How did hackers bypass 2FA during the $35 million Crypto.com hack?

2022-1-28 23:00

As the dust settles on the recent Crypto.com hack, observers wonder how thieves managed to crack security procedures to steal millions in crypto.

Crypto.com has not released precise details on how hackers managed to bypass security. But, the incident raises doubts about the effectiveness of two-factor authentication (2FA).

Crypto.com targetted in $35 million hack

Last week, Crypto.com CEO Kris Marszalek said an “unauthorized activity” event had occurred. At the time, he reported no user funds were lost during the incident.

Crypto.com shut down withdrawals and began investigating suspicious activity to combat the breach. Full service was then resumed within 14 hours.

Despite initial claims that no user funds were lost, users and third parties, including blockchain security firm Peckshield, said unauthorized withdrawals had happened.

Since then, following its investigations into the matter, Crypto.com has released a report of its findings. It shows hackers managed to steal around $35 million of cryptocurrency, mainly consisting of Ethereum. The firm was keen to stress that affected users were reimbursed for their losses.

“The incident affected 483 Crypto.com users.

Unauthorised withdrawals totalled 4,836.26 ETH, 443.93 BTC and approximately US$66,200 in other cryptocurrencies.”

The report added that hackers were able to get withdrawals approved without 2FA codes being inputted by the user.

“risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user.”

Is two-factor authentication safe?

2FA is a security system that requires two separate, distinct forms of identification to access or action something. It is meant to stop unauthorized activity even if the account password is compromised.

There are various types of 2FA, including single-use code sent by SMS to phone or time-based one-time passwords generated by a phone authentication app.

While 2FA seems secure at face value, it is not infallible for many reasons. To begin with, hackers can still gain account access through phishing attacks, account recovery procedures, and malware.

There is also the issue of intercepting SMS codes. This is possible through tricking phone networks into transferring the victim’s number to a new SIM card.

Although phone authentication apps are more secure than SMS codes, reports exist of malware copying and sending codes to hackers.

Crypto.com did not go into detail on how hackers managed to bypass 2FA. It’s unknown whether the fault lies with 2FA or a flaw in Crypto.com’s security protocol regarding 2FA.

Nonetheless, enabling and using 2FA remains good practice.

The post How did hackers bypass 2FA during the $35 million Crypto.com hack? appeared first on CryptoSlate.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Emerald Crypto (EMD) на Currencies.ru

$ 0.0095806 (+7.58%)
Объем 24H $0
Изменеия 24h: 2.35 %, 7d: -7.78 %
Cегодня L: $0.0086651 - H: $0.0095806
Капитализация $183.154k Rank 1690
Доступно / Всего 19.117m EMD / 32m EMD

crypto hack did hackers 2fa bypass million

crypto hack → Результатов: 126


Crypto Week In Review: $60m Hack, Institutional Investor Launches Fund, Binance to Singapore

Throughout the past seven days, this up and coming industry saw its fair share of cases of development and maturation, as institutions have continued to pile onto this market. 15 Global Institutions Launch kLmgo SA Blockchain Platform Per a previous NewsBTC report, 15 of the world’s foremost institutions have joined hands to create komgo SA, an.

2018-9-23 15:16


Japan’s Zaif Crypto Exchange loses about $59.7 Million in Fresh Hack

The continuous news of hacking of cryptocurrency exchanges has grown this year when compared to previous years in the cryptocurrency industry. It started with Coincheck a cryptocurrency exchange in Japan where about $500 million worth of NEM token was stolen and now another cryptocurrency exchange in Japan, Zaif exchange in the news after a hack […] The post Japan’s Zaif Crypto Exchange loses about $59.7 Million in Fresh Hack appeared first on ZyCrypto.

2018-9-20 13:43


Фото:

$60 Million Bitcoin And Bitcoin Cash Stolen In Latest Japanese Exchange Hack

Japan, the home of cryptocurrency, or is it now the home of the cryptocurrency hack? Although Japan now has some of the tightest regulations surrounding the operations of cryptocurrency exchanges, it seems these regulations haven’t been enough to stop yet another devastating hack take place, this time, seeing around $60 million stolen in Bitcoin, Bitcoin Cash and MonaCoin from Tech Bureau owned Zaif.

2018-9-20 12:30


Bitcoin Gold (BTG) Gets Delisted By Bittrex Crypto Exchange Due To $18 Million Hack

Bittrex Exchange Removes Bitcoin Gold From Their Exchange Among cryptocurrency startup companies, the risk of theft, extortion, or major attack is very significant. The cryptocurrency community has always been especially susceptible to crime, because of the prevalence of technology-minded hackers in the markets, as well as the anonymous nature of cryptocurrencies in general. For these […]

2018-9-4 13:37


Фото:

Clients’ Funds Not Affected by Atlas Hack but Personal Data of More Than 260,000 Users Stolen

The cryptocurrency industry is a favorite target of cybercriminals. This time, it was the Brazilian crypto investment platform Atlas that was targeted and eventually breached by hackers. The good news is that funds of clients are reported to be safe, but the bad news is that personal information of around 260,000 platform users has been […] Clients’ Funds Not Affected by Atlas Hack but Personal Data of More Than 260,000 Users Stolen was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

2018-9-1 15:59


Brazilian Crypto Trading Platform Atlas Suffers Hack, 261,000 Users’ Personal Data Stolen

As reported by YouTube channel Investimentos Digitais, the data of over 200,000 investors has been stolen in a hack on Brazilian cryptocurrency trading platform Atlas Quantum. According to Have I Been Pwned, a data breach reporting website, 261,000 users had their data leaked, with information “including their names, phone numbers, email addresses and account balances.

2018-8-28 19:50


Фото:

North Korean Hackers Infiltrate Unnamed Crypto Exchange in First-Ever MacOS Hack

North Korea’s notorious cyber-hacking outfit, “Lazarus Group,” has reportedly deployed a MacOS-based malware to infiltrate cryptocurrency exchanges and applications, according to Kaspersky Labs. North Korean Attackers Strike To date, Lazarus remains an unknown entity, with no information on the number of individuals identifying with the outfit.

2018-8-25 07:00


Good News! Over $1 billion worth of Crypto to be Returned to victims of Mt.Gox Hack

An end has not come to the controversy that surrounded the first cryptocurrency exchange and the world’s largest holder of bitcoin trades as at 2014. Mt. Gox saga made way for the likes of Tim Draper and the Winklevoss twins Tyler and Cameron the cofounders of Gemini exchange to make good fortune through the stolen […] The post Good News! Over $1 billion worth of Crypto to be Returned to victims of Mt.Gox Hack appeared first on ZyCrypto.

2018-8-25 21:56


Monex Executive Wants to Keep Cryptocurrency’s Future Within Japan

Oki Matsumoto Wants To Keep Financial Future Of Cryptocurrencies Within Japan Monex broke into the crypto industry fast by acquiring Coincheck, which recently was threated by a hack. Their hope is that the companies that can use various technologies would essentially develop the center of the entire financial industry, ensuring secure transactions for every entity. […]

2018-8-23 22:11


John McAfee: Wiping off doubts regarding the recent Bitfi Wallet-hack claims

On 4th August, Nick Hellmann of the YouTube crypto-channel Learn Crypto broadcast an interview with the Founder of the McAfee Associations and a famous crypto influencer, John McAfee. Recently, much controversy has surrounded the cryptocurrency wallet as a bounty of $250,000 was set as a reward for anybody that could hack the wallet. John McAfee […]

2018-8-7 16:49