Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft

A security failure in Crypto.com reportedly allowed attackers to bypass 2FA protections, leading to around $35 million in unauthorized withdrawals. […]

Picture of Rafid Rafid

Rafid Rafid

Table of Contents

A security failure in Crypto.com reportedly allowed attackers to bypass 2FA protections, leading to around $35 million in unauthorized withdrawals.

Major Security Incident Hits Crypto.com

Crypto.com experienced a large-scale theft affecting hundreds of customer accounts in a coordinated attack. Incorrectly designed login systems may unintentionally allow attackers to override or bypass security checks through malformed requests.

Estimated Losses Reach Tens of Millions

The incident involved unauthorized withdrawals of Bitcoin, Ethereum, and other digital assets, totaling approximately $35 million in value. Crypto.com stated it migrated to a new 2FA system and restored affected accounts after the incident.

Victims Report “Ghost Withdrawals”

Around 483 users reported transactions they did not initiate, indicating compromised account security. The platform added a 24-hour delay for new withdrawals and account changes to detect suspicious activity more effectively.

2FA System Failure at the Core

The attack reportedly involved bypassing or defeating two-factor authentication (2FA), a key security layer meant to prevent unauthorized logins.

Unclear Root Cause of the Breach

The company did not clearly explain whether 2FA codes were stolen, bypassed, or internally compromised during authentication.

Possible Ways 2FA Could Be Compromised

Security experts suggest multiple possibilities, including weak SMS authentication, stolen shared secrets, or server-side authentication flaws.

Insider Risk and Support Abuse Scenarios

Poor internal controls or compromised support workflows can sometimes allow attackers to reset accounts or bypass verification steps. Even strong security mechanisms like 2FA can fail if implementation, monitoring, or internal controls are weak.

Reading progress
0%
Share this article
Facebook
Twitter
LinkedIn
WhatsApp

🔥 Trending This Week

Top 5 Reasons You Lose Control of Your Android Phone (Before You Even Realize It)

Serious Security: OpenSSL fixes “error conflation” bugs – how mixing up mistakes can lead to trouble

Serious Security: Linux full-disk encryption bug fixed – patch now!

Serious Security: How to make sure you don’t miss bug reports!

Scroll to Top