Crypto.com has released a fuller postmortem on its previously disclosed security incident, confirming that 483 user accounts were affected by unauthorized cryptocurrency withdrawals on Jan. 17. According to the company, the stolen assets included 4,836.26 ETH, 443.93 BTC, and roughly $66,200 in other currencies. Based on the market prices cited in the report, the total value of the stolen bitcoin and ether alone exceeded $34 million.
Breakdown of the Unauthorized Withdrawals
The company’s disclosure provided a clearer picture of the scope of the breach. Crypto.com said the incident resulted in unauthorized withdrawals from hundreds of accounts, affecting a relatively limited subset of users but involving a significant amount of high-value crypto assets. Using the prices referenced in the article — about $42,083.95 per BTC and $3,178.94 per ETH — the losses tied to bitcoin and ether represented the overwhelming majority of the stolen funds.
The disclosure is notable because it moves beyond generic references to a security event and quantifies both the number of affected customers and the exact asset mix. That level of detail matters in the crypto industry, where trust often hinges on how quickly and transparently exchanges communicate after a breach.
CEO Says Users Were Fully Reimbursed
In comments to Bloomberg, Crypto.com CEO Kris Marszalek said the company had invested heavily in cybersecurity and built what he described as a multilayered security infrastructure. He noted that around 200 professionals worldwide had spent years developing the platform’s defenses. Even so, he acknowledged that in this case, some of those defensive layers were successfully bypassed.
Marszalek emphasized the company’s response time, saying Crypto.com was back online in roughly 13 to 14 hours. More importantly, he said all affected accounts were fully reimbursed on the same day, meaning customers did not bear the final financial loss. That point formed a central part of the company’s messaging after the incident: while funds were stolen, Crypto.com maintained that customer funds were never ultimately at risk because impacted users were made whole.
The CEO also framed the event as a learning moment for the company, saying it would continue to strengthen its infrastructure. In his view, the breach exposed areas where additional controls could be added, rather than undermining the broader scale of the business. He argued that, in context, the stolen amount was not material to the company’s operations, though the headline figure still underscored the seriousness of the incident.
New Security Measures and WAPP Rollout
Alongside the postmortem, Crypto.com announced a new protection initiative called the Worldwide Account Protection Program (WAPP). The company said the program is designed to provide additional security and protection for user funds held in the Crypto.com app and exchange.
According to the announcement, qualified users may be eligible for fund restoration of up to $250,000. While the company did not describe the program as a blanket guarantee for every circumstance, the launch of WAPP appears intended to reassure customers after the breach and demonstrate that the exchange is adding more formalized layers of user protection.
Marszalek also said Crypto.com was implementing additional layers of security and introducing new programs to reduce the risk of similar incidents in the future. Although the company did not publicly outline every technical safeguard in the cited report, the message was clear: the breach has triggered further hardening of the platform’s security architecture.
Regulatory Angle Remains Limited for Now
Because Crypto.com’s exchange operation is based in Singapore, questions also emerged about whether the country’s regulator had contacted the company. Marszalek said that at that stage, Crypto.com had not received any outreach from the Monetary Authority of Singapore (MAS).
Still, he noted that Crypto.com is a regulated business across multiple jurisdictions and expected that scrutiny could come. The company was preparing a report that it could share if and when inquiries were made. That response suggests the exchange was aware of the regulatory implications of such a high-profile incident, even if no immediate request had yet been made by Singapore’s central bank and financial regulator.
Why the Incident Matters
The Crypto.com hack highlights a familiar tension in the digital asset sector: even large, well-funded platforms with extensive compliance and security teams remain vulnerable to sophisticated attacks. The company’s emphasis on layered defenses, rapid restoration of service, and full reimbursement reflects the standards major exchanges increasingly need to meet after a breach.
At the same time, the event shows that post-incident handling can be almost as important as the breach itself. By disclosing the number of affected users, detailing the stolen assets, and rolling out a protection program with a stated cap of $250,000 for eligible customers, Crypto.com is seeking to position itself as transparent and operationally resilient.
For the broader market, the case serves as another reminder that security incidents remain a core operational risk for centralized crypto platforms. Even when customers are repaid, the reputational damage and the need for additional safeguards can be substantial. How exchanges respond — in terms of speed, reimbursement, communication, and security upgrades — continues to shape user confidence across the industry.

