Crypto.com Hack
Incident Overview
Crypto.com's user accounts were breached, bypassing the 2FA authentication control, and leading to the theft of ETH, BTC, and other currencies.
On 17 January 2022, unauthorized activity was detected on a few user accounts on Crypto.com. Transactions were being approved without the 2FA authentication control being inputted by the user. This led to an immediate investigation, during which all withdrawals on the platform were suspended. The impacted accounts were fully restored, and all customer 2FA tokens were revoked. Additional security measures were put in place, requiring all customers to re-login and set up their 2FA token. The withdrawal infrastructure was down for approximately 14 hours.
Stolen funds:
- 4,836.26 ETH
- 443.93 BTC
- $66,200 in other currencies
The stolen funds were deposited into a Tornado Cash mixer.
The attacker's address:
https://etherscan.io/address/0x6e1218c5…d29d3d
The transaction behind the attack:
https://bloxy.info/txs/calls_from/0x6e1218c5…d29d3d?signature_id=994162&smart_contract_address_bin=0x722122df…5b6967
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Crypto.com, these are the critical security checks that could have prevented this incident (January 2022).
- Verify all logic paths related to Private Key Compromised (Unknown Method) / Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$34.4M
Net Loss
0
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
-
01
Source 1 https://rekt.news/cryptocom-rekt/
- 02
- 03
Learn to Prevent the Next Crypto.com
The Crypto.com hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.