Live data from Hacker News

Crypto.com accounts had unauthorized withdrawals

crypto.com

281–290 of 321 posts

Re: Crypto.com accounts had unauthorized withdrawals

#281
post #113
post #90

Earlier quoted context omitted.

crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. But basically in this case, you didn't even need a password to log back in, it was just an email to click a link, then FaceId/PIN and logged in and prompt to re-add 2fa. The app must store the password itself somehow and auto use it. Anyone know how the do auth on the app? For users in the US there is no way to…

> crypto.com is a little mysterious when it comes to authentication honestly. I still have not understood it. If you're speaking from experience as a user of their service, I strongly suggest that you use a different exchange. Gemini + Coinbase both have very easy-to-understand authentication systems. If you don't understand the authentication system, that's a good red-flag that you should take as a reason to move to…

Agreed. As someone who has integrated with dozens of crypto bank APIs, I can tell you Gemini's authentication and security is top notch (second only to Fireblocks)

Re: Crypto.com accounts had unauthorized withdrawals

#282
post #103

Earlier quoted context omitted.

Its cliche, but it doesn’t really mean that crypto.com or any other crypto exchange isn’t on the hook for stolen funds. Crypto doesn’t mean regulation doesn’t apply or that companies are free from liability. Obviously you can’t squeeze blood from a stone if someone were to steal most of the funds from a crypto exchange (Mt. Gox comes to mind) But in the real world, if you use a crypto exchange in a reasonable locatio…

So in the real world when using a regulated crypto exchange, what's the point of a blockchain other than asset speculation (which can also be done through traditional trading instruments at this point)?

You need to send money to the hackers who ransomware'd your network. They don't accept SWIFT.

Re: Crypto.com accounts had unauthorized withdrawals

#284
post #220

Earlier quoted context omitted.

Tornado Cash is a smart contract system that allows you to send fixed denominations of Ethereum, and receive a cryptographic "note" that allows someone who knows the note to withdraw the same amount of Ethereum from the smart contract. Since zero-knowledge cryptography is used to ensure the generated note cannot be linked to the depositing transaction, it can be used to send money to yourself or another person withou…

Interesting! I’m surprised the regulated exchanges don’t blacklist coins connected to that smartcontract because of the ease of facilitating laundering.

Since all crypto on smart contract platforms tumbles around in defi and the various decentralized exchanges all the time, this would effectively prevent anyone from depositing their crypto to those exchanges, which would make the exchange unusable.

To expand on that, say someone withdraws ETH from Tornado cash and purchases an NFT with it. The seller of the NFT then swaps their ETH for USDC on a decentralized exchange (the ETH then goes into a pool). Later, a liquidity provider to the ETH/USDC pool withdraws liquidity from that pool, and sends their ETH to an exchange, let's say Binance. If Binance blocked such deposits (and especially if they did so without refunding the user on-chain), no one would use Binance, and they'd also be the target of a lot of lawsuits.

Re: Crypto.com accounts had unauthorized withdrawals

#285

Earlier quoted context omitted.

> No customers experienced a loss of funds. I mean, there's still plenty of money in other people's accounts they can use to cover the losses. Does anybody know whether the regulatory regime they operate under is sound? If a US bank lost this kind of customer money in a theft, I'd have some confidence that the the FDIC and the Federal Reserve would make sure they actually had all the money they were claiming they had…

Please explain how they can use the money from other people account to cover the losses. If i had a account there, i wouldn't allow them to use my money to cover this.

You're aware your bank (not crypto bank, just Bank of America or whatever competitor) uses your money to invest and doesn't just keep in into a vault, right?

Re: Crypto.com accounts had unauthorized withdrawals

#286

Earlier quoted context omitted.

I would argue that by you giving the torch to crypto.com as the company that caters to casual users that "just wanna invest and get rich", it is indeed one of the apexes of the industry. A product successfully marketing a fringe and specialized technology to the average consumer is just that.

This is a common play in several industries. Art of Shaving markets itself well to casual people interested in traditional shaving products but they take regular products, mark them up by a lot, rebrand and then upsell. Nobody claims Art of Shaving is the apex of shaving. Best Buy does similar marketing in regard to electronics, but Best Buy certainly isn't the apex of electronics retailers. What makes you think cryp…

I would say Best Buy is an apex electronics retailer. Why wouldn't you?

Re: Crypto.com accounts had unauthorized withdrawals

#287
post #77

Earlier quoted context omitted.

This is hilarious. This company is literally at the apex of the crypto industry and this is the kind of mistake they make. Yeah, immutable smart contracts written by their fellow proponents will also save the world lol

> This company is literally at the apex of the crypto industry Cryptocurrency was not even supposed to have these pseudobanks called exchanges leading this space. It wasn't even supposed to be an "industry". People were supposed to mine cryptocurrency on their own commodity hardware and use that to transact amongst themselves.

Almost like its core mission statement was only led by the voluntary virtuosity of its participants - and wasn't as novel as previously thought. Huh.

Re: Crypto.com accounts had unauthorized withdrawals

#288
post #208

Earlier quoted context omitted.

This... Is literally how banks work.

Banks do not work this way. Banks have insurance policies, both private and federal, that would cover the losses.

Banks might be protected under some federal legislation, but overall it doesn't really make much sense for any sizeable bank to insure themselves with some other party. For any non-rare event it's much easier to just keep some emergency money at hand. The only thing it'd make sense to insure themselves against are large scale damages that exceed the amount they can reasonably write off, but if the damages exceed the amount of funds a bank has readily available then there's little chance anyone else can cough up that amount of money other than the government.

Re: Crypto.com accounts had unauthorized withdrawals

#289
post #100

Earlier quoted context omitted.

Of course it matters. Even if we assume someone figured out how to own the 2FA system, that knowledge doesn't magically make its way into the brain of every script kiddy capable of credential stuffing a login form. They're two totally different vectors with different surface area.

My thought is that it’s not really 2FA, and 2FA means temporary tokens, and there’s a method to gain entry with just login+token, e.g. via password reset.

You can just make up whatever factors.

If you want to deliver security then MFA is an interesting strategy that needs careful consideration and planning, you might end up building things like Security Keys so as to solve real threats. You might fix real problems (Google eliminated phishing) at your organisation.

But if your goal is to bamboozle fools into giving you their real money in exchange for Itchy and Scratchy money that you may or may not then "lose" then you don't need all that hard work. Take whatever nonsense you cobbled together and say it's "Two factor" because that means "good" to people who don't know any better.

Re: Crypto.com accounts had unauthorized withdrawals

#290
post #12

> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open the…

Is anyone else getting the feeling from this press release that it seems they actually don't (yet?) know how their previous 2FA system was circumvented by the attackers?

If they knew, they'd share and talk about how they fixed it.

As a communications person, reading between the lines tell me they've got no idea what happened. Comforting!

Post reply on HN