A security failure in Crypto.com reportedly allowed attackers to bypass 2FA protections, leading to around $35 million in unauthorized withdrawals.
Major Security Incident Hits Crypto.com
Crypto.com experienced a large-scale theft affecting hundreds of customer accounts in a coordinated attack. Incorrectly designed login systems may unintentionally allow attackers to override or bypass security checks through malformed requests.
Estimated Losses Reach Tens of Millions
The incident involved unauthorized withdrawals of Bitcoin, Ethereum, and other digital assets, totaling approximately $35 million in value. Crypto.com stated it migrated to a new 2FA system and restored affected accounts after the incident.
Victims Report “Ghost Withdrawals”
Around 483 users reported transactions they did not initiate, indicating compromised account security. The platform added a 24-hour delay for new withdrawals and account changes to detect suspicious activity more effectively.
2FA System Failure at the Core
The attack reportedly involved bypassing or defeating two-factor authentication (2FA), a key security layer meant to prevent unauthorized logins.
Unclear Root Cause of the Breach
The company did not clearly explain whether 2FA codes were stolen, bypassed, or internally compromised during authentication.
Possible Ways 2FA Could Be Compromised
Security experts suggest multiple possibilities, including weak SMS authentication, stolen shared secrets, or server-side authentication flaws.
Insider Risk and Support Abuse Scenarios
Poor internal controls or compromised support workflows can sometimes allow attackers to reset accounts or bypass verification steps. Even strong security mechanisms like 2FA can fail if implementation, monitoring, or internal controls are weak.