Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Crypto.com

Crypto.com Vendor Cyber Rating & Cyber Score

crypto.com

Crypto.com was founded in 2016 and is the preferred crypto trading platform for over 100 million users worldwide, as well as the trusted industry leader in regulatory compliance, security, and privacy. We’re committed to accelerating the adoption of cryptocurrency through our vision: Cryptocurrency in Every Wallet™


Crypto.com A.I CyberSecurity Scoring

Crypto.com
Company Information
Website:https://www.crypto.com
Employees number:7,506
Number of followers:754,423
NAICS:52
Industry Type:Financial Services
Homepage:crypto.com
Crypto.com Risk Score (AI oriented)
Between 700 and 749
logo
Crypto.comFinancial Services
Updated:
02/04/2026
728/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Crypto.com Global Score (TPRM)
xxxx
logo
Crypto.comFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Crypto.com
Crypto.comModerate
Current Score
728Ba (MODERATE)
01000
2 incidents
-20 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
731Before Incident
MAY 2026
730Before Incident
APRIL 2026
728Before Incident
MARCH 2026
727Before Incident
FEBRUARY 2026
726Before Incident
JANUARY 2026
744Before Incident
Cyber Attack
01 Jan 2026Crypto.com
Facebook, Crypto.com and Microsoft: New 'Storm' Infostealer Remotely Decrypts Stolen Credentials

New Storm Infostealer Emerges as a Stealthy Threat to Browser and Crypto Security

724After Incident
CRITICAL-20
METMICCRY1775140151
New Storm Infostealer Emerges as a Stealthy Threat to Browser and Crypto Security Security researchers at Varonis have identified Storm, a sophisticated infostealer malware that harvests browser credentials, session cookies, and cryptocurrency wallets before exfiltrating encrypted data to attacker-controlled servers. First observed on underground cybercrime forums in early 2026, Storm represents an evolution in credential theft tactics, bypassing traditional detection methods. Unlike earlier infostealers that decrypted data locally making them vulnerable to endpoint security tools Storm avoids detection by transmitting encrypted files to remote infrastructure for decryption. This approach circumvents protections like Google’s App-Bound Encryption (introduced in Chrome 127 in July 2024), which previously forced attackers to rely on detectable methods such as Chrome injection or debugging protocol abuse. Storm targets both Chromium-based (Chrome, Edge) and Gecko-based browsers (Firefox, Waterfox, Pale Moon), extracting saved passwords, session cookies, autofill data, Google account tokens, credit card details, and browsing history. It also captures system information, screenshots, and session data from messaging apps like Telegram, Signal, and Discord, while targeting crypto wallets via browser extensions and desktop applications. All operations run in memory to minimize forensic traces. A key feature of Storm is its automation: rather than requiring manual replay of stolen logs, it uses Google Refresh Tokens and geographically matched SOCKS5 proxies to silently restore authenticated sessions, granting attackers access to SaaS platforms, internal tools, and cloud environments without triggering password-based alerts. Available for under $1,000 per month, Storm has already compromised victims across multiple countries, including Brazil, Ecuador, India, Indonesia, the U.S., and Vietnam. Varonis identified 1,715 entries in attacker panels, though some may include test data. The stolen credentials span high-value platforms such as Google, Facebook, Twitter/X, Coinbase, Binance, and Crypto.com data commonly sold on credential marketplaces for account takeovers, fraud, and further cyber intrusions.
INCIDENT DETAILS -
TYPE
Infostealer Malware
MOTIVATION
Financial gain (credential theft, fraud, account takeovers, crypto wallet compromise)
IMPACT
Data Compromised: Browser credentials, session cookies, autofill data, Google account tokens, credit card details, browsing history, system information, screenshots, messaging app session data, cryptocurrency wallet dataSystems Affected: Chromium-based browsers (Chrome, Edge), Gecko-based browsers (Firefox, Waterfox, Pale Moon), crypto wallet extensions, desktop applications (Telegram, Signal, Discord)Operational Impact: Unauthorized access to SaaS platforms, internal tools, and cloud environmentsIdentity Theft Risk: High (PII, financial data, and authentication tokens compromised)Payment Information Risk: High (credit card details and crypto wallet data exposed)
DATA BREACH
Browser credentialsSession cookiesAutofill dataGoogle account tokensCredit card detailsBrowsing historySystem informationScreenshotsMessaging app session dataCryptocurrency wallet dataNumber Of Records Exposed: 1,715 entries (some may include test data)Sensitivity Of Data: High (PII, financial data, authentication tokens, crypto wallet data)Data Exfiltration: Encrypted data transmitted to attacker-controlled servers for decryptionData Encryption: Data encrypted during exfiltration to bypass detectionPersonally Identifiable Information: Yes (saved passwords, autofill data, credit card details, Google account tokens)
DECEMBER 2025
744Before Incident
NOVEMBER 2025
743Before Incident
OCTOBER 2025
742Before Incident
SEPTEMBER 2025
741Before Incident
AUGUST 2025
740Before Incident
JULY 2025
739Before Incident
JUNE 2023
787Before Incident
Breach
16 Jun 2023Crypto.com
Crypto.com

Crypto.com Data Breach by Scattered Spider Hacking Group

709After Incident
CRITICAL-78
CRY0132901092125
Crypto.com suffered a data breach executed by the Scattered Spider hacking group, led by teenage cybercriminals including Noah Urban (18, Florida), who specialized in SIM-swapping and social engineering. The attack exposed personal information of users, though the company claimed only a 'very small number of individuals' were affected and no customer funds were stolen. However, Crypto.com never publicly disclosed the breach to impacted users, raising transparency concerns. The incident was uncovered by a Bloomberg investigation and blockchain investigator ZachXBT, who accused the company of a cover-up. Despite the breach, Crypto.com reported $1.5B in revenue and $1B in gross profit (2023), with CEO Kris Marszalek pushing for an IPO and partnerships (e.g., Trump Media). The attackers, originating from Minecraft gaming communities, exploited telecom employee deception to hijack phone numbers, escalating into high-profile cybercrime targeting MGM Resorts and other corporations.
INCIDENT DETAILS -
TYPE
Data BreachSocial EngineeringSIM-Swapping
MOTIVATION
Financial GainCriminal Enterprise
IMPACT
Personal Information of UsersNegative PublicityAccusations of Cover-UpLoss of TrustHigh (Due to Compromised Personal Information)None (No Customer Funds Accessed)
DATA BREACH
Personal InformationA Very Small Number (Exact Count Undisclosed)High (Personal Identifiable Information)ConfirmedConfirmed (Type Undisclosed)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Crypto.com ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Crypto.com's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Crypto.com's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Crypto.com ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Crypto.com's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?