How did hackers bypass 2FA during the $35 million Crypto.com hack?

Share This Post

As the dust settles on the recent Crypto.com hack, observers wonder how thieves managed to crack security procedures to steal millions in crypto.

Crypto.com has not released precise details on how hackers managed to bypass security. But, the incident raises doubts about the effectiveness of two-factor authentication (2FA).

Crypto.com targetted in $35 million hack

Last week, Crypto.com CEO Kris Marszalek said an “unauthorized activity” event had occurred. At the time, he reported no user funds were lost during the incident.

Crypto.com shut down withdrawals and began investigating suspicious activity to combat the breach. Full service was then resumed within 14 hours.

Despite initial claims that no user funds were lost, users and third parties, including blockchain security firm Peckshield, said unauthorized withdrawals had happened.

Since then, following its investigations into the matter, Crypto.com has released a report of its findings. It shows hackers managed to steal around $35 million of cryptocurrency, mainly consisting of Ethereum. The firm was keen to stress that affected users were reimbursed for their losses.

“The incident affected 483 Crypto.com users.

Unauthorised withdrawals totalled 4,836.26 ETH, 443.93 BTC and approximately US$66,200 in other cryptocurrencies.”

The report added that hackers were able to get withdrawals approved without 2FA codes being inputted by the user.

“risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user.”

Is two-factor authentication safe?

2FA is a security system that requires two separate, distinct forms of identification to access or action something. It is meant to stop unauthorized activity even if the account password is compromised.

There are various types of 2FA, including single-use code sent by SMS to phone or time-based one-time passwords generated by a phone authentication app.

While 2FA seems secure at face value, it is not infallible for many reasons. To begin with, hackers can still gain account access through phishing attacks, account recovery procedures, and malware.

There is also the issue of intercepting SMS codes. This is possible through tricking phone networks into transferring the victim’s number to a new SIM card.

Although phone authentication apps are more secure than SMS codes, reports exist of malware copying and sending codes to hackers.

Crypto.com did not go into detail on how hackers managed to bypass 2FA. It’s unknown whether the fault lies with 2FA or a flaw in Crypto.com’s security protocol regarding 2FA.

Nonetheless, enabling and using 2FA remains good practice.

The post How did hackers bypass 2FA during the $35 million Crypto.com hack? appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Crypto Rally Expected In Q4 2024 With ‘Exceptionally High’ Chances: Analyst

Bitcoin’s (BTC) breakout above $65,000 could lead to ‘exceptionally high’ chances for a wider crypto rally in Q4 2024, according to Markus Thielen, head of research at 10x Research

Dogecoin To The Moon? Trading Guru Sees A Bullish Breakout on the Horizon—Here’s Why

Veteran commodity trader Peter Brandt recently drew attention to Dogecoin (DOGE), the largest meme-based cryptocurrency by market capitalization, suggesting a potential bullish breakout Brandt shared

5 Best Cheap Cryptocurrencies to Buy Under 1 Dollar September 27 – Notcoin, Nervos Network, Bonk, SATS

The Crypto Fear & Greed Index, a popular tool for assessing market sentiment in the crypto industry, reached 61 on September 27, marking a slight

SEC May Appeal Ripple Case, Says Journalist—Senate Candidate Joins The Debate

The ongoing legal saga between Ripple Labs and the US Securities and Exchange Commission is heating up again as speculation mounts about a potential appeal from the SEC This comes after Judge Analisa

Putin: Russia Examining Digital Currencies for Independent Payments

Vladimir Putin highlighted that Russia is examining the use of national digital currencies to implement an independent and supranational alternative payment system However, he also outlined the

Bitcoin Set For Biggest September Gains In A Decade: Here’s Why

Bitcoin (BTC) looks poised to record its best September in a decade, surging past $65,000 This uncharacteristic price appreciation could be attributed to several key factors Reasons Behind