Wed. Sep 16th, 2026

Crypto.com Multi-Asset Deposit Freeze Extends Beyond a Week With Security Cause Unexplained

ByShane Neagle

September 16, 2026 #Crypto.com
Crypto.comCrypto.com

Crypto.com has kept deposits suspended for a group of cryptocurrencies for more than a week while providing little detail beyond saying it is investigating an “ongoing security concern.”

The incident began at 14:15 HKT on Sept. 7, according to Crypto.com’s official status page. The exchange initially paused deposits across a broad group of assets concentrated heavily around the Cosmos and Inter-Blockchain Communication ecosystems.

Archived versions of the notice listed 22 affected assets: AKT, ARCH, ATOM, AXL, DYM, FET, INIT, INJ, JUNO, KAVA, LUNA, LUNA2, MANTRAEVM, MANTRA, NTRN, ORAI, OSMO, RUNE, SEIEVM, SEI, TIA and XPLA.

The live incident has since narrowed considerably. As of Sept. 16, Crypto.com continues to list deposit suspensions for AKT, ARCH, ATOM, AXL, DYM, FET, JUNO, KAVA, ORAI, RUNE and TIA.

That suggests deposits for 11 assets have been removed from the active restriction since the initial notice, although Crypto.com has not published individual restoration announcements explaining why particular networks were cleared while others remain under investigation.

Crypto.com posted an update on Sept. 11 saying it was continuing to investigate the issue. Another update on Sept. 15 used the same wording, leaving the incident unresolved more than eight days after it began.

The company has not publicly identified an exploit, compromised wallet, malicious transaction or external infrastructure provider behind the suspension. It also has not disclosed whether funds were lost or placed at immediate risk.

The current incident specifically concerns deposits rather than a platform-wide withdrawal freeze. Crypto.com’s broader status dashboard continues to show its exchange, application, withdrawals and most other services as operational.

ORAI is an exception worth separating from the new incident. Crypto.com has another unresolved notice dating to Aug. 12 covering deposits and withdrawals for ONE, ORAI and RAVEN, also attributed to an “ongoing security concern.” That older restriction predates the Sept. 7 multi-asset event and has not been publicly explained either.

The Asset List Points Toward Shared Infrastructure, but Not a Proven Cause

The composition of the Sept. 7 list is difficult to ignore.

ATOM, Akash, Axelar, Dymension, Juno, Kava, Celestia, Oraichain and several of the other affected networks are built around or closely connected to Cosmos technology. The original list also included Osmosis, Neutron, Injective, Sei and MANTRA-related networks.

That creates a plausible possibility that Crypto.com’s concern involves some common element in its Cosmos-family deposit infrastructure, such as wallet handling, node software, transaction monitoring, validators or IBC-related processing.

There is no public evidence yet establishing which, if any, of those layers is responsible.

The timing also overlaps with heightened security scrutiny around Cosmos technology. A critical Cosmos EVM vulnerability was publicly disclosed on Sept. 3 after an earlier exploit campaign affected multiple Cosmos-based networks. A separate critical issue disclosed the same day involved non-atomic state commits that could under specific circumstances allow an attacker to create spendable native balances through affected Cosmos EVM deployments.

Those developments followed an August Cosmos EVM exploit in which attackers stole funds from six networks. Cosmos Labs said approximately $2.87 million was moved through decentralized venues and another estimated $2.85 million was sold through centralized exchanges.

But linking Crypto.com’s Sept. 7 restrictions directly to those vulnerabilities would go beyond the available evidence.

Several assets that remain suspended are not simply interchangeable Cosmos EVM deployments, while some EVM-related networks from the original Crypto.com list have subsequently disappeared from the active restriction. That makes a single known Cosmos EVM bug an incomplete explanation for the current pattern.

The episode comes during an unusually active period for cross-chain bridge security. Symbiosis recently halted its native Bitcoin bridge after an attacker exploited its infrastructure to mint billions of unbacked syBTC, while other routes remained operational.

Earlier, the Liquid Network was forced to halt activity following a separate incident involving roughly $320 million in Bitcoin.

Those incidents are unrelated to Crypto.com’s current suspension, but they demonstrate why exchanges can react conservatively when there is uncertainty around network or cross-chain infrastructure. Accepting deposits from a chain whose accounting or bridging mechanisms may be unreliable can leave an exchange crediting assets that later prove invalid or unbacked.

The Interesting Part Is Which Assets Came Back

The biggest clue may not be the 11 assets that remain suspended.

It may be the 11 that disappeared from the restriction.

Crypto.com’s original list was broad enough to suggest a common precaution rather than 22 unrelated security events happening simultaneously. Since then, INIT, INJ, LUNA, LUNA2, MANTRAEVM, MANTRA, NTRN, OSMO, SEIEVM, SEI and XPLA have been removed from the active incident list.

That looks like selective clearance.

If Crypto.com is validating chains one at a time, the sequence in which deposits return could eventually reveal what it is testing. Networks that share a wallet implementation, node version, IBC component or custody integration may move together. If they do not, the common factor could sit deeper inside Crypto.com’s own infrastructure.

This is where exchange status pages become surprisingly useful investigative tools.

A company does not have to name its custody provider or disclose a vulnerability for the dependency to become visible. Sometimes the dependency can be reconstructed simply by comparing which assets fail together and which ones recover together.

Crypto infrastructure is increasingly built from those hidden layers. Wallets, validators, RPC providers, bridges, node software and institutional custody systems sit behind interfaces that make deposits look simple to customers. Similar dependency questions arise as companies build more complex blockchain infrastructure while trying to hide technical complexity from users.

Cross-chain systems add another layer. Stablecoins and other assets increasingly move through cross-chain networks, creating more connections between systems that were previously easier to isolate.

That normally improves usability. During a security incident, it makes determining the real blast radius much harder.

Crypto.com’s caution may therefore turn out to be exactly the right response. If its security systems identified uncertainty around deposits, disabling them before accepting questionable transactions is preferable to discovering a problem after customer balances have already been credited.

But the lack of explanation becomes harder to ignore as the suspension moves beyond a week.

Security teams sometimes deliberately withhold technical details while a vulnerability remains exploitable. That is reasonable. Publishing the affected code path too early can give attackers a roadmap.

There is still room between publishing exploit instructions and saying nothing beyond “ongoing security concern.” Crypto.com could clarify whether customer funds are safe, whether the problem sits with an external network or internal infrastructure, and whether the remaining restrictions are precautionary.

The distinction matters because crypto companies are dealing with increasingly sophisticated security threats, ranging from blockchain exploits to infrastructure and supply-chain security breaches.

It also matters for users trying to decide whether to send funds. A deposit suspension is inconvenient. Sending assets into infrastructure whose status is uncertain can be considerably worse.

The next useful signal may arrive before Crypto.com publishes a post-mortem. Watch the affected-asset list.

If another cluster of Cosmos-linked networks suddenly returns together, it may reveal which technical dependency has been cleared. If the remaining 11 all resume simultaneously, the evidence would point more strongly toward a shared component.

Until then, the only confirmed explanation remains the one Crypto.com gave on Sept. 7: an ongoing security concern that, more than a week later, the exchange says it is still investigating.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *