Crypto.com, one of the world’s leading cryptocurrency exchanges, is facing scrutiny after a Bloomberg investigation revealed it may have suffered a security breach that was never disclosed. The report links the incident to Scattered Spider, a notorious hacking group known for using social engineering tactics. Comprising mostly teenagers, the group often tricks employees into surrendering credentials.
According to Bloomberg, attackers impersonated IT staff and convinced Crypto.com employees to hand over login details. Once inside, they attempted to escalate access by targeting senior staff accounts. The exchange admitted the incident impacted “a very small number of individuals,” but insisted no customer funds were compromised.
However, security experts argue that the lack of transparency undermines user trust. By withholding details, they warn that customers remain uncertain about the true scale of exposure and risk of future attacks. This concern echoes the case of Coinbase, which previously suffered a breach costing customers over $300 million annually.
Well-known blockchain investigator ZachXBT accused Crypto.com of deliberately covering up the incident, stressing this wasn’t the first time the exchange had been tied to undisclosed lapses. Critics across the industry argue that exchanges often downplay breaches to protect their reputation.
The controversy has also reignited debate around Know Your Customer (KYC) requirements, which create large databases of sensitive personal data. Pseudonymous researcher Pcaversaccio argued these systems serve as prime targets for hackers: “You can change a password, but not your passport.”
Broader concerns around data collection persist. Earlier this year, Coinbase CEO Brian Armstrong criticized the Bank Secrecy Act and anti-money laundering rules, calling them outdated and ineffective. He emphasized that companies are forced to collect sensitive customer data that does little to stop crime while increasing risk.
The alleged Crypto.com cover-up highlights ongoing challenges in crypto security and regulatory compliance, raising serious questions about transparency and trust in the industry.
Comment 0