The post Crypto.com Reveals Hidden User Data Breach appeared on BitcoinEthereumNews.com. According to a Bloomberg investigation, Crypto.com, one of the world’s largest cryptocurrency exchanges, reportedly suffered a security breach it never disclosed. The report linked the incident to Scattered Spider, a hacking group that often targets companies with social engineering tactics. The group comprises mainly teenagers who specialize in tricking employees into handing over their credentials. Sponsored Sponsored According to Bloomberg, the attackers posed as IT staff and persuaded unnamed Crypto.com employees to surrender login credentials. Once inside, they attempted to escalate their access by targeting senior staff accounts. Crypto.com told Bloomberg that the attack affected only “a very small number of individuals” and emphasized that customer funds remained untouched. The firm has yet to provide additional information about the incident as of press time. Meanwhile, security experts argue that the exchange’s decision not to disclose the breach undermines confidence in its security practices. They argue that its failure to share details about the incident leaves its users uncertain about the extent of the exposure and vulnerable to possible follow-up attacks. This concern is significant because Coinbase previously suffered a similar breach that exposed its customers to more than $300 million yearly losses. On-chain investigator ZachXBT accused Crypto.com of deliberately covering up the breach. He also stressed that this was not the first time the platform had been linked to undisclosed security lapses Sponsored Sponsored His comments echo wider industry frustration about exchanges that quietly downplay breaches to protect their reputations. Meanwhile, the incident has also reignited criticism of the industry’s reliance on Know Your Customer (KYC) systems. Pseudonymous security researcher Pcaversaccio reacted sharply to the issues, arguing that KYC requirements create massive data honeypots for hackers. “You can change a password easily, but _not_ your passport and they f#cking know it well. We’re basically the collateral in their surveillance racket,”… The post Crypto.com Reveals Hidden User Data Breach appeared on BitcoinEthereumNews.com. According to a Bloomberg investigation, Crypto.com, one of the world’s largest cryptocurrency exchanges, reportedly suffered a security breach it never disclosed. The report linked the incident to Scattered Spider, a hacking group that often targets companies with social engineering tactics. The group comprises mainly teenagers who specialize in tricking employees into handing over their credentials. Sponsored Sponsored According to Bloomberg, the attackers posed as IT staff and persuaded unnamed Crypto.com employees to surrender login credentials. Once inside, they attempted to escalate their access by targeting senior staff accounts. Crypto.com told Bloomberg that the attack affected only “a very small number of individuals” and emphasized that customer funds remained untouched. The firm has yet to provide additional information about the incident as of press time. Meanwhile, security experts argue that the exchange’s decision not to disclose the breach undermines confidence in its security practices. They argue that its failure to share details about the incident leaves its users uncertain about the extent of the exposure and vulnerable to possible follow-up attacks. This concern is significant because Coinbase previously suffered a similar breach that exposed its customers to more than $300 million yearly losses. On-chain investigator ZachXBT accused Crypto.com of deliberately covering up the breach. He also stressed that this was not the first time the platform had been linked to undisclosed security lapses Sponsored Sponsored His comments echo wider industry frustration about exchanges that quietly downplay breaches to protect their reputations. Meanwhile, the incident has also reignited criticism of the industry’s reliance on Know Your Customer (KYC) systems. Pseudonymous security researcher Pcaversaccio reacted sharply to the issues, arguing that KYC requirements create massive data honeypots for hackers. “You can change a password easily, but _not_ your passport and they f#cking know it well. We’re basically the collateral in their surveillance racket,”…

Crypto.com Reveals Hidden User Data Breach

2025/09/22 03:09

According to a Bloomberg investigation, Crypto.com, one of the world’s largest cryptocurrency exchanges, reportedly suffered a security breach it never disclosed.

The report linked the incident to Scattered Spider, a hacking group that often targets companies with social engineering tactics. The group comprises mainly teenagers who specialize in tricking employees into handing over their credentials.

Sponsored

Sponsored

According to Bloomberg, the attackers posed as IT staff and persuaded unnamed Crypto.com employees to surrender login credentials. Once inside, they attempted to escalate their access by targeting senior staff accounts.

Crypto.com told Bloomberg that the attack affected only “a very small number of individuals” and emphasized that customer funds remained untouched.

The firm has yet to provide additional information about the incident as of press time.

Meanwhile, security experts argue that the exchange’s decision not to disclose the breach undermines confidence in its security practices.

They argue that its failure to share details about the incident leaves its users uncertain about the extent of the exposure and vulnerable to possible follow-up attacks.

This concern is significant because Coinbase previously suffered a similar breach that exposed its customers to more than $300 million yearly losses.

On-chain investigator ZachXBT accused Crypto.com of deliberately covering up the breach. He also stressed that this was not the first time the platform had been linked to undisclosed security lapses

Sponsored

Sponsored

His comments echo wider industry frustration about exchanges that quietly downplay breaches to protect their reputations.

Meanwhile, the incident has also reignited criticism of the industry’s reliance on Know Your Customer (KYC) systems.

Pseudonymous security researcher Pcaversaccio reacted sharply to the issues, arguing that KYC requirements create massive data honeypots for hackers.

This concern aligns with broader industry skepticism about regulatory frameworks.

Earlier this year, Coinbase CEO Brian Armstrong criticized the Bank Secrecy Act and existing anti-money laundering rules as outdated and ineffective.

He explained that companies are being forced to collect sensitive data against their will. According to him, the requirements do little to prevent crime despite the burden they place on firms and customers.

Source: https://beincrypto.com/crypto-com-hidden-users-data-breach-sparks-criticism/

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

The post Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO appeared on BitcoinEthereumNews.com. Aave DAO is gearing up for a significant overhaul by shutting down over 50% of underperforming L2 instances. It is also restructuring its governance framework and deploying over $100 million to boost GHO. This could be a pivotal moment that propels Aave back to the forefront of on-chain lending or sparks unprecedented controversy within the DeFi community. Sponsored Sponsored ACI Proposes Shutting Down 50% of L2s The “State of the Union” report by the Aave Chan Initiative (ACI) paints a candid picture. After a turbulent period in the DeFi market and internal challenges, Aave (AAVE) now leads in key metrics: TVL, revenue, market share, and borrowing volume. Aave’s annual revenue of $130 million surpasses the combined cash reserves of its competitors. Tokenomics improvements and the AAVE token buyback program have also contributed to the ecosystem’s growth. Aave global metrics. Source: Aave However, the ACI’s report also highlights several pain points. First, regarding the Layer-2 (L2) strategy. While Aave’s L2 strategy was once a key driver of success, it is no longer fit for purpose. Over half of Aave’s instances on L2s and alt-L1s are not economically viable. Based on year-to-date data, over 86.6% of Aave’s revenue comes from the mainnet, indicating that everything else is a side quest. On this basis, ACI proposes closing underperforming networks. The DAO should invest in key networks with significant differentiators. Second, ACI is pushing for a complete overhaul of the “friendly fork” framework, as most have been unimpressive regarding TVL and revenue. In some cases, attackers have exploited them to Aave’s detriment, as seen with Spark. Sponsored Sponsored “The friendly fork model had a good intention but bad execution where the DAO was too friendly towards these forks, allowing the DAO only little upside,” the report states. Third, the instance model, once a smart…
Paylaş
BitcoinEthereumNews2025/09/18 02:28
Shytoshi Kusama Addresses $2.4 Million Shibarium Bridge Exploit

Shytoshi Kusama Addresses $2.4 Million Shibarium Bridge Exploit

The post Shytoshi Kusama Addresses $2.4 Million Shibarium Bridge Exploit appeared on BitcoinEthereumNews.com. The lead developer of Shiba Inu, Shytoshi Kusama, has publicly addressed the Shibarium bridge exploit that occurred recently, draining $2.4 million from the network. After days of speculation about his involvement in managing the crisis, the project leader broke his silence. Kusama emphasized that a special “war room” has been set up to restore stolen finances and enhance network security. The statement is his first official words since the bridge compromise occurred. “Although I am focusing on AI initiatives to benefit all our tokens, I remain with the developers and leadership in the war room,” Kusama posted on social media platform X. He dismissed claims that he had distanced himself from the project as “utterly preposterous.” The developer said that the reason behind his silence at first was strategic. Before he could make any statements publicly, he must have taken time to evaluate what he termed a complex and deep situation properly. Kusama also vowed to provide further updates in the official Shiba Inu channels as the team comes up with long-term solutions. As highlighted in our previous article, targeted Shibarium’s bridge infrastructure through a sophisticated attack vector. Hackers gained unauthorized access to validator signing keys, compromising the network’s security framework. The hackers executed a flash loan to acquire 4.6 million BONE ShibaSwap tokens. The validator power on the network was majority held by them after this purchase. They were able to transfer assets out of Shibarium with this control. The response of Shibarium developers was timely to limit the breach. They instantly halted all validator functions in order to avoid additional exploitation. The team proceeded to deposit the assets under staking in a multisig hardware wallet that is secure. External security companies were involved in the investigation effort. Hexens, Seal 911, and PeckShield are collaborating with internal developers to…
Paylaş
BitcoinEthereumNews2025/09/18 03:46