Hacker News new | ask | show | jobs
by FlacoJones 1613 days ago
If they had access to the private keys they wouldn't have to go through the crypto.com platform at all.

They'd just pop it in any wallet and sign withdrawal transactions.

There's no 2FA or whitelisted withdrawal addresses (for most tokens) or emails on-chain.