01Summary
On January 17, 2022, Crypto.com detected unauthorized activity on 483 user accounts. The attackers had bypassed the platform's two-factor authentication (2FA) to approve withdrawals without user authorization. Approximately $30 million worth of Ethereum (ETH) and Bitcoin (BTC) were stolen. Crypto.com temporarily suspended all withdrawals to contain the breach and later restored services with enhanced security. The company fully reimbursed all affected users. The breach was significant because it targeted a major cryptocurrency exchange that was widely used and had previously marketed its strong security credentials.
02Background
Crypto.com was one of the world's largest cryptocurrency exchanges, with millions of users. The platform had invested heavily in marketing and security, including high-profile sponsorships. The breach damaged its reputation as a secure platform.
03Key revelations
- 012FA protections on a major crypto exchange could be bypassed.
- 02483 user accounts were compromised in a coordinated attack.
- 03Crypto.com's security reputation was significantly damaged.
04Technical analysis
The attackers exploited a vulnerability in Crypto.com's withdrawal approval process, bypassing the 2FA requirement. The specific technical details of the exploit were not fully disclosed by Crypto.com. The attack did not involve compromise of Crypto.com's core wallet infrastructure, suggesting the attackers exploited a logic or session management flaw.
- Attack vector
- 2FA bypass / Withdrawal process vulnerability
- Attack method
- Unauthorized cryptocurrency withdrawals
- Initial access
- Session manipulation or logic flaw
- Exfiltration
- Cryptocurrency transfer from user accounts
Vulnerabilities exploited
- Withdrawal process vulnerability (2FA bypass)
05Threat actor
The perpetrator(s) behind the Crypto.com hack remain unidentified. The sophistication of the 2FA bypass suggests a well-organized criminal group with significant technical capabilities.
Attribution sources
- Crypto.com Disclosure
- Media Reports
- Blockchain Analysis
06Victims and impact
Additional victims
- 483 User Accounts
Countries affected
- Global
07Data exposed
Data types
- Cryptocurrency (ETH, BTC)
08Financial damage
$30M stolen; Crypto.com fully reimbursed users.
09Timeline
- 2022-01-17Attackers bypass 2FA and withdraw ~$30M from 483 Crypto.com accounts.
- 2022-01-18Crypto.com suspends withdrawals and discloses the breach.
- 2022-01-20Crypto.com resumes full operations with enhanced security.
10Reaction and fallout
Public reaction
The breach caused significant concern among cryptocurrency holders and raised questions about the security of centralized exchanges.
Political impact
The incident was cited by regulators as evidence of the risks of centralized cryptocurrency platforms.
11Legal
No arrests were reported. Crypto.com faced regulatory scrutiny in Singapore.
12Aftermath
Security improvements
- Crypto.com implemented enhanced withdrawal verification procedures.
- Mandatory delays on high-value withdrawals introduced.
13Significance and legacy
Significance
The Crypto.com breach was one of the highest-profile cryptocurrency exchange hacks of 2022, demonstrating that even platforms with strong security marketing could be vulnerable.
Legacy
The incident highlighted the ongoing security challenges facing centralized crypto exchanges and the importance of robust withdrawal protections.
14Disclosure and media
- Authentication
- Crypto.com disclosure and blockchain analysis
Publishing organisations
- Crypto.com
15Field notes
- 01Crypto.com had recently paid $700M for the naming rights to the Los Angeles Staples Center.
- 02The 483 affected accounts were a tiny fraction of Crypto.com's 10M+ user base, but the $30M theft was still massive.
16Resolution
Crypto.com reimbursed all affected users, enhanced security protocols, and restored full services.
17Sources
Official documents
- Crypto.com post-incident report
References
- [1]Crypto.com disclosure (Jan 2022)
- [2]Media reports (Reuters, CoinDesk)









