Crypto.com dismisses the possibility of a hidden breach: according to the company, there was a social engineering campaign in 2023.Crypto.com dismisses the possibility of a hidden breach: according to the company, there was a social engineering campaign in 2023.

Crypto.com and the alleged data breach: timeline, notifications, what’s missing

Crypto.com dismisses the hypothesis of a hidden breach: according to the company, in 2023 there was a social engineering campaign targeting an employee, contained within a few hours and with limited impact on personal data. Doubts remain about documents, timelines, and officially communicated numbers.

What Happened: Accusations and Denials Compared

A member of the Scattered Spider group, cited by Bloomberg, claims to have gained access to an internal account of Crypto.com between the end of 2022 and the beginning of 2023.

On-chain investigator ZachXBT then echoed the allegations on X, stating that Crypto.com allegedly covered up a personal data leak, adding that the company had been “breached several times.”

Crypto.com categorically denies having concealed the incident. In a statement, a spokesperson confirmed that the company detected a social engineering episode on an employee in 2023, contained within a few hours, and issued a “Notice of Data Security Incident” through the reporting system of the Nationwide Multistate Licensing System (NMLS) and to other relevant authorities in the United States.

According to data collected by industry analysts who have examined public timelines and on-chain posts, temporal discrepancies emerge between the claims of the accusers and the regulatory filings reported by the company.

Analysts also note that, in the absence of verifiable links to the filings, it is impossible to confirm the exact number of people affected by the potential exposure.

What is confirmed (company)

  • Vector: targeted social engineering attack on an employee (2023).
  • Containment: incident neutralized within a few hours of detection.
  • Impact: exposure of personal data “limited” to a very small number of individuals.
  • Funds: no access or risk to clients’ funds.
  • Notifications: submission of reports through the appropriate regulatory channels, including filing in the NMLS system.

What is contested (accusations)

  • Scope of access: alleged accusations of a broader and repeated intrusion.
  • Transparency: hypothesized deficit in communication towards the public and clients.
  • Numbers: lack of official figures regarding the number of individuals and the types of data involved.

Timeline: from social engineering to regulatory filings

  1. End of 2022 / beginning of 2023 — According to the allegations, access to an internal account occurred during this period.
  2. 2023 — Crypto.com detects the social engineering incident and contains it within a few hours, with no impact on customer funds.
  3. 2023 — The company files a “Notice of Data Security Incident” in the NMLS system and communicates it to other relevant authorities.
  4. 2025 — The case returns to public attention after being shared on X and receiving new media coverage, reigniting the debate on transparency.

Impact: which data would have been exposed

Crypto.com speaks of a “limited” exposure of PII (personally identifiable information) for a very small number of individuals, without providing precise details on the categories of data affected (e.g., email, phone numbers, addresses, or documents).

In the absence of official numbers and a detailed list of the data involved, criticisms about communication are fueled. Analysts point out that the definition of “few” users can vary significantly: for a company with millions of customers, even hundreds of accounts involved represent a significant case.

Where are the documents: sources, posts, and statements

  • Bloomberg — Reported statements attributed to a member of Scattered Spider.
  • Cointelegraph — Published the official position of Crypto.com and the reference to the regulatory filing.
  • Post on X by ZachXBT — He reiterated the accusations, raising the issue of transparency.
  • Post on X by CEO Kris Marszalek — He described the accusations as “disinformation” and reiterated the sending of regulatory notifications.
  • NMLS (homepage) — Crypto.com refers to a “Notice of Data Security Incident” in the Nationwide Multistate Licensing System; the direct link to the filing is not publicly available.

Why Transparency is Being Discussed

In the US financial sector, state laws on data breach notification and regulatory requirements mandate timely communication of security incidents.

In this context, without accessible documents and a complete incident report, customer trust relies primarily on the company’s statements and independent verification of the facts.

Social engineering cases are among the most frequent: the Data Breach Investigations Report (DBIR) by Verizon highlights how the human factor is involved in the majority of incidents (in recent reports, the indicated percentage is around 68%) Verizon DBIR.

Guidelines for incident management and regulatory notifications recommend documented processes and clear reporting times, as indicated in the best practices published by the NIST SP 800-61.

The incident highlights a particularly sensitive issue for exchanges: how to communicate a limited impact incident without causing alarm, especially when timing and numbers are not yet fully defined?

  1. Multi-factor authentication: enable and verify the TOTP app; avoid relying solely on SMS.
  2. Password: change it if not updated since 2023; use a password manager and unique credentials.
  3. Phishing alert: be wary of suspicious emails or links that request data submission; always check the domain and message headers.
  4. Account monitoring: regularly check logins and authorized devices.
  5. Notifications: check your inbox and the app for any official communications regarding the incident.

FAQ

Did the company hide the incident?

Crypto.com claims otherwise, reiterating that it has filed the “Notice of Data Security Incident” in the NMLS system and reported the incident to the relevant authorities. The accusations argue the opposite, demanding greater transparency and the publication of additional documents.

How many users are involved and what data?

A precise number has not been disclosed. The company mentions a limited impact with PII exposure for “few” users, without providing a detailed list of the categories of data affected.

Were the clients’ funds at risk?

According to the official version of Crypto.com, no access to customer funds has ever occurred nor were they at risk.

Some regulatory filings, such as those related to the NMLS, are not public or appear on portals with limited access, so a direct verifiable link is not available at the moment.

The overview, in summary

The case unfolds between accusations of a more extensive internal breach and the official denials from Crypto.com. Without access to complete public documents and verifiable figures, the debate remains open. Transparency on the timing and impact of the incident will be crucial in defining the matter.

Source note: a publicly verifiable link to the alleged “Notice of Data Security Incident” on NMLS is not available; the indications are based on company statements and coverage by Bloomberg

Piyasa Fırsatı
null Logosu
null Fiyatı(null)
--
----
USD
null (null) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

USD/CAD rises above 1.3750 after rebounding from three-month lows

USD/CAD rises above 1.3750 after rebounding from three-month lows

The post USD/CAD rises above 1.3750 after rebounding from three-month lows appeared on BitcoinEthereumNews.com. USD/CAD rebounds from a three-month low of 1.3730
Paylaş
BitcoinEthereumNews2025/12/17 11:25
Bitwise Forecasts Bullish 2026 for Crypto: Bitcoin to Hit New All-Time Highs, ETF Demand to Surge, Institutional Adoption to Deepen

Bitwise Forecasts Bullish 2026 for Crypto: Bitcoin to Hit New All-Time Highs, ETF Demand to Surge, Institutional Adoption to Deepen

Cryptocurrency asset manager Bitwise has released an optimistic forecast for 2026, painting a picture of comprehensive strength across digital assets. The firm predicts Bitcoin will reach new all-time highs, ETF demand will surge dramatically, crypto-related equities will outperform traditional markets, and institutional adoption will deepen across various market segments.
Paylaş
MEXC NEWS2025/12/17 12:59
Hong Kong Backs Commercial Bank Tokenized Deposits in 2025

Hong Kong Backs Commercial Bank Tokenized Deposits in 2025

The post Hong Kong Backs Commercial Bank Tokenized Deposits in 2025 appeared on BitcoinEthereumNews.com. HKMA to support tokenized deposits and regular issuance of digital bonds. SFC drafting licensing framework for trading, custody, and stablecoin issuers. New rules will cover stablecoin issuers, digital asset trading, and custody services. Hong Kong is stepping up its digital finance ambitions with a policy blueprint that places tokenization at the core of banking innovation.  In the 2025 Policy Address, Chief Executive John Lee outlined measures that will see the Hong Kong Monetary Authority (HKMA) encourage commercial banks to roll out tokenized deposits and expand the city’s live tokenized-asset transactions. Hong Kong’s Project Ensemble to Drive Tokenized Deposits Lee confirmed that the HKMA will “continue to take forward Project Ensemble, including encouraging commercial banks to introduce tokenised deposits, and promoting live transactions of tokenised assets, such as the settlement of tokenised money market funds with tokenised deposits.” The initiative aims to embed tokenized deposits, bank liabilities represented as blockchain-based tokens, into mainstream financial operations. These deposits could facilitate the settlement of money-market funds and other financial instruments more quickly and efficiently. To ensure a controlled rollout, the HKMA will utilize its regulatory sandbox to enable banks to test tokenized products while enhancing risk management. Tokenized Bonds to Become a Regular Feature Beyond deposits, the government intends to make tokenized bond issuance a permanent element of Hong Kong’s financial markets. After successful pilots, including green bonds, the HKMA will help regularize the issuance process to build deep and liquid markets for digital bonds accessible to both local and international investors. Related: Beijing Blocks State-Owned Firms From Stablecoin Businesses in Hong Kong Hong Kong’s Global Financial Role The policy address also set out a comprehensive regulatory framework for digital assets. Hong Kong is implementing a regime for stablecoin issuers and drafting licensing rules for digital asset trading and custody services. The Securities…
Paylaş
BitcoinEthereumNews2025/09/18 07:10