Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

221–230 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#221
Act I: Matt Damon, looking out over the face of his space empire…”the Future belongs to the Brave”

Act II: thousands of men and women sign up to be brave with semi-retired Jason Bourne.

Act III: “we regret to inform you that our security protocols are a disaster”.

Re: Crypto.com accounts had unauthorized withdrawals

#222

Earlier quoted context omitted.

> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…

Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.

> Please explain how they can use the money from other people account to cover the losses.

Once it enters their hands, the money isn't really “from” a particular account in any tangible way.

> If i had a account there, i wouldn't allow them to use my money to cover this.

An account is just a record of funds to which you are entitled; there are certain types of relations where someone keeping money for you legally needs to keep it segregated from other funds of theirs, but crypto.com doesn't have that kind of relationship with account holders. If they don't provide you with your funds when you ask, you can try legal action to recover it, but you don't have a veto on whether they update the entry recording someone else's balance to make them whole after a hack, even if that increases the risk that they won't have your money when you want to withdraw it.

Re: Crypto.com accounts had unauthorized withdrawals

#223

I am a cyber security consultant for startups. The first thing that I communicate is that just by not being in crypto you have drastically lowered your risk profile. Attackers care a lot about what they can get to if they are able to breach your security.

Eh, yes of course, what are you saying really? Is there some deeper point I miss? Just like finance companies have a different risk profile than companies generating bingo cards, crypto companies have different risk profiles than other non-financial ones. Are people arguing that this is not true or something?

Crypto companies have a different risk profile than most finance companies.

For most finance companies, if they have a whoopsie and lose money to a software boo-boo, they'll just reverse the transaction. Times when such a transaction cannot be reversed (https://www.bloomberg.com/news/articles/2021-03-19/citigroup...) are the extremely rare exception, and are adjudicated by a civil court.

Whereas if a crypto company has their wallets breached, it's almost certainly immediately irreversible.

Re: Crypto.com accounts had unauthorized withdrawals

#224

It seems to me that while banning crypto by western governments is politically untenable, a better way would be to have their security services keep hacking it to make it unattractive

...It's totally politically tenable if it's nigh impossible to wrangle necks to wring to hold service providers accountable. What? Do you think Principles of System Architecture are completely absent in the public space?

Why do you think everything tends to centralize? To keep things localizable.

...Until that backfires anyway. Thank you 2008.

Re: Crypto.com accounts had unauthorized withdrawals

#225

Earlier quoted context omitted.

Eh, yes of course, what are you saying really? Is there some deeper point I miss? Just like finance companies have a different risk profile than companies generating bingo cards, crypto companies have different risk profiles than other non-financial ones. Are people arguing that this is not true or something?

People generally don't understand how vast the difference is. The pro crypto narrative has pushed the idea that "Blockchain is more secure" because "it cannot be edited" when in reality that feature makes it much more of a target for attackers because once they transfer the coins the transfer cannot be edited. In comparison if an attacker gets a credit card that card could be disabled and or have transactions cancell…

> In comparison if an attacker gets a credit card that card could be disabled and or have transactions cancelled.

That's why attackers never go after credit card numbers, right?

I think non-revertible payments do not really make a big difference to attackers, it just makes value extraction more efficient. Some percentage of fraudulent transactions will always make it through. So long as the funds accessible to the attacker are sufficiently large, it's still a juicy target. 10% of 200 megadollars is still 20 megadollars.

I agree with @capableweb2. They're an attractive target because they are a financial company with control over lots of value, not because of anything to do with cryptocurrencies in particular.

Re: Crypto.com accounts had unauthorized withdrawals

#227
post #208

Earlier quoted context omitted.

This... Is literally how banks work.

Banks do not work this way. Banks have insurance policies, both private and federal, that would cover the losses.

> Banks do not work this way

Yes, they do.

> Banks have insurance policies, both private and federal, that would cover the losses.

The federal insurance policy covers you if, after operating this way (or for some other reason) the bank ends up without money to cover your account (and, the regulation that comes with the insurance means that it's more likely that the Federal government will force the sale of your bank to one that does have extra money to cover your account even before that happens.)

But banks still operate as described (and using some of their pool of assets to buy private insurance is functionally the same as just adjusting the balances of people it is compensating for losses and increasing risk to others by doing so, except it smooths things a bit over time at the expense of higher average cost.)

Re: Crypto.com accounts had unauthorized withdrawals

#228

Earlier quoted context omitted.

Calling crypto.com anything near "apex of the cryptocurrency industry" is a very broad lie. Crypto.com is for people who just "wanna invest in crypto and get rich", others who are actually involved in the space (developers, companies and others) are nowhere near crypto.com as they have proven time and time again they are not serious about anything, even the basics like security.

I would argue that by you giving the torch to crypto.com as the company that caters to casual users that "just wanna invest and get rich", it is indeed one of the apexes of the industry. A product successfully marketing a fringe and specialized technology to the average consumer is just that.

Is it? I'm not sure of numbers of total accounts but anyone who knows anything about crypto is suspicious of crypto.com as a platform and I don't know anyone who uses it when things like coinbase are available. They just bought an expensive URL and spammed a bunch of ads. If that makes them the apex of the industry I guess CALL THE GENERAL AND SAVE SOME TIME is the apex of the car insurance industry.

Re: Crypto.com accounts had unauthorized withdrawals

#229
post #8

It has been painfully admitted. But you know what I am going to say if you're storing your crypto life-savings or JPEGs on an exchange: Not your keys, Not your coins and certainly not your NFTs.

I love hove cryptocurrency people are also discovering what we anti-cloud people have been shouting from the rooftops for years.

Re: Crypto.com accounts had unauthorized withdrawals

#230

It's almost like we need a centralized authority that can undo these withdrawals and a know your customer paper trail.

Funny that, ain't it? Perhaps we could Automate it. It'd be like.. a house for clearing transactions.

Nah... Probably never catch on.

Post reply on HN