21 ms·
Crypto.com accounts had unauthorized withdrawals
- ricotico060 5y agoReminder that cliches are cliche for a reason: not your keys, not your crypto
- tsimionescu 5y agoYes, and apparently this allowed all those attacked not to lose a single penny.
- davidwparker 5y agoThey also said they've reimbursed all funds. So if you were hacked personally, you would be out money here, vs keeping it on their exchange where you would be made whole again.
- smokey_circles 5y agoThat's not a fair comparison though. An exchange is a fat, juicy target. I am not
- PragmaticPulp 5y agoIts cliche, but it doesn’t really mean that crypto.com or any other crypto exchange isn’t on the hook for stolen funds. Crypto doesn’t mean regulation doesn’t apply or that companies are free from liability. Obviously you can’t squeeze blood from a stone if someone were to steal most of the funds from a crypto exchange (Mt. Gox comes to mind) But in the real world, if you use a crypto exchange in a reasonable location (e.g. US exchange adhering to US laws) then small thefts like this are going to be reimbursed one way or another. Now if the entire exchange and their cold wallets were stolen somehow, it would be game over.
- croon 5y agoSo in the real world when using a regulated crypto exchange, what's the point of a blockchain other than asset speculation (which can also be done through traditional trading instruments at this point)?
- snotrockets 5y agoYou need to send money to the hackers who ransomware'd your network. They don't accept SWIFT.
- PragmaticPulp 5y agoYou could argue that it allows people to send funds in ways that are faster than some other current options. But that’s about it. It’s basically another game to play with new financial assets printed out of thin air.
- imtringued 5y agoWhen you think about it, liquidity is the source of speculation. This is because liquidity is the ability to quickly trade your thing for other things. Lending money via a certificate of deposit reduces liquidity because you are locking up your funds. Lending via demand deposits increases liquidity because the original deposit and the loan are both available to be spent immediately. Spending money on physical things is very time consuming. First you must pick what you want to buy among billions of product choices that are available to you. Even if you buy something, it takes time to drive to the store or for it to be delivered. The real world is quite illiquid which means that fiat currency is less volatile and has greater stability than Bitcoin. Now there are two exceptions. Trading money vs financial assets and money vs other money. In the financial sector you are trading liquidity for liquidity. Buying an iPhone and selling it takes time. Buying Bitcoin and selling it does not. It can happen as quickly as technology allows it. This inevitably leads to speculation because it is possible to instantly react to any other transaction. Someone buys Bitcoin? Buy more! Someone sells Bitcoin? Sell! To be more specific, the problem isn't liquidity itself but excessive amounts of liquidity that go way beyond what the real economy needs. This is a huge problem with fiat currency but it's also a problem with Bitcoin because the "Bitcoin economy" is absolutely tiny.
- curiousllama 5y agoAnd thank god for that. Very happy to be a luddite with have exposure to the rise in crypto prices without the risk of getting it stolen.
- dabeeeenster 5y ago> In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure. That isn't the technical solution I was looking for...
- gitfan86 5y agoI am a cyber security consultant for startups. The first thing that I communicate is that just by not being in crypto you have drastically lowered your risk profile. Attackers care a lot about what they can get to if they are able to breach your security.
- mritchie712 5y agoHow many startups do you talk to that are "on the fence" with somehow using crypto in their product? Seems pretty core to what the company would be doing.
- danaris 5y agoI dunno, I've seen a lot of mentions of different companies trying to stuff crypto/blockchain in to seem trendy and marketable when it's clear that there's absolutely nothing crypto/blockchain brings to that use case. (In fact, I have yet to see a single genuine use case for cryptocurrencies or blockchain that aren't served at least as well by more proven technologies, aside from "separating money from fools" and "making libertarians/anarchocapitalists squee".)
- capableweb 5y agoEh, yes of course, what are you saying really? Is there some deeper point I miss? Just like finance companies have a different risk profile than companies generating bingo cards, crypto companies have different risk profiles than other non-financial ones. Are people arguing that this is not true or something?
- gitfan86 5y agoPeople generally don't understand how vast the difference is. The pro crypto narrative has pushed the idea that "Blockchain is more secure" because "it cannot be edited" when in reality that feature makes it much more of a target for attackers because once they transfer the coins the transfer cannot be edited. In comparison if an attacker gets a credit card that card could be disabled and or have transactions cancelled.
- vmception 5y agoCrypto.com giving me some WAP > with enhancements we’ve made to our security infrastructure and the introduction of the Worldwide Account Protection Program.
- deleted 5y ago[deleted]
- husamia 5y agothis trigged an avalanche of selling!
- siva7 5y agoThat happens if you let startups operate like a big bank without all the SecOps
- camjohnson26 5y agoBy the numbers, around $34 million in funds is affected, mostly Ethereum. They say in the press release that they prevented most of the unauthorized withdrawals and reimbursed the remainder, but it’s unclear how much they had to pay for reimbursements. For context, this is the startup that has been using Matt Damon as it’s face.
- ammonammonammon 5y agoAd even earlier started out with MCO as their iconic token, then shifted to a new crypto while leaving early stakeholders in the dark. Those early maneuvers were something of a red flag.
- JohnJamesRambo 5y agoYep when I found out this was Monaco Coin guy rebranded, everything Crypto.com does started making a lot more sense. https://www.cryptovantage.com/news/opinion-the-crypto-com-mco-swap-has-outraged-investors/ https://www.cryptovantage.com/news/opinion-the-crypto-com-mc...
- VHRanger 5y agoPresumably they mostly stole ETH because tornado cash is the best mixer around to launder stolen funds
- sparkling 5y agoI assume they stole just anything they got. I'd assume any attacker would at least transfer everything to a BTC/whatever address generated offline, then figure out later how to launder it.
- NelsonMinar 5y agoI'd love to read more about these money laundering operations like Tornado Cash. Are they just straight up 100% fraud companies? Do they have any pretense of a legitimate use case or does everyone just understand they're used for criminal activity? Are they regulated at all? I assume you have to trust your magic beans to them at some point; do the money launderers sometimes just steal them? What do they charge for their service?
- VHRanger 5y agoMATT DAMON HOW COULD YOU DO THIS TO ME
- JaggerFoo 5y agoIs Matt Damon the signal of Peak Crypto?
- tootie 5y agoIt's funny how many comments are about Matt Damon. That must be a pretty sticky ad campaign. It's also bizarre that I never heard of them before this marketing blitz although they seemingly have enough cash to hire Matt Damon and buy naming rights to an NFL stadium. I guess all their budget went to marketing instead of hardening their platform.
- agloeregrets 5y agoThe ad campaign is notable because, much like most Perfume ads, it's downright bizarre. The ad sells a concept extremely well and then makes the leap of a lifetime for the subject that is a crazy let down. Edit: the funny thing for me is that if the ad ended with the SpaceX (or Boeing, or Northrop, or USAF) logo and gave the SpaceX employment site at the end, I'm sure it would be seen as one of the best ads of the last few years. The leap is what kills it.
- devmor 5y agoIt plays before every single movie in my local theatres. And every time there's at least several people booing it. It's kind of funny.
- the_snooze 5y agoTo be fair, a more honest ad wouldn't be as compelling: "Exchange your real money for online scrip because reasons!"
- cuteboy19 5y ago
- GiorgioG 5y agoI guess fortune doesn't always favor the brave.
- ceejayoz 5y agoIt does, there's just usually someone braver out there.
- udbhavs 5y agoBrave enough to manage their own keys in this case
- criddell 5y agoThat depends on whether or not you consider stealing cryptocurrency to be brave.
- singlow 5y agoThat's the crypto.com marketing slogan which is spewed by Matt Damon in their commercials.
- muttantt 5y agoExchanged are the weakest link in crypto. If anything can kill crypto, it will be due to the exchangers, from hacking to over regulation, etc.
- gkoberger 5y agoMaybe, but I think you can make a case for the opposite too. Without exchanges, there'd be no crypto. Exchanges are the only reason 99% of people who have crypto can figure out how.
- Kye 5y agoEspecially with mobile devices taking over. An increasing number of people don't even have a laptop or desktop to hold a whole blockchain on. Even an iPhone 13 Pro with 1TB of storage would lose 10-20% of its space to that. That isn't going to improve. The more popular it gets, the faster it grows, and it would compete with all the other storage needs that also grow. Get someone to load up and maintain a whole blockchain on their 1TB phone, and you lose them the moment they need more room for photos or offline synced music and files.
- gruez 5y agonot sure about how big the ETH blockchain is, but the bitcoin blockchain fits in under 6GB if you enable prune mode. I still wouldn't run a full node on my phone, but disk space isn't the limiting factor.
- gkoberger 5y agoAgreed. And even if the storage issue isn't the main blocker, there's also energy usage, bandwidth, security and usability issues when it comes to phones.
- thinkmassive 5y agoNot everyone needs a full copy of the blockchain to run a node. A pruned full node downloads and validated all blocks, then discard everything not relevant to its own wallet. A variety of “light clients” are also available for most chains, which fetch transaction data from peers as needed (usually using something like bloom filters to increase privacy). Most ethereum apps just go through Infura. That’s a horrible centralized single point of failure that I’m not advocating, but the point is there are many ways a wallet app can connect to a remote full node.
- rvz 5y agoIt has been painfully admitted. But you know what I am going to say if you're storing your crypto life-savings or JPEGs on an exchange: Not your keys, Not your coins and certainly not your NFTs.
- salawat 5y agoI love hove cryptocurrency people are also discovering what we anti-cloud people have been shouting from the rooftops for years.
- paulpauper 5y agohow do you think it was done. said 2fa was bypassed for some accounts. maybe some sort of client side exploit.
- Miner49er 5y agoSeems really unlikely, but maybe someone guessed or discovered the keys? Would likely only happen if Crypto.com somehow was generating them insecurely or if someone had inside access to their systems or something. Maybe a leak? Since it is across multiple currencies, I think it is unlikely it has to do with generation. Maybe could still be a leak or something.
- FlacoJones 5y agoIf they had access to the private keys they wouldn't have to go through the crypto.com platform at all. They'd just pop it in any wallet and sign withdrawal transactions. There's no 2FA or whitelisted withdrawal addresses (for most tokens) or emails on-chain.
- wepple 5y agoIn practice, there’s often so much complexity that finding a path isn’t all that hard. Some examples: - abuse the logic flow and simply don’t submit the 2FA step - submit an empty 2FA token (I’ve seen it work) - get a signed transaction from a legitimate transfer and replay it in a compromised account - find the admin API that their help desk uses that doesn’t require 2FA - brute force 2FA code. If you get 3x attempts at a 6-digit pin you have a 1/333,333 chance. Multiply by a few thousand accounts you can find reused creds for - Find an API to abuse to disable 2FA (maybe via CSRF?) - move the money into an account that doesn’t require 2FA (some kind of whitelisted arbitrage account maybe?) then cash out from there - keep transfers under a 2FA threshold but then either script up the transfer to repeat or change the transfer amount after the threshold check has occurred I could riff on for ages. Some more plausible than others. Some I’ve definitely seen (and used in legal testing)
- sudoaza 5y agoThis, they don't say, maybe they don't even know, since: > In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure. > 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect.
- Shank 5y ago> 2FA tokens for all users worldwide were subsequently revoked to ensure the new infrastructure was in effect. We have mandatory 2FA policies on both the frontend and backend to protect users during this revocation phase, as outflows such as withdrawals have a requirement to setup and use 2FA in order to withdraw. How is this supposed to work? They revoked all of their 2FA for all accounts? Doesn't this just open them up to credential stuffing attacks? This is a really, really odd response to me. I can understand migrating to a new 2FA system, but they'd have to re-establish the chain-of-trust somehow. Are they just hoping that users don't have compromised email/SMS accounts in order to enable the new 2FA system?
- PinguTS 5y agoThat was exactly my question when I read this. How do they establish trust, when 2FA is revoked? How they prevent that the bad guy enables now 2FA and the god guy is locked out of his account? May the god guy didn't get the message that Crypto.com had an issue, because s/he is unavailable.
- Scoundreller 5y agoMy thought is maybe they didn’t really do 2FA, but exploited a password reset mechanism that only required 2FA? IE: single factor resets, so a compromised “2FA” was actually keys to the kingdom? But you’d think the attacker would need access to a user’s email or some such then.
- tsimionescu 5y agoGiven that apparently their previous system simply allowed login/payments without the configured mandatory 2FA, per their statements about the root cause of the issue, this may have been a move of desperation...
- ceejayoz 5y agoI'm wondering if it's a badly-worded way of saying "anyone in the system gets kicked out and has to re-2FA". If they literally removed 2FA from everyone, that's insane.
- 101008 5y agoHow did they check if a withdrawal was unauthorized (real) or not? What if I did a withdrawal, say it was unauthorized, and claim the money (and also have the crypto in a different wallet)?
- YXNjaGVyZWdlbgo 5y agoI guess they know which accounts circumvented their previous 2FA implementation.
- samjmck 5y agoI'm guessing any withdrawal that was done while using an exploit to bypass 2FA could be called unauthorized in this case
- JaimeThompson 5y agoI'm not sure but I suggest they use some sort of distributed crypto solution to resolve such issues.
- gercott 5y agoThis is why CRO requires 24 hours whitelist before you can transact withdrawals...
- arkitaip 5y agoUnderstandable yet totally absurd. Can you imagine if your bank had the same requirement?
- duxup 5y agoDepends on my bank. I’ve got long term investment accounts that I hardly touch … I would have no problem with such a rule/ extra validation of any moves of money. Granted crypto.com might not be / want to operate like that.
- criddell 5y agoMaybe it shouldn't be mandatory, but it might be a nice (default) option to have.
- thebean11 5y agoThey certainly have similar requirements. ACH transfers take days, wire transfers require you to jump through verification hoops, ATMs have low daily limits.
- foobiekr 5y agoI would actually love such a feature, especially in a brokerage context.
- mcescalante 5y agoAt least one US investment banks I've used require a waiting period before transacting with a newly added account/routing number for wires/ACH. I've even got calls from customer service manually confirming transfers/withdrawals if it's a new account or one that's been unused for a long period of time. That said, there is no waiting period on me withdrawing from my checking account.
- PikachuEXE 5y ago
- karmicthreat 5y agoSo is starting a crypto exchange how many large crypto holders plan to cash out?
- n_time 5y agoThank goodness it's decentralized and there are no single points of failure.
- mritchie712 5y agoI'm guessing this is sarcasm? crypto.com is very very far from a single point of failure.
- boopboopbadoop 5y agoThey might be alluding to the removal of centralized authorities that would have otherwise been able to get that money back.
- capableweb 5y agoThe allude from my naive point of view is that n_time thinks we're lucky the network is decentralized and that users are spread out over various wallet software and services, so the impact of the issue was only related to a sub-section of the network as a whole. But I might just misunderstand the sarcasm or something.
- tsimionescu 5y agoWell, traditional banking is much more decentralized in this sense, as there are many more banks than crypto exchanges, and the vast majority offer payment apps etc.
- dematz 5y agoI assumed it's sarcastic, the point is even if the network is decentralized in practice people use centralized services.
- thebean11 5y agoHow is this a single point of failure? The issue was limited to a subset of users keeping funds in a Crypto.com wallet. Unless by "it" you mean crypto.com and not Ethereum. Crypto.com is not decentralized.
- smnplk 5y agoWhy shouldn't I work for Crypto.com ? That’s a tough one but I'll take a shot. -- Will from Good Will Hunting
- Kon-Peki 5y ago"How do you like them apples?" will be the Crypto.com response to anyone that lost their money.
- exdsq 5y agoNo-one lost any money :)
- thehappypm 5y agoCrypto.com sure did.
- kingcharles 5y agoI assume they have SMS as a 2FA option and that was the weak link?
- rvz 5y ago> SMS as a 2FA option I hope not, if that is true. The year is 2022 and companies managing >$100B in assets are STILL using SMS 2FA for protecting their life savings, despite SIM hijacking and SIM swapping still about. Quite pathetic really.
- shmatt 5y agoThese companies want more cash heavy users. Like those older than 50. There is absolutely no way my parents could figure out 2fa in any way other than phone call/sms. They would be cutting out the less technical crowd, which is exactly who they're trying to convince to buy in
- AlexandrB 5y agoIt's one thing to offer SMS in addition to other 2FA options. It's completely another when SMS is the only 2FA option at these institutions. See also: Canadian banks (at least the ones that even support 2FA of any kind).
- JaggerFoo 5y agoSo their backend allowed withdrawal transactions without 2FA control. Not a good sign for a system that should thrive on secure transactions. Ethereum seems to be the token most prized during a breach, most likely to be used on tornado.cash. Cheers
- outside1234 5y agoIt's almost like we need a centralized authority that can undo these withdrawals and a know your customer paper trail.
- salawat 5y agoFunny that, ain't it? Perhaps we could Automate it. It'd be like.. a house for clearing transactions. Nah... Probably never catch on.
- imalerba 5y ago> In an abundance of caution, we revamped and migrated to a completely new 2FA infrastructure. Can someone setup, test and rollout a _completely new_ authentication system in 3 days?
- AlexandrB 5y agoUnless they were working on this already for other reasons, I imagine a lot of corners were cut to make it happen so quickly. We might be hearing from crypto.com again soon.
- labrador 5y agoIt seems to me that while banning crypto by western governments is politically untenable, a better way would be to have their security services keep hacking it to make it unattractive
- Applejinx 5y agoWhy would they not be doing both, if getting replaced as a money standard by an anarchist cybercurrency was an existential threat to these western governments?
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- salawat 5y ago...It's totally politically tenable if it's nigh impossible to wrangle necks to wring to hold service providers accountable. What? Do you think Principles of System Architecture are completely absent in the public space? Why do you think everything tends to centralize? To keep things localizable. ...Until that backfires anyway. Thank you 2008.
- deleted 5y ago[deleted]
- shp0ngle 5y ago
- EMM_386 5y ago> On Monday, 17 January 2022 at approximately 12:46 AM UTC Crypto.com’s risk monitoring systems detected unauthorized activity on a small number of user accounts where transactions were being approved without the 2FA authentication control being inputted by the user. This triggered an immediate response from multiple teams to assess the impact. I sometimes find it hard to believe these statements, but I guess I can only take them at face value. Which seems more likely, that these "risk monitoring systems" actually caught this, or that they were inundated by sudden urgent calls from the 483 users saying "DUDE WTF WHERE'S MY MONEY?".
- perlgeek 5y agoIf it's true, there's this funny situation where the exchange/banking software didn't require 2FA to withdraw funds, BUT their monitoring noticed this situation. So their monitoring is smarter than their main application? Wow, just wow.
- deegles 5y agoResponding to escalations from customer support is a risk monitoring system, just not a very good one.
- kgermino 5y agoWorse, many companies can't even do that reliably.
- deleted 5y ago[deleted]
- Shank 5y ago> Which seems more likely, that these "risk monitoring systems" actually caught this, or that they were inundated by sudden urgent calls from the 483 users saying "DUDE WTF WHERE'S MY MONEY?". For better or for worse, a lot of insight can be gained from a sudden influx of tickets from normally-quiet users, all with the same general story. This is definitely how many critical bugs in production are caught, because even a small number of disparate users that suddenly write in about the same issue is a huge red flag. But, most likely, they have metrics on average withdrawal amounts, deposit amounts, etc., hooked up to something like datadog, with an off-the-shelf anomaly detection monitor.
- nathias 5y agoWhat is the robbery of a CEX compared to the founding of a CEX?
- zknill 5y agoThe Worldwide Account Protection Program seems to be a way for Crypto.com to limit their exposure, while marketing it as "protection" for the customers. Around $34million stolen, 483 users affected. If the funds were spread evenly, then each user would have lost about $71k. But the funds won't be evenly spread (average). It's likely some users will have lost much more, and some much less. From the announcement, it looks like Crypto.com is making the users whole again; > No customers experienced a loss of funds. This means that (in some cases) Crypto.com was on the hook for much more than $71k / user. The WAPP appears to put a series of conditions on the user, and introduce an upper limit to the amount that Crypto.com will return in the future. > WAPP restores funds up to USD$250,000 for qualified users; terms & conditions apply. > Enable Multi-Factor Authentication (MFA) on all transaction types where MFA is currently available, > Set up an anti-phishing code at least 21 days prior to the reported unauthorized transaction, > Not be using jailbroken devices, > File a police report and provide a copy of it to Crypto.com; and > Complete a questionnaire to support a forensic investigation. This looks more like a mechanism to limit Crypto.com's exposure to future events than it does a policy to protect users.
- loceng 5y agoAnd so what are we going to do as a society with these stolen funds? Playing a wallet mixing tracking game is a rat race and a waste of energy, otherwise we need a centralized system [on an immutable blockchain] to keep track of stolen funds, to then cross-reference every transaction with at point of sale/transfer - to then prevent it, no? If not a centralized solution like above then what? We just allow stolen funds to be used now or any point in the future, rewarding criminal behaviour?
- roywiggins 5y agoThere's no centralized system to track stolen dollars (at least not in the sense you're talking about), so I don't know why crypto would necessarily need one.
- capableweb 5y ago
- NoblePublius 5y agoFoRtUn3 faVor5 th3 thE boLd
- janandonly 5y agoNot your keys, not your coins....
- uptown 5y agoFortune favors the brave...and also apparently anyone who can circumvent the 2FA protections.
- kryogen1c 5y agoBoy this whole thing just reeks. > No customers experienced a loss of funds. In the majority of cases we prevented the unauthorized withdrawal, and in all other cases customers were fully reimbursed. so which is it? no one lost funds or everyone that lost funds got paid back? where did that money come from? > transactions were being approved without the 2FA authentication control being inputted by the user. the withdrawal system allows for non-2fa when its enabled, but informs the risk system when it happens? what kind of feature is that? > While Crypto.com already performs internal and external penetration tests, Crypto.com has immediately engaged with third-party security firms to perform additional security checks ah yes. the "we already had 7 double checkers, better add an 8th" solution. sounds like maybe the problem is not with the testing and auditing suite. > releasing additional end-user security features as we move away from 2-Factor Authentication and to true Multi-Factor Authentication (MFA) 2fa isnt true MFA? did we evolve some new jargon im not aware of? > WAPP is designed to protect user funds in cases where a third party gains unauthorized access to their account and withdraws funds without the user’s permission. WAPP restores funds wait i thought they said they already did this? are they gonna start charging for it now because they lost money? > To qualify for the WAPP program, users must: Set up an anti-phishing code at least 21 days prior to the reported unauthorized transaction wtf is that? a PSK? a TOTP? > File a police report and provide a copy of it to Crypto.com; and hello, local police department? i need to file a report - my cryptocurrency wallet just had an unauthorized funds withdrawal. no, i dont have a suspect, or evidence, or any action for you to take. just come down here and write down that i said this happened please.
- deleted 5y ago[deleted]
- vmception 5y agoThey got paid back from company treasury. CeFi (incorporated, custodial, web 2.0 financial services operating in the crypto space) makes alot of money, it isn’t that hard. Crypto.com is on par with FTX, Binance, Celsius, Coinbase and we have many varying examples of their valuations and supporting revenues and balance sheets. $30mm irrecoverably stolen with zero liability for the hacker? No problem for the user experience or health of the company these days.
- sneak 5y agoI still can't believe that Matt Blaze finally sold crypto.com to them, after so many years of refusing. We all have our price.
- the_svd_doctor 5y ago“Crypto.com will be releasing additional end-user security features as we move away from 2-Factor Authentication and to true Multi-Factor Authentication (MFA), providing added strength for our global user base.” What does this mean? Does MFA means xFA for x > 2?
- deleted 5y ago[deleted]
- iambateman 5y agoAct I: Matt Damon, looking out over the face of his space empire…”the Future belongs to the Brave” … Act II: thousands of men and women sign up to be brave with semi-retired Jason Bourne. … Act III: “we regret to inform you that our security protocols are a disaster”.
- ck2 5y agoThis somehow triggered me badly for the losses on Cryptsy.com (and missed out on settlement too! and domain name apparently is being re-used, ugh)
- ouid 5y agoI'm confused. Ostensibly the tradeoff for crypto is that only you know the secret factors that allow you to spend money, but there is no possibility of reversing a fraudulent transaction. If you give the keys to someone else, you lose the first condition, which was the benefit, but keep the second condition, which was the drawback. There was no reason to give anyone anyone else your keys!
- thr0wawayf00 5y agoThis is the downside of decentralization that doesn't get enough attention. Digital wallets are just too cumbersome to use on their own for the vast majority of people and carry a lot of risks. I like how when my credit card gets a fraudulent transaction, all I have to do is push a button on my phone and it magically goes away. This is a major, major benefit of having a central authority.
- vmception 5y agoDecentralized crypto currency is a benefit for everyone willing to take a shot at how much they can collect before they themselves get hacked. Its a human coordination mechanism that forces other humans to make it increasingly more resilient when under pressure. It is Machiavellian with no evolutionary dead ends, just mutating and hardening due to the needs of all of its ever growing participants. Rapid market based iteration on steroids.
- qqii 5y agoThere's no reason you cannot construct a token that can be frozen and reversed - USDT (other issues as side) being an example. Accounts as we know them don't have to be at the level of public address-private key but rather a smart contract as seen by Loopring. The difference is what was centralised is now decentralised, what was implicit and required trust is now explicit and requires formal verification.
- swalsh 5y agoUSDC has a blacklist feature too. I don't think funds are reversed though, just frozen (my rough understanding)
- londons_explore 5y agoWho backs this WAPP scheme? If it's just crypto.com, then it's worthless against a widespread hack of their infrastructure.
- KeAShizukuTio 5y agoNot your keys.
- ancode 5y agoPretty sure crypto.com doesn't actually hold some of the stuff they allow you to trade. Chia coin would be the example, they allow you to 'purchase' but not withdraw it to your own wallet.
- xyst 5y agoI signed up for an account at this CEX but never actually used it. Tried to cancel/close the account, and they have the weirdest set of demands before the account is deleted/closed. > A photo of you holding a paper with the following handwritten on it, as it states in this FAQ. - Your name - Today's Date - "Crypto.com” src: https://help.crypto.com/en/articles/3640569-how-to-close-crypto-com-account https://help.crypto.com/en/articles/3640569-how-to-close-cry...
- _robbywashere 5y agoThe money will be recovered. That amount cannot be washed anymore