Open app

HostDeFi › Is Crypto.com safe

Is Crypto.com safe? The venue that watched 2FA fail and paid every cent back

Crypto.com owns the incident this corpus likes least and respects most: on January 17, 2022, its risk systems caught withdrawals being approved without the 2FA control the users had set — the one prompt that is supposed to be the last line. The attackers took ~$33.8M from 483 accounts. The response was the right shape — 14-hour freeze, all 2FA tokens revoked globally, new withdrawal-address delay, every affected user fully reimbursed the same day — and the disclosure was three days slow. Both belong on this page.

Updated September 28, 2026 · By the HostDeFi editorial desk · Sources linked throughout; vendor claims labeled.

What Crypto.com is

Crypto.com (Singapore, founded 2016 as Monaco) is one of the largest retail-facing custodians — the Matt-Damon-ads, stadium-naming ($700M, Crypto.com Arena) exchange that grew on aggressive consumer marketing plus a Visa-card rewards loop. Custody shape is standard CEX: balances are claims on platform cold/hot wallets, gated by account-level controls — which makes its one documented incident the interesting case in this batch: it is the only exchange here whose public breach ran through the account security layer, not the treasury layer.

January 17, 2022: when 2FA wasn't the last line

The documented incident, per Crypto.com's own post-mortem: around 12:46 AM UTC on January 17, 2022, risk monitoring flagged "transactions being approved without the 2FA authentication control being inputted by the user." Attackers had found a path that let withdrawals clear without the user's 2FA — a platform-side control bypass, not users being phished. Unauthorized withdrawals totaled 4,836.26 ETH and 443.93 BTC plus ~$66,200 in other currencies — ~$33.8M across 483 accounts. PeckShield traced roughly half the ETH into Tornado Cash within hours; on-chain analysts had the theft mapped — size, destinations, mixers — before the company publicly named it.

The response chain, in order: all withdrawals suspended ~14 hours; every customer 2FA token revoked globally (all users re-enrolled on a migrated 2FA architecture); a mandatory 24-hour delay between registering a new withdrawal address and its first withdrawal was added — the control that kills exactly this attack class; and all 483 affected accounts were fully reimbursed, most within the day. CEO Kris Marszalek's framing — "no customer funds were lost" — was technically true by reimbursement, though the company's own accounting shows $33.8M did in fact leave attacker-bound.

The disclosure gap, priced honestly

The part this page owes you beyond the post-mortem: the market knew before Crypto.com told it. Security researchers flagged the outflows and users reported thefts on social media while official communications still said only "incident"; the CEO's public confirmation came in a Bloomberg TV interview roughly three days after detection, and the detailed post-mortem a day after that. The cover was complete and fast; the candor lagged the on-chain record — and in this family, that ordering matters, because every custodian's post-incident statement is either ahead of the chain or behind it.

Read against the corpus's reference cases: KuCoin named the vector (leaked hot-wallet keys) within days and itemized the recovery; Crypto.com reimbursed faster but described less. Neither damaged a user balance — the difference is how much you had to trust the venue during the window the truth was assembling itself.

What the 2FA bypass actually changed

The durable lesson the incident left in the product: 2FA protects you from your password leaking; it does not protect you from the venue's approval logic failing. The controls Crypto.com shipped afterward map to that distinction exactly — withdrawal-address whitelisting with a time delay (the fix that matters most), a rebuilt 2FA architecture, and an account-protection program covering qualifying unauthorized withdrawals up to a stated cap. Those are the controls a venue installs after learning its own approval layer was the hole — worth more, as safety evidence, than a decade of marketing about military-grade anything.

The standing protections that were already there and stayed: institutional-grade custody for the bulk of assets, proof-of-reserves publications in the post-FTX wave, and a balance sheet deep enough that $33.8M was absorbed as an operating event rather than a solvency event — the CEO's "not material" line was arrogant in delivery and accurate in scale.

Where Crypto.com stands

The dated read: a big-brand custodian whose only documented breach was a control bypass it disclosed slowly and covered completely — followed by a control refresh aimed at exactly that failure. The residual risks are the standing custodial set — counterparty, withdrawal integrity — plus two named items: a demonstrated willingness to let the on-chain record run ahead of the company's own acknowledgment, and a marketing-heavy brand that makes it the most-impersonated retail exchange name after Binance. Compared to the set: slower candor than KuCoin, faster reimbursement than almost anyone, and the only venue here whose breach path ran through "the user did everything right.," and the scale note the other venues make relevant: $33.8M was absorbed in a day as an operating event — the same figure that ended lesser venues is, at this book size, a rounding item — the quiet advantage the mega-custodians hold over the second tier."

Frequently asked questions

Was Crypto.com hacked?

Yes — January 17, 2022: attackers bypassed the 2FA control on withdrawals and drained 4,836.26 ETH + 443.93 BTC + ~$66K other, ~$33.8M across 483 accounts. It was a platform-side approval flaw, not user phishing — users had 2FA set and the withdrawal cleared anyway. Crypto.com froze withdrawals ~14 hours, revoked all customer 2FA tokens, migrated the 2FA architecture, added a 24-hour new-address withdrawal delay, and reimbursed every affected account.

Did Crypto.com reimburse the hack victims?

Fully — all 483 affected accounts were made whole, most same-day; the CEO's "no customer funds were lost" line is true only via that reimbursement (the ~$33.8M did leave, roughly half laundered through Tornado Cash per PeckShield). The honest criticism in the record is disclosure speed: researchers and users had the theft mapped ~3 days before the company's detailed acknowledgment landed.

Is Crypto.com's 2FA safe now?

The incident was a bypass of the approval system, not of your authenticator — the fix was architectural (new 2FA stack, all tokens revoked and re-enrolled) plus the control that actually prevents the attack class: a 24-hour delay between registering a withdrawal address and its first use. For you: TOTP or passkey over SMS, withdrawal whitelisting on, and read any "security upgrade" email as suspect — the brand's size makes it a top impersonation target.

Is Crypto.com regulated?

It holds the largest license stack in its tier: multiple US state MTLs plus a federal-adjacent posture (it has publicly pursued US institutional products), and registrations across EU/UK/other jurisdictions — real licensing, though "regulated" varies sharply by jurisdiction and product. What it does not make: crypto balances on any exchange FDIC-insured — the account-protection program and corporate balance sheet are the backstop, not a government guarantee.

Is Crypto.com safer than Coinbase or Kraken?

On record, it sits below both on incident-free custody: Coinbase's 2021 was an SMS-recovery flaw (users' credentials already phished), Kraken has never lost user funds; Crypto.com's 2022 was a platform-side control bypass — a more direct custody-layer failure, fully covered and followed by architectural fixes. On transparency, Coinbase's public-company disclosures and Kraken's decade of PoR both outrank Crypto.com's PoR publications. Honest placement: big-brand security with one real scar and the controls to show for it.

Should you keep funds on Crypto.com?

Same custodial rule as the whole family: a trading surface, not a vault. Its incident history says the balance sheet absorbs user-sized losses and the control layer now guards the exact path that failed; its disclosure history says you may learn about a problem from the chain before the company. Keep on-venue what the card/rewards features earn for you; custody what you hold elsewhere.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product