Crypto.com team ‘covered up a breach’ – Scattered Spider breach, revealed!

ambcrypto發佈於 2025-09-21更新於 2025-09-22

Key Takeaways

Were Crypto.com customer funds affected?

No, Crypto.com confirmed that no customer funds were accessed or at risk. Only a very small number of users’ partial personal information was affected.

Did Crypto.com disclose the breach publicly?

No, the company did not publicly notify the impacted users, which drew criticism from blockchain investigator ZachXBT.


Crypto.com reportedly suffered a previously undisclosed data breach linked to the Scattered Spider hacking group, raising concerns over its security posture.

Details of the attack

According to a Bloomberg investigation, the attack involved teenage hackers, including 18-year-old Noah Urban from Florida, who specialized in phishing employees at telecom, tech, and cryptocurrency firms.

Urban and his collaborators accessed sensitive user information. The group previously targeted MGM Resorts and other corporations.

Crypto.com acknowledged that the breach impacted “a very small number of individuals” but emphasized that no customer funds were compromised.

Crypto.com’s response

Despite this, the company did not notify the affected users publicly.

Remarking on the same, Crypto.com CEO, Kris Marszalek, noted

“Any suggestion that we did not report or disclose a security incident is completely unfounded – as we reported in a NMLS Notice of Data Security incident filing and in additional reports with the relevant jurisdictional regulators, we detected a phishing campaign that targeted one of our employees in 2023.”

Marszalek stated that the incident was contained within hours, with no customer funds ever at risk, and only a very limited number of users’ partial personal information was affected.

He even emphasized the company’s “security-first” culture.

What does ZachXBT have to say about this breach?

However, blockchain investigator ZachXBT took to X to call out Crypto.com for not disclosing the data breach. He said,

“Your team covered up a breach that impacted the personal information of your users.”

He added

“They’ve been breached several times.”

That being said, the Crypto.com breach was part of a larger criminal campaign orchestrated by the Scattered Spider group, which had evolved from simple SIM-swapping to sophisticated corporate infiltration.

Florida native Noah Urban, then a teenager, acted as a “caller” inside the group, persuading employees to hand over credentials that unlocked internal systems.

Broader criminal campaign

The attack happened before March 2023. Urban was arrested nine months later, in January 2024, and charged with hacking 13 companies.

Authorities said the group also misused United Parcel Service data.

Following indictments of Urban and four accomplices, he pled guilty to wire fraud and aggravated identity theft.

It resulted in the seizure of $4.8 million in crypto, $13 million in restitution, and a 10-year prison sentence with additional supervised release.

All these disclosures coincided with CEO Marszalek’s predictions of a strong fourth-quarter performance and a partnership with Yorkville Acquisition Corp. and Trump Media to form Trump Media Group CRO Strategy, Inc., a digital asset treasury focused on acquiring Cronos (CRO).

Share

你可能也喜歡

天主教与执法团体警告CLARITY法案可能削弱打击加密货币犯罪的安全措施

一个由天主教领袖、执法相关团体及反贩卖倡导者组成的联盟警告称,《清晰法案》可能会削弱打击加密货币犯罪的安全措施。批评焦点在于法案中保护非托管软件开发者免受货币传输服务商待遇的条款。 这一争议触及了加密货币监管中最棘手的问题之一:如何区分中性软件与金融中介。加密倡导者认为,发布非托管代码的开发者不应像交易所或支付处理商那样受到监管。批评者则担心,广泛的豁免可能使追踪非法金融活动变得更加困难。 非托管软件是去中心化金融(DeFi)的核心。钱包、智能合约和去中心化协议通常允许用户在没有公司控制资金的情况下进行交易。这种架构是加密货币价值主张的核心部分,但当不法分子使用相同工具时,也带来了执法挑战。 《清晰法案》旨在制定更清晰的市场结构规则,但反对意见表明并非所有政策争论都围绕投资者保护或交易所注册。一些立法者在决定开发者保护应扩展到何种程度时,还会考虑人口贩卖、制裁逃避、欺诈以及执法可见性等因素。 尽管面临阻力,该法案并未夭折,但支持者可能需要回应法案可能为非法金融活动创造漏洞的担忧。这可能导致修正案、更狭窄的安全港规则或额外的报告要求。对加密公司而言,风险很高:更明确的规则可能在美国释放投资和产品开发潜力,但如果法案被定性为削弱犯罪防护,其政治道路将变得更为艰难。

bitcoinist3 小時前

天主教与执法团体警告CLARITY法案可能削弱打击加密货币犯罪的安全措施

bitcoinist3 小時前

加密独角兽 Blockstream 深陷严重欺诈始末

今年以来,比特币先驱Adam Back及其创立的Blockstream频繁引发争议。本月初,调查账号NatInfoSec发布长文,指控Blockstream发行的比特币矿业票据(BMN)可能存在严重问题。 指控核心包括:1. **算力与兑付能力存疑**:根据BMN的兑付义务,Blockstream需运营远超其公开显示的算力(约15 EH/s),但未在公开渠道找到相匹配的矿场、电力或算力证据。票据条款允许其以任意来源的BTC进行兑付,透明度不足。2. **高收益与高风险**:相关票据提供高达20%的固定年化收益,在波动剧烈的挖矿行业中难以持续,资金来源成疑。3. **关键人物前科与披露问题**:Blockstream矿业业务的重要关联方、Exacore CEO Christopher Cook曾被判邮件欺诈罪,但此前未在发行文件中披露,其背景陈述也存在夸大。4. **牵连BSTR上市计划**:质疑者担心BMN的潜在风险可能波及Adam Back关联的、正筹备SPAC上市的Bitcoin Standard Treasury Company(BSTR),尽管其法律独立性尚不明确。 BitMEX Research随后发表评论,承认Cook的前科属实且高收益令人担忧,但认为其他部分指控证据不足或存在误导,例如BMN与BSTR在法律上可能独立。社区争论焦点集中于Blockstream矿场算力的**可验证性**——投资者能否独立核查支撑收益的真实挖矿活动。 目前,围绕BMN仍存在几个关键疑问:实际发行规模与责任边界、矿场算力是否足以支撑兑付、近20%固定收益的具体来源、兑付资金的链上可验证性,以及Cook的实际角色。Blockstream尚未对此作出系统性回应。尽管指控有待最终证实,但BMN产品在透明度、风险披露和收益合理性方面,确实存在需要厘清的空间。

marsbit7 小時前

加密独角兽 Blockstream 深陷严重欺诈始末

marsbit7 小時前

交易

現貨
合約
活动图片