Crypto.com's January Breach: How a $15M Ether Theft Grew Into a $33.7M Bitcoin Trail
In mid-January 2022, Crypto.com became the latest major centralized exchange to suffer a security incident, and the company spent days minimizing what had actually happened.
Crypto.com's first public statement on the matter came at 04:44 AM UTC on January 17, 2022, via Twitter: "We have a small number of users reporting suspicious activity on their accounts. We will be pausing withdrawals shortly, as our team is investigating. All funds are safe."

Roughly eight hours later, at 12:17, the exchange repeated that assurance in a follow-up tweet: "Earlier today a small number of users experienced unauthorized activity in their accounts. All funds are safe."
That claim did not hold. Later the same day, at 18:44 UTC, wallets belonging to hundreds of Crypto.com users were drained. It remains unclear exactly how the attacker got past both two-factor authentication and the email-based withdrawal-approval process on so many accounts simultaneously.
CEO @Kris_HK publicly repeated the "all funds are safe" line even as a growing number of users reported publicly that their ETH had gone missing.
Security firm PeckShield estimated the damage at around $15 million, with at least 4,600 ETH withdrawn directly from hundreds of separate user wallets. CertiK put the figure slightly higher, at approximately 4,836 ETH across 282 affected wallets. The stolen ether was routed through Tornado Cash, and the receiving address went dormant on January 18, 2022 at 01:21:13 AM UTC.
The attacker had defeated both existing 2FA safeguards and the withdrawal whitelist, raising questions about whether the intrusion was purely external. Notably, Crypto.com had previously advertised a "SOC2" security audit performed by Deloitte, which evidently offered no protection here. Based on the losses known at the time, the incident placed Crypto.com at position 29 on Rekt's leaderboard of crypto losses.
Beyond the direct financial cost, incidents like this carry reputational weight for the wider industry — when a brand as recognizable as Crypto.com is compromised, retail users already wary of centralized platforms have another reason to lose confidence.
The story didn't stop there.
Two days after the initial breach, further digging by independent researcher ErgoBTC turned up a separate, previously undisclosed outflow of funds: an additional 444 BTC, worth roughly $18.7 million. Added to the earlier ETH losses, that brought the total estimated damage to $33.7 million and moved Crypto.com up to position 15 on the leaderboard — all while the exchange continued to offer no public acknowledgment that any funds had been lost.

ErgoBTC's investigation traced an unusually large withdrawal from Crypto.com's own payout wallet, bc1q7cyrfmck2ffu2ud3rn5l5a8yv6f0chkp0zpemf, executed via transaction 06f7b6adac715ea7f30e2f23f52b3dfeed53.... Shortly after that withdrawal, several hundred smaller withdrawals were consolidated into four outputs totaling 67.75 BTC. From there, 271 BTC moved in a series of 24-to-25 BTC deposits into a well-known Bitcoin tumbling service. A further 173 BTC sitting at bc1qk8wlwypvvr6v5lmsngg5a248k2a9cgrsrw5jsq, believed to be tied to the hack, had not yet been forwarded to the tumbler at the time of the report. That same tumbling service has reportedly been used in past laundering attempts linked to North Korea's Lazarus Group, as well as in efforts to launder funds tied to the Darkside ransomware operation earlier that summer.
Even with this second, larger batch of evidence in hand, Crypto.com still had not issued any public accounting of the losses. Its CEO instead posted content researchers described as celebratory, drawing further criticism that the exchange should be informing its users of what happened to their money rather than posting unrelated social media content.
As it stands, Crypto.com has not confirmed the losses, published a post-mortem, or clarified whether affected users will be compensated — whether through a formal restitution plan covering the estimated damages, or through quiet, unannounced refunds.
Get new scam files the moment we publish them — usually 2–3 emails a week.