On January 17, Crypto.com cryptocurrency platform suspended withdrawals due to “suspicious activity” on user accounts. The company assured that customer funds are safe, however, according to PeckShield analysts, this is a hacker attack, during which more than $15 million was stolen.
The @cryptocom loss is about $15M with at least 4.6K ETHs and half of them are currently being washed via @TornadoCash https://t.co/PUl6IrB3cp https://t.co/6SVKvk8PLf pic.twitter.com/XN9nmT857j
— PeckShield Inc. (@peckshield) January 18, 2022
“Several users have reported suspicious activity on their accounts, we will be suspending withdrawals shortly as our team investigates. All funds are safe,” wrote Crypto.com.
After a few hours of users asked Log in to your accounts and reset your two-factor authentication (2FA) settings.
At approximately 10:00 AM UTC, platform CEO Chris Marszalek toldthat the technicians carry out the last checks – the withdrawal function restored in an hour and a half.
Marszalek said the downtime was about 14 hours. The CEO emphasized that no client funds were lost and the team took steps to strengthen the infrastructure.
Some thoughts from me on the last 24 hours:
— no customer funds were lost
— the downtime of withdrawal infra was ~14 hours
— our team has hardened the infrastructure in response to the incidentWe will share a full post mortem after the internal investigation is completed.
– Kris | Crypto.com (@Kris_HK) January 18, 2022
Nevertheless, PeckShield experts claim that hackers withdrew 4600 ETH from the platform (~$15.05 million at the current exchange rate). At the time of writing, the address labeled by Etherscan as belonging to the attacker holds 1.17 ETH — the rest of the assets have been sent to the Tornado Cash mixer.
CertiK also reported that Crypto.com was hacked. Startup analysts claim that more than 282 users were affected during the incident — 4836 ETH (~$15.82 million) was withdrawn from their accounts.
#SkyTrace Analysis
Using SkyTrace, we can see that the hacker is moving the stolen funds to Tornado Cash
Check it out yourself using this link 👇https://t.co/hgWz2TU0NA pic.twitter.com/1pO9NuakRN
— CertiK Security Leaderboard (@certikorg) January 18, 2022
Clients of the platform also announced the loss of funds. So, more than 17 ETH was allegedly stolen from one of the users.
We have a small number of users reporting suspicious activity on their accounts.
We will be pausing withdrawals shortly, as our team is investigating. All funds are safe.
— Crypto.com (@cryptocom) January 17, 2022
Earlier, Crypto.com announced an increase in insurance coverage of users’ assets to $750 million. The program was implemented in partnership with Arch Underwriting, a member of the Lloyd’s insurance market.
Stay in touch! Subscribe to World Stock Market in Telegram.