Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

261–270 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#261

Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…

The whole thing is really unclear, but it sounds like if they are hacked and you lose funds, they will only reimburse you if you file a police report... even though they would know if you lost funds, and only they would know the circumstances and have any evidence.

I wouldn't touch crypto.com with a very long barge pole...

Re: Crypto.com accounts had unauthorized withdrawals

#262

Earlier quoted context omitted.

Uniswap is one of the biggest exchanges and is fully decentralized. Things are trending that way.

Trending? Really?

Yes. A few years ago decentralized exchanges did not exist, now one of the largest exchanges is fully decentralized..Obviously simple payments could always be made in a decentralized way but creating actual applications wasn't possible until recently.

Re: Crypto.com accounts had unauthorized withdrawals

#263

Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…

> the withdrawal system allows for non-2fa when its enabled, but informs the risk system when it happens? what kind of feature is that?

I don't know about crypto.com but this is how binance does it. You can enable 2FA for everything or individually for specific actions such as logging in, withdrawals, etc. Lets everyone choose their security/inconvenience trade-off which I find reasonable.

> wtf is that? a PSK? a TOTP?

There is something similar on binance too. You set up some unique code on their website, every official email they send you will include that code as proof of authenticity. A weak form of signature I guess.

Re: Crypto.com accounts had unauthorized withdrawals

#264

Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…

The whole thing is really unclear, but it sounds like if they are hacked and you lose funds, they will only reimburse you if you file a police report... even though they would know if you lost funds, and only they would know the circumstances and have any evidence. I wouldn't touch crypto.com with a very long barge pole...

The police report is probably due to their insurance, but it is odd that they would need individual police reports for each account.

Re: Crypto.com accounts had unauthorized withdrawals

#265

Earlier quoted context omitted.

People generally don't understand how vast the difference is. The pro crypto narrative has pushed the idea that "Blockchain is more secure" because "it cannot be edited" when in reality that feature makes it much more of a target for attackers because once they transfer the coins the transfer cannot be edited. In comparison if an attacker gets a credit card that card could be disabled and or have transactions cancell…

> In comparison if an attacker gets a credit card that card could be disabled and or have transactions cancelled. That's why attackers never go after credit card numbers, right? I think non-revertible payments do not really make a big difference to attackers, it just makes value extraction more efficient. Some percentage of fraudulent transactions will always make it through. So long as the funds accessible to the at…

No they go after crypto bros because hacking banks is actually hard unlike these shady clowns based in Dubai or whatever.

Re: Crypto.com accounts had unauthorized withdrawals

#266

Earlier quoted context omitted.

> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…

Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.

This was the path Mt Gox went after they were hacked. Didn't work out so well for them in the end.

Re: Crypto.com accounts had unauthorized withdrawals

#268
post #96

> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can o…

If it's true, there's this funny situation where the exchange/banking software didn't require 2FA to withdraw funds, BUT their monitoring noticed this situation.

So their monitoring is smarter than their main application? Wow, just wow.

Re: Crypto.com accounts had unauthorized withdrawals

#269
post #253
post #232

I'm confused. Ostensibly the tradeoff for crypto is that only you know the secret factors that allow you to spend money, but there is no possibility of reversing a fraudulent transaction. If you give the keys to someone else, you lose the first condition, which was the benefit, but keep the second condition, which was the drawback. There was no reason to give anyone anyone else your keys!

There's no reason you cannot construct a token that can be frozen and reversed - USDT (other issues as side) being an example. Accounts as we know them don't have to be at the level of public address-private key but rather a smart contract as seen by Loopring. The difference is what was centralised is now decentralised, what was implicit and required trust is now explicit and requires formal verification.

USDC has a blacklist feature too. I don't think funds are reversed though, just frozen (my rough understanding)

Re: Crypto.com accounts had unauthorized withdrawals

#270

Earlier quoted context omitted.

Somehow I doubt a fraudulent company on the verge of an exit scam would spend $700 million to rename an arena right before pulling the plug. Incompetent? Probably. Fraudulent? Unlikely. https://www.latimes.com/business/story/2021-11-16/crypto-sta...

The Houston Astros played at Enron Field until Enron was revealed to be a criminal enterprise and several of its leaders went to prison. The world has a short memory, it seems.

What OP was referring to was a take-the-money-and-run plan where the company knows ahead of time that the whole thing is going to explode and causes it to on purpose.

My understanding is that Enron's leaders were caught in fraud and that led to the collapse of the company—they weren't planning on it collapsing, so the investment actually made sense in that case.

Post reply on HN