Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

271–280 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#271
post #7

Earlier quoted context omitted.

Presumably they mostly stole ETH because tornado cash is the best mixer around to launder stolen funds

I'd love to read more about these money laundering operations like Tornado Cash. Are they just straight up 100% fraud companies? Do they have any pretense of a legitimate use case or does everyone just understand they're used for criminal activity? Are they regulated at all? I assume you have to trust your magic beans to them at some point; do the money launderers sometimes just steal them? What do they charge for th…

It requires users to pay gas fees when making deposits, as well as for the services that "obfuscate" the withdrawals. Thats the payment. You trust that the nodes will obfuscate the transactions to receive the fees. The rest is basic smart contracts execution.

The compliance topic is tricky and deceptive. Only the user with a "Note" is able to link deposit and withdrawal. With this note the user can generate a proof of origin. This makes tornado cash compliant enough.

E.G. If the withdrawal address is under Money laundry suspicion, it may be urged to provide the origin of the transaction. That is possible [1] but there is no way of a 3rd party to Tag an account as "suspicious" based on the Tornado chain information (due to the obfuscation done by the Nodes that are getting the fees).

As far as I understand there is no accountability. The regulators would have to persecute all the nodes for helping out with the laundry. But there is no way for the nodes to know they're participating in laundry. So they cant be persecuted. Regulations needs to be invented for this kind of schema.

Please someone correct me if I said anything wrong. Im not an expert is just my conclusion based on some reading.

[1]: https://tornadocash.eth.link/compliance/

Re: Crypto.com accounts had unauthorized withdrawals

#272

Earlier quoted context omitted.

I would argue that by you giving the torch to crypto.com as the company that caters to casual users that "just wanna invest and get rich", it is indeed one of the apexes of the industry. A product successfully marketing a fringe and specialized technology to the average consumer is just that.

Is it? I'm not sure of numbers of total accounts but anyone who knows anything about crypto is suspicious of crypto.com as a platform and I don't know anyone who uses it when things like coinbase are available. They just bought an expensive URL and spammed a bunch of ads. If that makes them the apex of the industry I guess CALL THE GENERAL AND SAVE SOME TIME is the apex of the car insurance industry.

The two car insurance companies I see the most adverts from are State Farm and Geico - and yes, it looks like those two are the apex of their industry: https://www.valuepenguin.com/largest-auto-insurance-companie...

Re: Crypto.com accounts had unauthorized withdrawals

#273

Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…

> Set up an anti-phishing code

I believe this is a system where you give a website something that you will recognize (I've seen small images used as well as text) that they agree to display to you in their layout. It is supposed to make building convincing phishing websites harder, as the attackers cannot know what content a given user has sent to the service.

Re: Crypto.com accounts had unauthorized withdrawals

#274

Earlier quoted context omitted.

Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.

> If i had a account there, i wouldn't allow them to use my money to cover this. They're...not going to ask your permission? If you have an account there, they have a large central pile of assets, and a database row saying that you are entitled to X amount of those assets. Someone else has a database row saying that they are entitled to Y amount of those assets. If someone breaks into the other account, and makes an…

Ok, i get it now.

Re: Crypto.com accounts had unauthorized withdrawals

#275
post #10

Earlier quoted context omitted.

> For context, this is the startup that has been using Matt Damon as it’s face. They're also notable lately for getting the naming rights to the (former) Staples Center. > https://en.wikipedia.org/wiki/Crypto.com_Arena

I wouldn't call it a startup, it paid 700mil$ to rename an arena!

Having been around on the first dotcom boom, renaming an arena is an extremely startup thing to do if you've raised a huge amount of money.

Re: Crypto.com accounts had unauthorized withdrawals

#276

Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…

> Set up an anti-phishing code I believe this is a system where you give a website something that you will recognize (I've seen small images used as well as text) that they agree to display to you in their layout. It is supposed to make building convincing phishing websites harder, as the attackers cannot know what content a given user has sent to the service.

What stops the attacker from fetching the image or text?

Re: Crypto.com accounts had unauthorized withdrawals

#277
post #264

Earlier quoted context omitted.

The whole thing is really unclear, but it sounds like if they are hacked and you lose funds, they will only reimburse you if you file a police report... even though they would know if you lost funds, and only they would know the circumstances and have any evidence. I wouldn't touch crypto.com with a very long barge pole...

The police report is probably due to their insurance, but it is odd that they would need individual police reports for each account.

It's probably at least partly to discourage you from making false loss claims. Lying on a police report is a crime.

Re: Crypto.com accounts had unauthorized withdrawals

#278

Earlier quoted context omitted.

Calling crypto.com anything near "apex of the cryptocurrency industry" is a very broad lie. Crypto.com is for people who just "wanna invest in crypto and get rich", others who are actually involved in the space (developers, companies and others) are nowhere near crypto.com as they have proven time and time again they are not serious about anything, even the basics like security.

I would argue that by you giving the torch to crypto.com as the company that caters to casual users that "just wanna invest and get rich", it is indeed one of the apexes of the industry. A product successfully marketing a fringe and specialized technology to the average consumer is just that.

This is a common play in several industries. Art of Shaving markets itself well to casual people interested in traditional shaving products but they take regular products, mark them up by a lot, rebrand and then upsell. Nobody claims Art of Shaving is the apex of shaving. Best Buy does similar marketing in regard to electronics, but Best Buy certainly isn't the apex of electronics retailers. What makes you think cryptocurrency companies would be any different?

Re: Crypto.com accounts had unauthorized withdrawals

#279

Boy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withd…

I wouldn't be surprised if "reimbursing" is just updating a number on their database and hoping customers won't immediately withdraw.

Re: Crypto.com accounts had unauthorized withdrawals

#280
post #276

Earlier quoted context omitted.

> Set up an anti-phishing code I believe this is a system where you give a website something that you will recognize (I've seen small images used as well as text) that they agree to display to you in their layout. It is supposed to make building convincing phishing websites harder, as the attackers cannot know what content a given user has sent to the service.

What stops the attacker from fetching the image or text?

In this case you set the anti-phishing code in your account settings (arbitrary string). Then they include it in all email comms (in the top right of the email body). So if you get an email from what looks like "Crypto.com", but with a different anti-phishing code - then you can be certain that it's phishing.
Post reply on HN