Thu. Sep 10th, 2026

Crypto.com Suspends Deposits for 22 Assets Over Security Concern

ByShane Neagle

September 9, 2026 #Crypto.com
CryptoCrypto

Crypto.com has suspended deposits for 22 cryptocurrencies over what it describes only as an “ongoing security concern,” with the restriction remaining unresolved more than two days after it was introduced.

The exchange paused deposits at 2:15 p.m. Hong Kong time on Sept. 7 and has yet to provide a detailed explanation of the security issue behind the decision.

The affected assets are Akash Network (AKT), Archway (ARCH), Cosmos (ATOM), Axelar (AXL), Dymension (DYM), Fetch.ai (FET), Initia (INIT), Injective (INJ), Juno (JUNO), Kava (KAVA), Terra (LUNA), Terra 2.0 (LUNA2), MANTRA EVM, MANTRA, Neutron (NTRN), Oraichain (ORAI), Osmosis (OSMO), THORChain (RUNE), Sei EVM, Sei (SEI), Celestia (TIA) and XPLA.

Crypto.com’s status page continues to classify the incident as under investigation.

The notice does not say whether Crypto.com itself suffered a security breach, whether the precaution relates to one or more underlying blockchain networks, or whether the exchange identified a risk in infrastructure shared by the affected assets.

There is also no indication in the notice that customer funds have been lost.

The restriction specifically applies to deposits of the 22 named assets. Crypto.com’s broader status dashboard continues to show buying, selling, sending and withdrawals as operational, suggesting the incident is not a general shutdown of the exchange’s crypto wallet services.

Users should nevertheless check individual assets inside the app before initiating transfers because network availability can differ from the platform-wide status.

The composition of the affected list is notable.

A large majority of the suspended assets belong to, were built using, or maintain close technical links with the broader Cosmos ecosystem. ATOM, OSMO, JUNO, KAVA, NTRN, TIA, DYM, AKT, INJ and several others use Cosmos technology or participate in its interchain environment.

That concentration raises the possibility that Crypto.com is responding to an infrastructure or network-level risk rather than an incident isolated to one token.

Crypto.com, however, has not confirmed such a connection.

The timing comes shortly after the Cosmos ecosystem disclosed multiple serious security vulnerabilities.

In late August, Cosmos Labs published a post-mortem covering an actively exploited Cosmos EVM vulnerability that affected six networks between Aug. 20 and Aug. 25.

Attackers exploited a chain of software flaws to create or extract assets improperly on affected networks. Cosmos Labs estimated that approximately $2.87 million in stolen assets was moved through decentralized exchanges, with another estimated $2.85 million sold through centralized exchanges.

The company coordinated remediation efforts with around 40 Cosmos-based networks and released patched versions of Cosmos EVM.

A separate critical Cosmos EVM security advisory was published on Sept. 3.

That vulnerability involved non-atomic state commits and the ERC-20 IBC middleware. Under specific conditions, an attacker could manipulate a failed cross-chain transaction so that a credit remained in the blockchain state without the corresponding debit, effectively creating spendable native balances without legitimate backing.

Patched Cosmos EVM versions 0.6.3 and 0.7.3 were released to address the flaw.

There is currently no public evidence that this vulnerability caused Crypto.com’s Sept. 7 suspension, and many of the assets affected by the exchange’s precaution are not necessarily exposed to that specific Cosmos EVM issue.

The previous incidents nevertheless provide relevant context for why an exchange might temporarily stop accepting deposits across a broad group of interconnected networks while validating chain state, wallet infrastructure or software versions.

Centralized exchanges face particular risks when a blockchain suffers an inflation, accounting or consensus-related exploit.

If an attacker can generate invalid or unbacked tokens and deposit them into an exchange before the problem is detected, those assets may be sold for bitcoin, stablecoins or other legitimate cryptocurrencies. The attacker can then withdraw the proceeds, turning a blockchain vulnerability into a direct loss for the exchange.

Suspending deposits prevents that route while allowing the platform to determine whether incoming assets can be trusted.

Crypto.com has previously used temporary deposit and withdrawal restrictions as a security precaution when individual networks encounter operational or security problems.

The scale of the latest suspension is more unusual because 22 assets were halted simultaneously under a single security notice.

The exchange has not provided an estimated restoration time or said what conditions must be satisfied before deposits resume.

Until it does, the central unanswered question remains the same: whether Crypto.com is responding to a known exploit, a newly discovered vulnerability or simply taking a broad precaution while a potential threat is investigated.

The Asset List May Be the Biggest Clue

The phrase “ongoing security concern” is deliberately vague, but the list of assets tells us more than the status message does.

Crypto.com did not randomly suspend 22 unrelated cryptocurrencies.

The list is overwhelmingly concentrated around Cosmos-connected networks.

That does not prove the problem sits inside Cosmos, IBC or Cosmos EVM. THORChain, Celestia, Injective, Sei and the other affected projects have different architectures, software versions and security assumptions.

But when an exchange simultaneously freezes deposits across such a closely related group, shared infrastructure becomes the obvious area to investigate.

There is a practical reason exchanges react aggressively to this type of risk.

Imagine a vulnerability that allows an attacker to create tokens that appear valid on-chain. The attacker does not necessarily need those tokens to retain value for long.

They only need an exchange to credit the deposit.

Once credited, the attacker can sell the questionable asset for USDT, Bitcoin or another liquid cryptocurrency and attempt to withdraw the proceeds. By the time the originating blockchain reverses transactions, halts or identifies the invalid supply, the exchange may be left holding the loss.

That is why deposit suspension is often the first defensive action.

And the fact that Crypto.com appears to have kept withdrawals and trading broadly operational is important.

It suggests the immediate concern may be about accepting new coins from particular networks rather than uncertainty over assets already held inside Crypto.com.

If that interpretation is correct, the exchange is effectively saying: customers can continue using the platform, but we are not prepared to trust incoming transactions from these networks yet.

The bigger problem is communication.

A temporary precaution lasting a few hours requires little explanation. A restriction covering 22 assets and continuing for more than two days deserves more detail.

Crypto.com does not need to publish technical information that could help an attacker exploit an unresolved vulnerability.

It could still tell customers whether the issue originates with Crypto.com, an external infrastructure provider or the affected blockchain networks, whether customer assets remain safe and whether withdrawals are fully unaffected.

Those distinctions matter.

“Security concern” can mean anything from a theoretical vulnerability being patched out of caution to an active exploit involving real losses.

Leaving that range unexplained invites speculation.

The recent Cosmos security incidents make that speculation particularly understandable. The ecosystem has already dealt with an actively exploited EVM vulnerability and another critical flaw disclosed only days before Crypto.com imposed the deposit restrictions.

But correlation is not attribution.

Until Crypto.com or the affected network teams establish a link, those vulnerabilities should remain background rather than an explanation for the suspension.

What makes this story worth following is precisely what is still missing.

Twenty-two assets were restricted simultaneously. The restriction has lasted for days. Crypto.com says security is the reason.

It still has not said what the security problem actually is.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *