Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsCrypto.com reported that unauthorized withdrawals were approved on January 17, 2022, without users entering the expected two-factor authentication (2FA) control. The company later said 483 users were affected and reported withdrawals worth $33,812,346 at the time. The precise technical method that let the transactions pass was not disclosed in the reporting reviewed, so “2FA bypass” describes the reported symptom—not an established explanation of the exploit.
What happened in the Crypto.com hack?
Crypto.com said its risk-monitoring systems detected unauthorized account activity on January 17, 2022. In a statement quoted by TechCrunch, the company said “transactions were being approved without the 2FA authentication control being inputted by the user.” That describes the failure customers experienced; it does not reveal how the attackers got around the control. TechCrunch’s January 20, 2022 report noted that the company had not disclosed the attack mechanism.
How much was taken, and how many users were affected?
Crypto.com reported 483 affected users and total unauthorized withdrawals of $33,812,346. The commonly used “$34 million” figure is a rounded description of the reported value at the time, not a current valuation.
| Asset | Amount reported | Incident-time value reported |
|---|---|---|
| Ethereum (ETH) | 4,836.26 ETH | $15,132,516 |
| Bitcoin (BTC) | 443.93 BTC | $18,613,630 |
| Other currencies | Not specified | About $66,200 |
| Total | — | $33,812,346 |
These are the incident figures Crypto.com disclosed in January 2022, as reported by BleepingComputer. They should not be read as the present-day value of the crypto assets.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How did attackers bypass Crypto.com 2FA?
The specific technical path remains publicly unexplained in the cited reporting. Crypto.com reported that transactions were approved without users entering 2FA, but the available account of the incident does not establish whether a software flaw, configuration error, compromised credential, outside provider, or another cause was responsible. Those possibilities should not be presented as findings.
How did Crypto.com respond?
The exchange halted withdrawals while it investigated. Reports put the interruption at about 14 hours. Crypto.com revoked customer 2FA tokens and told customers to log in and configure 2FA again. The company also said it had “revoked all customer 2FA tokens and added additional security hardening measures,” as reported by TechCrunch.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Changes to withdrawal and authentication controls
- New-address delay: Crypto.com added a mandatory 24-hour wait between registering a new withdrawal address and making the first withdrawal to it, giving account holders time to notice an unauthorized address change.
- Security review: The company said it engaged third-party security firms.
- Move toward MFA: Crypto.com said it planned to transition from 2FA toward multi-factor authentication (MFA). The cited reports do not establish the current status of that plan.
Were customers reimbursed?
Crypto.com said most unauthorized withdrawals were prevented and that all other affected customers were fully reimbursed. This is the company’s reported outcome; the cited coverage does not provide independent audit findings confirming individual reimbursements. BleepingComputer’s incident report attributes the outcome to Crypto.com.
What was Crypto.com’s account-protection program?
In January 2022, Crypto.com announced its Worldwide Account Protection Program (WAPP), which contemporaneous coverage described as offering up to $250,000 to qualified users under stated conditions. Reported requirements included MFA on eligible transaction types, an anti-phishing code set at least 21 days earlier, a police report, a questionnaire for a forensic investigation, and a device that was not jailbroken. These are historical reported terms; the cited sources do not establish whether WAPP is currently available or what its current terms are. See TechCrunch’s January 2022 coverage.
Rank #3
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the public record does—and does not—establish
The contemporaneous reports establish the incident date, the company’s reported figures, the observed 2FA failure, and the response measures it described. They do not establish the technical root cause or offer independent verification of individual reimbursements. In January 2022, Channel NewsAsia reported that Singapore’s Monetary Authority of Singapore (MAS) was aware of the incident and following up with Crypto.com’s applicant; it also said the operator was exempt from a Payment Services Act licence while its application was under review at that time. That is historical regulatory context, not a statement about Crypto.com’s current licensing status. Channel NewsAsia.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5C Nano is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C Nano secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: The YubiKey 5C Nano is designed to stay plugged into your device via USB-C. Simply tap it to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




