Crypto.com suspended cryptocurrency withdrawals on January 17, 2022 after users reported suspicious activity in their accounts. The exchange announced the pause at approximately 04:44 UTC, said it was investigating and told customers that their funds were safe.

The action mattered beyond the affected accounts. Crypto.com was a prominent centralized trading and custody platform, and stopping withdrawals interrupted the mechanism customers used to move assets into wallets or other venues. The incident therefore tested both the exchange’s account-security controls and the credibility of its assurances while the investigation was still incomplete.

A platform-wide response to account reports

Crypto.com initially characterized the reports as involving a “small number” of users. It did not identify the affected assets, quantify unauthorized transactions or explain how activity could have been approved when customers said they had enabled two-factor authentication. Those details were not established publicly on January 17.

At approximately 12:17 UTC, the company acknowledged that some accounts had experienced unauthorized activity. It said security was being enhanced across all accounts and required users to sign back into the Crypto.com App and Exchange and reset their two-factor authentication, or 2FA. The company said withdrawals would be enabled again after the update reached users.

That reset was significant because it applied a security response platform-wide rather than only to the accounts that had reported suspicious activity. Logging users out invalidated existing sessions, while revoking and re-establishing 2FA credentials created a new authentication boundary before withdrawals resumed. The measures showed that the company was treating the reports as more than an isolated customer-support dispute, although they did not disclose the underlying failure.

Crypto.com announced at approximately 17:42 UTC that withdrawals had resumed and warned users to expect processing backlogs. CoinDesk recorded the same sequence during January 17: suspension, mandatory account sign-in and 2FA reset, followed by the resumption notice.

Why withdrawal access was the central issue

Trading-platform security is not limited to whether an exchange’s aggregate reserves remain intact. Customers also depend on account authentication, withdrawal-address controls and the ability to transfer assets when needed. A platform can reimburse unauthorized withdrawals and still expose users to operational risk if credentials or transaction approvals do not function as represented.

The event also illustrated the limits of event-day visibility. Crypto.com controlled the relevant account records, authentication infrastructure and internal monitoring data. Public blockchains could show transfers from identified addresses, but they could not by themselves establish which transactions were authorized, which accounts were affected or whether the exchange would absorb the losses.

Contemporaneous reports cited individual users alleging missing bitcoin or ether, including transactions they said bypassed 2FA. Those were material warning signals, not yet a verified count or complete loss estimate. Coinburn therefore does not assign an event-day dollar value to the incident or treat social-media claims as an audited ledger.

What remained unknown on January 17

By the end of January 17, the verified record established that Crypto.com had received suspicious-activity reports, stopped withdrawals, forced an account and 2FA reset, and announced that withdrawals were operating again. It did not yet establish the number of affected customers, the total assets withdrawn or the precise technical mechanism.

No cryptocurrency price reaction is attributed to the incident. Crypto assets traded continuously across fragmented venues, and the reviewed sources provide no controlled measurement connecting the exchange interruption to a specific bitcoin, ether or CRO price move.

Later context

Crypto.com’s January 20 security report subsequently said the incident affected 483 users and involved unauthorized withdrawals totaling 4,836.26 ETH, 443.93 BTC and approximately $66,200 in other cryptocurrencies. The company said most withdrawals were stopped and affected customers were fully reimbursed. Those figures clarified the earlier record but were not publicly available when Crypto.com issued its January 17 notices.

Primary sourceCrypto.com — Initial January 17 withdrawal-suspension notice

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.