Crypto.com has released additional details about the security incident that led to unauthorized withdrawals from user accounts, revealing that 483 accounts were compromised in the Jan. 17 breach. According to the company’s postmortem, the stolen assets included 4,836.26 ETH, 443.93 BTC, and roughly $66,200 in other cryptocurrencies. Based on the market prices cited in the report, the total value of the stolen bitcoin and ether alone exceeded $34 million.
Breakdown of the stolen assets
The company said the breach affected a limited number of users relative to the scale of its business, but the value of the unauthorized withdrawals was still substantial. Using the prices referenced in the original report — $42,083.95 for bitcoin and $3,178.94 for ether — the BTC and ETH removed from affected accounts amounted to a loss worth more than $34 million at the time of publication. The inclusion of additional cryptocurrencies pushed the total economic impact even higher, though the company did not provide a broader asset-by-asset breakdown beyond the figures disclosed in its postmortem.
The scale of the theft quickly made the incident one of the more closely watched exchange security events at the time, especially because it involved both major crypto assets and a consumer-facing platform with a large international user base. In disclosing the number of impacted accounts and the exact token amounts, Crypto.com moved to address market speculation around the scope of the breach.
CEO says customers were fully reimbursed
Crypto.com CEO Kris Marszalek said the company responded rapidly once the unauthorized withdrawals were detected. In comments cited in the report, he said the platform was back up and running in about 13 to 14 hours. More importantly for customers, he stated that all affected users were fully reimbursed on the same day, arguing that there was ultimately no loss of customer funds despite the successful theft.
Marszalek acknowledged that the incident represented a serious security failure. He noted that Crypto.com had invested heavily in cybersecurity and maintained a team of around 200 professionals worldwide who had spent years building what he described as a robust, multilayered security infrastructure. Even so, he conceded that some of those defensive layers were breached in this case.
That admission is notable because it highlights a recurring tension in the digital asset industry: even well-funded platforms with sophisticated internal controls can remain vulnerable to targeted attacks. The company’s message was that the breach was contained quickly and that customer restitution was handled promptly, but it also framed the incident as a lesson that would lead to further hardening of its systems.
New safeguards and the WAPP program
Alongside the postmortem, Crypto.com announced an additional security initiative called the Worldwide Account Protection Program (WAPP). The company said the program would provide extra protection for eligible users holding funds in the Crypto.com app and on the Crypto.com exchange. Under the program, qualifying users may receive restoration of funds of up to $250,000.
The launch of WAPP appears to be part of a broader trust-restoration effort following the breach. Beyond reimbursement after the fact, the program is meant to give users a clearer sense of what protections are available in the event of future incidents. Crypto.com also said it is implementing additional layers of security and rolling out new programs designed to reduce the likelihood of similar unauthorized access events.
While the company did not outline every technical change in the material provided, the emphasis was clear: improve account-level defenses, reinforce existing controls, and supplement operational security with formalized user protection policies. In the wake of exchange hacks, market participants often focus not only on how much was lost, but also on whether the platform can transparently explain what happened and what it will change next.
Regulatory response and jurisdictional context
Because the Crypto.com exchange is based in Singapore, questions were raised about whether the Monetary Authority of Singapore (MAS) had contacted the company following the incident. Marszalek said that, at that stage, there had been no outreach from the regulator. However, he added that Crypto.com operates as a regulated business across multiple jurisdictions and was preparing a report that could be shared if and when inquiries were received.
That response suggests the company anticipated regulatory interest even if no formal contact had yet been made. For crypto platforms operating internationally, security incidents can trigger scrutiny not only from users and the market, but also from supervisory bodies assessing internal controls, incident response procedures, and consumer protection standards.
Why the incident matters
The Crypto.com breach underscores several persistent realities of the digital asset industry. First, exchange security remains a critical operational risk, regardless of platform size or brand recognition. Second, speed of response matters: the ability to suspend suspicious activity, restore services, and compensate affected users can influence whether an incident becomes a long-term reputational problem. Third, transparency in post-incident communication is now a key expectation among both users and regulators.
Marszalek argued that, given the scale of the business, the amount involved was not especially material to the company. Even so, the headline figures — 483 affected accounts and more than $34 million in stolen BTC and ETH — ensure that the hack will remain a significant case study in exchange risk management. For users, the event is another reminder that account security, platform safeguards, and reimbursement policies all matter when choosing where to hold and trade crypto assets.
Ultimately, Crypto.com’s handling of the aftermath rests on two claims: that affected customers were made whole, and that the platform is strengthening defenses to prevent a repeat. Whether those measures are sufficient will be judged over time, but the episode has already reinforced an uncomfortable truth for the sector: multilayer security systems can still fail, and trust must be rebuilt quickly when they do.

