Quietly, 1,598,263 Logins Surfaced in the CRYPTON_TXT Leak
No press release, no big announcement, just a quiet Telegram upload on 10-Oct-2025 called CRYPTON_TXT 10.10. Buried inside were 1,598,263 login records, making it one of the larger files in a string of CRYPTON_TXT uploads that have been trickling out over the past few weeks.
Why This Is Dangerous
The quiet nature of these releases is part of wich makes them so effective for criminals. A file this size draws less attention than a splashy corporate breach, so it can sit on criminal marketplaces for a long time before security researchers or the press catch wind of it, giving attackers a longer window to act.
What Was Exposed
The CRYPTON_TXT 10.10 upload contained:
- Email Addresses
- Plaintext Passwords
- URLs tied to each account
- 1,598,263 records exposed
Why This Matters
At over 1.5 million records, this file is large enough to power credential stuffing campaigns that hit dozens of major services at once. Passwords sitting in plaintext form make the job even easier, since there's no need to spend time or computing power cracking anything before it becomes usefull to an attacker.
How Stealer Logs Work
Stealer logs like this one are built by malware that infects a device and copies saved credentials straight from the browser, then packages everything into a single dump file. It happens in the background while the person keeps using their computer as normal, completely unaware anything is occuring.
Check If You Are Affected
With over a million and a half records in circulation from this leak alone, it's worth checking your own exposure directly. HEROIC's free breach scanner covers a database of more than 400 billion leaked records, so you can search your email and get a clear picture in seconds.
Breach Breakdown
1,598,263 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds