ZeroHour
Security Affairspublished ()ingested @securityaffairs

A small number of Crypto.com users reported suspicious activity on their wallets

mediumVulnerabilityimportance 30
Full article316 words · extracted from securityaffairs.com · click to collapse

Several Crypto.com users reported suspicious transactions that stole thousands of dollars in Ethereum (ETH) from their wallets.

Several Crypto.com users reported suspicious transactions that stole thousands of dollars in Ethereum (ETH) despite their accounts being protected with 2FA.

https://twitter.com/BENBALLER/status/1482955116416172033

Yes my account shows multiple withdrawals of .17 BTC

— mohamed qudah (@qudah_mohamed) January 17, 2022

My wallet was just hacked. .27 bitcoin withdraws 7 times in my account. WTH is going on?

— Nick D (@NickDushko) January 17, 2022

Crypto.com is a cryptocurrency exchange app based in Singapore, the app currently has 10 million users and 3,000 employees.

The company has confirmed the unauthorized access to wallets belonging to a ‘small number’ of users.

2/2
This update will be rolled out to users progressively over the next few hours.

Once complete, withdrawals will be re-enabled.

We understand this may be an inconvenience, but security comes first.

Thank you for your support.

— Crypto.com (@cryptocom) January 17, 2022

In response to the users’ reports of suspicious transactions, the company temporarily suspended all withdrawals and launched an internal investigation.

The cryptocurrency exchange app now has restored withdrawal services and reassured its users saying that all funds are safe:

Update: Withdrawal services have been restored.
All funds are safe.

It will take time to clear the backlogs. We appreciate your patience. https://t.co/ZKMfyTMebi

— Crypto.com (@cryptocom) January 17, 2022

The company did not provide details about the attack either the exact amount of stolen funds from the compromised wallets. It is not clear how the attackers were able to bypass two-factor authentication (2FA), if confirmed they have exploited some vulnerabilities in the platform.

Crypto.com users have to monitor their balance and report to the company any suspicious transaction. Experts also recommend enabling both 2FA and Face ID/Touch ID to protect their accounts from unauthorized access.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Crypto.com)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/126847/hacking/crypto-com-fraudulent-transactions.html