Yes. Crypto.com confirmed a security incident that began on January 17, 2022. Its later incident figures identified 483 affected users and about $33.8 million in unauthorized withdrawals, valued at the time of the incident. Crypto.com said it blocked many withdrawals and reimbursed the remaining affected customers. The event is historical—not a newly confirmed 2026 breach—and the public account does not establish exactly how attackers got transactions approved.
What happened in the Crypto.com breach?
Crypto.com detected unauthorized activity on January 17, 2022, and suspended withdrawals while it investigated. Withdrawals resumed on January 18 after the company added security measures, according to contemporaneous reporting. On January 19, CEO Kris Marszalek publicly described roughly 400 compromised accounts. The more detailed figures reported the next day put the total at 483 users. The initial number was an estimate; 483 was the later incident-report figure. TechCrunch reported the CEO’s initial acknowledgment, and BleepingComputer reported the later figures.
| Incident detail | Reported figure |
|---|---|
| Affected users | 483 |
| Ether withdrawn | 4,836.26 ETH |
| Bitcoin withdrawn | 443.93 BTC |
| Other currencies | About $66,200 |
| Total value | About $33.8 million at the incident-time valuation |
The dollar total is the reported value at the time, not a current-market valuation of those assets. Coverage sometimes rounded the loss to $34 million or $35 million; the company’s reported total was approximately $33.8 million.
Did customers lose money?
Unauthorized withdrawals did occur, but Crypto.com said most were prevented and that all remaining affected customers were reimbursed. That describes the company’s response to this incident; it is not a promise that every future loss on the platform will be covered. Any account-protection programme has its own current eligibility rules, exclusions, geography and limits. Crypto.com’s security guidance describes the programme and its conditions, which may change: Crypto.com security best practices.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Was Crypto.com’s 2FA broken?
The company said its monitoring systems detected transactions being approved without users entering the required 2FA control. That supports describing the event as an account and transaction-approval security failure, but it does not establish that the authenticator algorithm itself was cryptographically broken. The public incident materials do not identify a confirmed phishing, SIM-swap, database, device, session, recovery, or internal-system cause. Contemporaneous reporting on the 2FA issue and response does not resolve the precise attack path.
Two-factor authentication remains useful: it adds a layer beyond a password. It is not a complete defense if an attacker compromises a device, tricks someone into revealing a code, exploits account recovery, or reaches an already authenticated session. Protect the email account and device tied to an exchange account as well as the exchange login itself.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What to do if you suspect account access now
If you see an unfamiliar transaction, withdrawal address, login, or security change, act through the official app or manually entered Crypto.com domain—not a link in an unsolicited email, text, search ad, or social-media message. Crypto.com says its customer service is available around the clock for security and phishing cases; use its official support route: Crypto.com’s phishing and security guidance.
- Contact Crypto.com promptly. Report suspected unauthorized access and ask support to secure or lock the account. If you are locked out, do not open a second account because a social-media responder tells you to.
- Secure your linked email account. Change its password to a unique one, sign out unknown sessions, inspect forwarding rules, and enable strong MFA. Change any reused Crypto.com password too.
- Reset Crypto.com 2FA using the app. Current app instructions list Settings → Security → 2-Factor Authentication → Reset 2FA. If you cannot complete the reset, Crypto.com directs users to its 2FA reset guidance and chat.crypto.com. Remove the old authenticator entry after the reset and enable the new one promptly.
- Review account activity. Check transaction history, withdrawal addresses, devices, and any API keys or access you do not recognize. Do not approve an unfamiliar address change. If the account offers a lock feature, use it while you work with support.
- Freeze a Crypto.com Visa Card if needed. Use the app’s card controls if the card is lost or exposed; the company’s security guidance recommends freezing a lost card.
- Preserve evidence. Save timestamps, screenshots, emails, wallet addresses, transaction hashes, device details, and support-ticket numbers. If funds were sent, report the incident to law enforcement and relevant financial authorities where appropriate. A report may help an investigation, but it cannot guarantee recovery; blockchain transfers may be irreversible.
Watch for fake support and recovery scams
A reported breach can prompt secondary fraud. Be suspicious of messages claiming to arrange reimbursement, reset 2FA, verify your account, or recover stolen crypto—especially if they create urgency or ask you to move funds. Crypto.com says it will not request your password, MFA security code, private key, or recovery phrase. Anyone asking for a recovery phrase or authenticator code is not legitimate support, whatever logo or account name they use. Never install remote-access software at a stranger’s direction or pay an upfront “recovery” fee.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
To check whether a communication channel is official, Crypto.com provides Crypto.com Verify. You can also configure an anti-phishing code so genuine platform emails display a code you chose. Current app instructions place this under Settings → Security → Anti-Phishing Code; Exchange interface labels may differ. See the company’s guides for the App and Exchange.
Which account protections are useful?
Crypto.com’s current help and security materials describe several controls. Availability and labels can vary by product, region, and app version, so check the interface you use.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Authenticator-app 2FA: Current setup guidance describes TOTP codes that expire after 30 seconds. They are stronger than password-only access, but can still be exposed through phishing or a compromised device. Setup instructions: Crypto.com App 2FA.
- Passkeys or security keys, where supported: These can resist conventional phishing better because authentication is tied to the legitimate site or app. Plan for device loss and account recovery; a method is only practical if you can recover access securely.
- Withdrawal-address protections: A delay before the first withdrawal to a newly added address can provide time to catch an unauthorized change. It will not protect a withdrawal to an address already trusted, so review address changes and keep available protections enabled.
- Account lock and verification tools: Crypto.com’s security materials describe an account-lock feature and Crypto.com Verify for checking official channels. Consult the current Crypto.com security page and help materials for the controls available to your account.
For the 2022 response, Crypto.com revoked customer 2FA tokens, required users to sign in again and set up 2FA, added security hardening, and introduced a 24-hour delay between adding a withdrawal address and the first withdrawal to it. The company also announced an account-protection programme. Those steps document its response then; they do not prove that the same programme, terminology, coverage, or eligibility applies to every user today.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Does the 2022 incident mean Crypto.com is unsafe today?
The incident is evidence of a serious historical security failure and demonstrates why users should not treat 2FA or a reimbursement statement as a guarantee. By itself, it does not establish the platform’s current security posture. A sound decision should consider your own risk tolerance, the controls available for your product and location, current account terms, and how much exposure you are comfortable keeping with any single service. Moving assets elsewhere is a personal risk-management choice, not a conclusion compelled by this 2022 incident alone.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For U.S. readers, do not assume ordinary bank-deposit insurance or securities-investor protections automatically cover cryptocurrency held on an exchange. Crypto.com’s reimbursement statement for this incident, a contractual account-protection programme, and statutory protections are distinct; applicable rules depend on the asset, product, account and jurisdiction.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




