Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

Crypto.com’s $34 Million Hack: What the 2FA Compromise Really Means

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Crypto.com confirmed that unauthorized withdrawals were approved without users entering the required two-factor authentication (2FA) control during an incident detected on January 17, 2022. The exchange reported that 483 users were affected and that withdrawals totaling approximately $33.8 million—commonly rounded to $34 million—were involved. Crypto.com said it stopped many transactions and fully reimbursed affected customers.

However, the company did not publicly disclose the precise technical exploit. “2FA compromise” accurately describes the observed security outcome, but it does not prove that attackers cracked authenticator codes or stole every victim’s 2FA secret.

The incident at a glance

Detail Reported information
Detection date January 17, 2022
Affected users 483
Ethereum withdrawn 4,836.26 ETH
Bitcoin withdrawn 443.93 BTC
Other assets Approximately $66,200
Contemporaneous value Approximately $33.8 million
Withdrawal suspension Approximately 14 hours
Customer reimbursement Crypto.com said all affected users were fully reimbursed

These figures come from Crypto.com’s incident disclosure and contemporary reporting. The dollar total was a valuation at the time, not a permanently fixed measure of the cryptocurrency involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Crypto.com’s incident report said that most unauthorized withdrawals were prevented and that the remaining affected users were reimbursed. Because this is the company’s own account, reimbursement should be attributed to Crypto.com rather than presented as an independently audited finding.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What happened?

  1. January 17: Crypto.com’s risk-monitoring systems detected unauthorized withdrawal activity at approximately 12:46 a.m. UTC, according to contemporary reproductions of the company’s statement.
  2. January 17–18: The exchange suspended withdrawals for about 14 hours while investigating and implementing security measures.
  3. January 19: CEO Kris Marszalek publicly acknowledged that customer accounts had been hacked and said affected customers had been reimbursed.
  4. January 20: Crypto.com published its incident report, including the number of affected users and the asset breakdown.

Crypto.com subsequently revoked existing customer 2FA tokens and required users to establish new ones. The exchange also introduced additional withdrawal controls.

Contemporary reporting from BleepingComputer provides the detailed timeline, figures and suspension duration.

Was Crypto.com’s 2FA actually bypassed?

In the operational sense, yes: Crypto.com said transactions had been approved without users entering the required 2FA authentication control. That is why coverage described the event as a 2FA compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In the technical sense, the answer is unknown: Crypto.com did not publicly explain whether attackers:

  • stole passwords and one-time codes;
  • phished users in real time;
  • stole authenticated sessions;
  • abused account recovery or security-change workflows;
  • compromised stored authentication tokens; or
  • exploited a server-side error in withdrawal authorization.

There is no cited evidence proving that attackers “cracked” authenticator-app codes or obtained every affected user’s secret. The most accurate description is that the platform approved unauthorized withdrawals without the normal user-entered 2FA step, while the exact attack chain remained undisclosed.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

This distinction matters because multi-factor authentication is not merely a six-digit code. It includes enrollment, token validation, session management, recovery processes and transaction authorization. A weakness in any of those layers can undermine the protection users believe 2FA provides.

How much cryptocurrency was involved?

Crypto.com reported the following asset amounts:

Asset Amount Reported value at the time
Ethereum 4,836.26 ETH Approximately $15.13 million
Bitcoin 443.93 BTC Approximately $18.61 million
Other currencies — Approximately $66,200
Total — Approximately $33.81 million

Early blockchain-analysis estimates were lower. PeckShield initially estimated approximately $15 million in Ethereum losses, while OXT Research reportedly estimated a total closer to $33 million. Those observations helped identify transfers but did not replace Crypto.com’s later exchange-specific disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some contemporary reports said funds were sent through Tornado Cash. That describes observed blockchain movements; it does not, by itself, establish who controlled the addresses or prove the full laundering narrative.

For that reason, “approximately $33.8 million in unauthorized withdrawals” is more precise than stating without qualification that exactly $34 million was permanently stolen.

Were customers permanently out of pocket?

Crypto.com said no affected customer ultimately suffered a permanent loss from the incident: the company reported that it blocked most unauthorized withdrawals and fully reimbursed users in the remaining cases.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That answers the customer-reimbursement question, not the root-cause question. Reimbursement does not show that the authentication or withdrawal-authorization system worked correctly, and it does not establish whether insurance or another source funded the payments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did Crypto.com change?

According to its incident report, Crypto.com:

  • revoked all existing customer 2FA tokens;
  • migrated to new 2FA infrastructure;
  • added further security hardening; and
  • required a 24-hour delay between registering a new withdrawal address and making the first withdrawal to it.

The 24-hour delay is more than a generic security feature. It creates a detection and cancellation window: if an attacker adds a new destination address, the account owner may receive an alert and contact the exchange before funds can be sent there.

Crypto.com also said it planned to move beyond conventional 2FA toward what it called “true multi-factor authentication.” That was a stated plan at the time and should not be treated as proof that every planned change was completed immediately.

The Account Protection Programme

Crypto.com’s original announcement described protection of up to $250,000 for qualified users in selected markets. The stated conditions included:

  • enabling multi-factor authentication for all applicable transaction types;
  • setting an anti-phishing code at least 21 days before the unauthorized transaction;
  • filing a police report and providing it to Crypto.com;
  • completing a questionnaire to support the forensic investigation; and
  • not using a jailbroken device.

Availability, limits, exclusions and terminology may have changed. Readers should consult Crypto.com’s current security help center and applicable policy rather than assuming that the 2022 terms remain unchanged.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why authenticator 2FA is not the same as phishing-resistant MFA

Authenticator apps are materially stronger than passwords alone, but one-time codes can still be exposed through real-time phishing, malware, session theft or weaknesses in the service implementing them. They also do not protect against an exchange-side authorization failure that accepts a withdrawal without correctly checking the required factor.

Passkeys and FIDO2 security keys are generally more resistant to phishing because authentication is cryptographically tied to the legitimate website or application. Crypto.com’s current security page advertises support for passkeys, FIDO2, passwords, biometrics, authenticator codes and hardware security modules. Those are current first-party claims and should not be projected backward onto the January 2022 system.

Nor does a stronger login method make an exchange invulnerable. Account recovery, session controls, withdrawal authorization and monitoring still matter.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What users can do now

  1. Prefer passkeys or FIDO2 security keys where the service supports them. Enroll a spare key and maintain a recovery plan.
  2. Use an authenticator app instead of SMS when stronger phishing-resistant options are unavailable.
  3. Use a unique password generated and stored in a reputable password manager.
  4. Enable withdrawal allowlisting, address delays and alerts where available.
  5. Set an anti-phishing code if the platform offers one, and treat unexpected messages or prompts as suspicious.
  6. Keep only the trading balance on an exchange and consider appropriately secured self-custody or institutional custody for long-term holdings.
  7. Act immediately after an unauthorized transaction: contact the platform, preserve device and account evidence, and file a police report.

These steps reduce user-side risk; they cannot guarantee protection against an exchange’s backend failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Exchange protection is not the same as deposit insurance

Crypto.com’s current U.S. security page says FDIC coverage for eligible U.S. dollar balances applies if the relevant insured bank fails. It does not describe FDIC insurance as protection against cryptocurrency theft or fraud. Consumers should not treat FDIC coverage as a guarantee against an exchange security incident.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

What this breach shows

The Crypto.com incident illustrates why “MFA enabled” is not a complete security assessment. A secure design must ensure that:

  • the correct factor is enrolled and validated;
  • sessions cannot be silently taken over;
  • recovery flows cannot become an easier route around MFA;
  • security-setting changes receive appropriate friction and notification; and
  • withdrawals are independently risk-checked and authorized server-side.

It also shows why incident reporting needs careful language. On-chain observations, exchange-confirmed withdrawals, customer reimbursement and the technical cause are separate facts. Combining them into one headline can make the event sound more technically understood than it really is.

Bottom line

Crypto.com’s January 2022 breach was real: the company reported unauthorized withdrawals affecting 483 users and involving approximately $33.8 million in cryptocurrency at the time. It also reported that the withdrawals were approved without the required user-entered 2FA control and that affected customers were fully reimbursed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

But the public record does not establish how attackers defeated that control. The best-supported conclusion is that 2FA enforcement failed somewhere in the account or withdrawal workflow—not that authenticator codes were definitively cracked, or that authenticator-based MFA is inherently useless.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.