{"id":56074,"date":"2022-01-18T09:57:22","date_gmt":"2022-01-18T07:57:22","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=56074"},"modified":"2025-09-04T04:40:22","modified_gmt":"2025-09-04T01:40:22","slug":"analysts-report-crypto-com-hack-company-denies-loss-of-funds","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/analysts-report-crypto-com-hack-company-denies-loss-of-funds\/","title":{"rendered":"Analysts report Crypto.com hack; company denies loss of funds"},"content":{"rendered":"<p>On 17 January, the Crypto.com cryptocurrency platform suspended withdrawals due to &#8216;suspicious activity&#8217; on user accounts. The company assured that customers&#8217; funds are safe, but PeckShield analysts say the incident involved a hacking attack in which more than $15 million was stolen.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">The <a href=\"https:\/\/twitter.com\/cryptocom?ref_src=twsrc%5Etfw\">@cryptocom<\/a> loss is about $15M with at least 4.6K ETHs and half of them are currently being washed via <a href=\"https:\/\/twitter.com\/TornadoCash?ref_src=twsrc%5Etfw\">@TornadoCash<\/a> <a href=\"https:\/\/t.co\/PUl6IrB3cp\">https:\/\/t.co\/PUl6IrB3cp<\/a> <a href=\"https:\/\/t.co\/6SVKvk8PLf\">https:\/\/t.co\/6SVKvk8PLf<\/a> <a href=\"https:\/\/t.co\/XN9nmT857j\">pic.twitter.com\/XN9nmT857j<\/a><\/p>\n<p>\u2014 PeckShield Inc. (@peckshield) <a href=\"https:\/\/twitter.com\/peckshield\/status\/1483246262371557378?ref_src=twsrc%5Etfw\">January 18, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cSeveral users reported suspicious activity on their accounts; in the near future we will suspend withdrawals, as our team conducts an investigation. All funds are safe,\u201d Crypto.com wrote.<\/p>\n<\/blockquote>\n<p>A few hours later, users <a href=\"https:\/\/twitter.com\/cryptocom\/status\/1483050866894868484?s=20\">were asked<\/a> to log back into their accounts and reset their two-factor authentication (2FA).<\/p>\n<p>Around 19:00 MSK, Crypto.com\u2019s chief executive <a href=\"https:\/\/twitter.com\/Kris_HK\/status\/1483106015755182083?s=20\">Kris Marshalek<\/a> said that technical specialists were conducting final checks \u2014 the withdrawal function <a href=\"https:\/\/twitter.com\/cryptocom\/status\/1483132559530029061?s=20\">was restored<\/a> about an hour and a half later.<\/p>\n<p>According to Marshalek, the downtime lasted roughly 14 hours. The CEO stressed that customer funds were not lost, and the team had taken steps to bolster the infrastructure.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Some thoughts from me on the last 24 hours:<\/p>\n<p>\u2014 no customer funds were lost <br \/>\u2014 the downtime of withdrawal infra was ~14 hours <br \/>\u2014 our team has hardened the infrastructure in response to the incident<\/p>\n<p>We will share a full post mortem after the internal investigation is completed.<\/p>\n<p>\u2014 Kris | Crypto.com (@Kris_HK) <a href=\"https:\/\/twitter.com\/Kris_HK\/status\/1483277350683185155?ref_src=twsrc%5Etfw\">January 18, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Nevertheless, PeckShield specialists say hackers withdrew 4,600 ETH (about $15.05 million at the current rate). At the time of writing, the address <a href=\"https:\/\/etherscan.io\/address\/0x6e1218c55f1acb588fc5e55b721f1183d7d29d3d\">address<\/a>, which Etherscan labelled as belonging to the attacker, holds 1.17 ETH \u2014 the remainder of the assets have been sent to the Tornado Cash mixer.<\/p>\n<p>CertiK also reported a Crypto.com breach. The startup&#8217;s analysts claim that more than 282 users were affected \u2014 4,836 ETH were withdrawn from their accounts (~$15.82 million).<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/SkyTrace?src=hash&#038;ref_src=twsrc%5Etfw\">#SkyTrace<\/a> Analysis <\/p>\n<p>Using SkyTrace, we can see that the hacker is moving the stolen funds to Tornado Cash<\/p>\n<p>Check it out yourself using this link \ud83d\udc47<a href=\"https:\/\/t.co\/hgWz2TU0NA\">https:\/\/t.co\/hgWz2TU0NA<\/a> <a href=\"https:\/\/t.co\/1pO9NuakRN\">pic.twitter.com\/1pO9NuakRN<\/a><\/p>\n<p>\u2014 CertiK Security Leaderboard (@certikorg) <a href=\"https:\/\/twitter.com\/certikorg\/status\/1483278628997713924?ref_src=twsrc%5Etfw\">January 18, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Users also reported losses; one user allegedly had more than 17 ETH stolen.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">My wife had 17.43 ETH wiped within minutes without her authorization. She has 2FA. She is in panic mode. We tried contacting the chat but no help.<\/p>\n<p>\u2014 Yugesh Bhattarai (@yougesify) <a href=\"https:\/\/twitter.com\/yougesify\/status\/1482950885651087361?ref_src=twsrc%5Etfw\">January 17, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Earlier, Crypto.com <a href=\"https:\/\/u1f987.com\/en\/news\/crypto-com-expands-insurance-coverage-to-750-million\">announced an increase in the insured coverage for user assets<\/a> to $750 million. The program is implemented in partnership with Arch Underwriting \u2014 a Lloyd\u2019s market participant.<\/p>\n<p>Back in January 2022, hackers <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-siphon-18-million-from-animoca-brands-lympo-platform\">drained from hot wallets of the sports NFT platform Lympo<\/a> assets worth $18.2 million.<\/p>\n<p>Read ForkLog&#8217;s bitcoin news on our <a href=\"\/\/telegram.me\/forklog\" target=\"\u201c_blank\u201d\" rel=\"\u201cnofollow\u201d noopener\">Telegram<\/a> \u2014 crypto news, prices and analytics.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On 17 January, the Crypto.com platform suspended withdrawals due to &#8216;suspicious activity&#8217; on user accounts. The company assured that customers&#8217; funds are safe, but PeckShield analysts say the incident involved a hacking attack in which more than $15 million was stolen.<\/p>\n","protected":false},"author":1,"featured_media":56075,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1452],"class_list":["post-56074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-crypto-com"],"aioseo_notices":[],"amp_enabled":true,"views":"25","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/56074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=56074"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/56074\/revisions"}],"predecessor-version":[{"id":56076,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/56074\/revisions\/56076"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/56075"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=56074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=56074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=56074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}