Sat. Sep 19th, 2026

Crypto.com Multi-Asset Deposit Freeze Extends Beyond a Week With Security Cause Unexplained

ByShane Neagle

September 18, 2026 #Crypto.com
Crypto.comCrypto.com

Crypto.com has kept deposits suspended for a group of cryptocurrencies for more than a week while continuing to provide only a broad explanation that it is investigating an “ongoing security concern.”

The incident began on Sept. 7 at 14:15 HKT, when Crypto.com paused deposits for 22 assets spanning a large portion of the Cosmos and IBC ecosystem.

The original list included AKT, ARCH, ATOM, AXL, DYM, FET, INIT, INJ, JUNO, KAVA, LUNA, LUNA2, MANTRAEVM, MANTRA, NTRN, ORAI, OSMO, RUNE, SEIEVM, SEI, TIA and XPLA.

Crypto.com’s latest status page now lists 11 assets as still affected: AKT, ARCH, ATOM, AXL, DYM, FET, JUNO, KAVA, ORAI, RUNE and TIA.

That means INIT, INJ, LUNA, LUNA2, MANTRAEVM, MANTRA, NTRN, OSMO, SEIEVM, SEI and XPLA are no longer included in the active suspension notice.

Crypto.com has not explained why those networks were cleared while the other 11 remain restricted.

The exchange posted follow-up updates on Sept. 11 and Sept. 15 saying only that it was continuing to investigate the issue. It has not identified a compromised wallet, validator problem, exploit, custody provider or common infrastructure component connecting the affected assets.

The restriction applies to deposits. Crypto.com’s broader status dashboard does not indicate a general platform-wide withdrawal or trading outage.

One important exception is ORAI, which also appears in a separate incident that began on Aug. 12. In that older case, Crypto.com suspended both deposits and withdrawals for ONE, ORAI and RAVEN because of another unspecified security concern. That incident remains open and should not be merged automatically with the Sept. 7 event.

The composition of the newer suspension is nevertheless striking. ATOM, Akash, Axelar, Dymension, Juno, Kava, Celestia and Oraichain all sit within or close to the Cosmos ecosystem, while several assets removed from the original restriction — including Osmosis, Injective, Neutron and Sei — also share Cosmos-related infrastructure.

That clustering creates a plausible hypothesis that Crypto.com identified a shared dependency somewhere in its Cosmos-family deposit stack.

Possible layers include wallet infrastructure, node software, transaction monitoring, validator services, IBC processing or an external custody dependency. Crypto.com has not confirmed any of those explanations.

The timing also comes during heightened scrutiny of Cosmos security.

Cosmos EVM disclosed a critical vulnerability on Sept. 3 involving non-atomic state commits. Under specific conditions involving IBC refund handling, the flaw could allow an attacker to create spendable native balances without the corresponding debit being completed.

That disclosure followed an earlier Cosmos EVM vulnerability that was actively exploited in August across six networks. Attackers exchanged roughly $2.87 million of stolen assets through decentralized venues and an estimated additional $2.85 million through centralized exchanges.

There is no evidence Crypto.com’s suspension was caused by either Cosmos EVM issue. Several of the still-restricted networks do not fit neatly into a single Cosmos EVM explanation, making that connection too weak to state as the cause.

Recent events elsewhere show why exchanges may suspend deposits before they fully understand an upstream problem. The Nomic exploit affecting Osmosis created unbacked Bitcoin representations that remained undetected for weeks, while Osmosis later had to halt allBTC deposits and redemptions after discovering the backing deficit.

A similar accounting failure recently hit cross-chain infrastructure at Symbiosis, where an attacker minted billions of unauthorized syBTC before converting a much smaller amount into real liquidity.

And in the Liquid Network security incident, unbacked L-BTC was ultimately accepted by infrastructure that released genuine Bitcoin from reserves.

Those incidents are unrelated to Crypto.com, but they illustrate the risk an exchange faces if it continues crediting deposits from infrastructure whose state or backing may be uncertain.

The Recovery Pattern May Reveal More Than Crypto.com’s Updates

The most interesting part of this incident may now be the assets that have returned rather than the ones that remain suspended.

Crypto.com began with 22 affected tokens and has quietly reduced that number to 11 without publishing a technical explanation.

That looks like a selective validation process.

If all 22 assets were paused because Crypto.com suspected one shared component, removing individual chains after investigation would make sense. Engineers could verify wallet implementations, node versions, transaction paths or custody integrations one network at a time and restore deposits as each environment was cleared.

The sequence could therefore provide clues before Crypto.com publishes a formal post-mortem.

If networks sharing the same software or service provider return together, the common dependency becomes easier to identify. If chains with very different technical stacks are restored in no obvious grouping, the problem may sit further inside Crypto.com’s own deposit infrastructure.

This is increasingly how hidden infrastructure risk appears in crypto.

Users see an exchange deposit address and assume the transaction path is simple. Behind it can sit node operators, RPC services, wallet-management systems, blockchain analytics, custody infrastructure and cross-chain messaging components.

Companies are trying to hide more of that complexity as blockchain products move toward seamless wallet infrastructure. That improves usability, but it also means users often cannot see which dependency has failed when several networks suddenly stop working together.

The security logic behind Crypto.com’s caution is defensible. If there is uncertainty around whether a chain’s deposits can be trusted, stopping credits before questionable transactions reach customer balances is safer than trying to reverse them later.

But the information gap becomes harder to justify as the incident stretches beyond a week.

Crypto.com does not need to publish exploit instructions while a vulnerability remains live. It could still clarify whether customer assets are safe, whether the problem originated inside or outside Crypto.com and whether the remaining deposit suspensions are precautionary.

That matters because security incidents increasingly produce second-order risks even when funds are not directly stolen. The recent Brevo breach affecting crypto firms showed how one compromised infrastructure provider can expose multiple downstream companies to a shared threat.

The same principle applies to blockchain plumbing.

A single dependency used across many networks can make what initially looks like 20 separate asset suspensions one infrastructure incident.

For now, that remains a hypothesis rather than a conclusion.

But Crypto.com’s shrinking list offers a useful trail to follow. If the remaining 11 assets resume together, the case for a shared technical dependency becomes stronger. If they return individually over several days, it would point more toward chain-by-chain security validation.

Until Crypto.com explains the root cause, the clearest confirmed fact is also the most unusual one: more than a week after deposits were first paused across 22 assets, half of them have quietly returned while 11 remain suspended under the same unexplained “ongoing security concern.”

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *