

Re: Crypto.com accounts had unauthorized withdrawals

#187
post #10

Earlier quoted context omitted.

> For context, this is the startup that has been using Matt Damon as it’s face. They're also notable lately for getting the naming rights to the (former) Staples Center. > https://en.wikipedia.org/wiki/Crypto.com_Arena

I wouldn't call it a startup, it paid 700mil$ to rename an arena!

Since no one really knows how to define a "startup" then this whole discussion is basically moot.

https://news.ycombinator.com/item?id=11162052

Re: Crypto.com accounts had unauthorized withdrawals

#188
“Crypto.com will be releasing additional end-user security features as we move away from 2-Factor Authentication and to true Multi-Factor Authentication (MFA), providing added strength for our global user base.”

What does this mean? Does MFA means xFA for x > 2?

Re: Crypto.com accounts had unauthorized withdrawals

#189
post #114

The Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it lo…

Sure but exchanges have their own treasury, they make alotttt of money

Why lead with the ponzi assumption? There are so many more quantifiable assumptions

Re: Crypto.com accounts had unauthorized withdrawals

#190
post #77

Earlier quoted context omitted.

Wouldn't this also allow an attacker to add his own 2FA?

This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol

I'd say Coinbase is the company at the apex of the US cryptocurrency industry.

crypto.com is a two bit player in comparison.

Post reply on HN