Reimbursement
Investigations tagged with this subject. A topic describes what a page is about — an attack type, a jurisdiction, a regulator, a named actor — as distinct from the source that produced it.
3 investigations on this topic
M2 is a UAE-based cryptocurrency exchange licensed by the Abu Dhabi Global Market (ADGM) Financial Services Regulatory Authority, operating as a regulated Multilateral Trading Facility and custodian since late 2023. On October 31, 2024, the exchange suffered a $13.7 million hot wallet breach attributed to an access control vulnerability across the Bitcoin, Ethereum, and Solana networks. M2 subsequently reimbursed all affected customers from its own assets and stated it had engaged law enforcement and regulatory authorities.
avoid.net/cryptocom→58/100[CAUTIONARY]Crypto.com is a Singapore-headquartered centralized cryptocurrency exchange founded in 2016 (originally as Monaco) by Kris Marszalek, Bobby Bao, Gary Or, and Rafael Melo. The platform has been subject to multiple serious security incidents, including a confirmed January 2022 hack in which $34 million was stolen via a 2FA bypass and laundered through Tornado Cash, and an alleged 2023 data breach linked to the Scattered Spider hacking group that the company did not publicly disclose to affected users. Blockchain investigator ZachXBT has publicly accused Crypto.com of governance manipulation and tokenomics fraud, citing the March 2025 reissuance of 70 billion CRO tokens that had been permanently burned in 2021, and the company's controversial 2020 forced swap from its original MCO token to CRO at unfavorable rates.
avoid.net/ledger→58/100[CAUTIONARY]Ledger is a France-based manufacturer of hardware cryptocurrency wallets (Nano S, Nano X, Stax, Flex) and maker of the Ledger Live companion app, reportedly securing over $100 billion in client assets across more than 7 million devices sold and preparing a US IPO targeting a valuation above $4 billion. The company has a strong core security record for its hardware products but has been repeatedly implicated in data-handling and supply-chain incidents: a 2020 breach of its own e-commerce/marketing database exposed roughly 1 million emails and 270,000 physical addresses, leading to years of phishing and alleged extortion attempts against customers and an ongoing US class action; a December 2023 npm supply-chain compromise via a former employee's account led to roughly $600,000 in DeFi losses; a May 2023 product announcement ('Ledger Recover') triggered a major trust backlash over perceived key-extraction capability; and in January 2026 a breach at third-party processor Global-e exposed customer order data. Separately, third parties impersonating Ledger — including a fraudulent 'Ledger Live' app that passed Apple App Store review in April 2026 — have caused further customer losses that Ledger did not directly control.