Cointime

Download App
iOS & Android

'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

What to know:

  • Coinbase said it will reimburse impacted users with up to $400 million following last week's data breach.
  • Security experts say the breach could have been prevented by imposing stricter background checks on staff and warning systems.
  • The breach draws comparisons to the Ledger incident in 2021, which led to a surge in real-world robberies.

Last week's highly organized breach of cryptocurrency exchange Coinbase (COIN) left behind more questions than answers.

While some hailed Coinbase's response as a "really great example" in dealing with a crisis, the breach has now caused a potentially massive privacy issue that mirrors the Ledger data breach in 2021 — which led to a spate of real-world robberies as criminals were able to get a hold of names and addresses of crypto holders. Coinbase has already acknowledged that its customers may have lost close to half a billion U.S. dollars as a result of its breach.

Cybercriminals accessed Coinbase user data by bribing and convincing Coinbase support employees to share that data, but this was entirely preventable, according to numerous experts that spoke to CoinDesk.

“A failsafe system would make stealing data technically impossible, but Coinbase clearly didn't prioritize these measures, leaving the door wide open,” Andy Zhou, co-founder of blockchain security firm BlockSec told CoinDesk.

Allowing these criminals to access personal data, whether through a hack or, in this case, social engineering, is a major blight on an exchange that facilitates billions of dollars worth of volume every day. The breach created a myriad of issues, including user privacy and trust. How could Coinbase, a publicly traded company, allow attackers to steal personal information and money through the front door? And could it have been prevented?

Hackett Communications CEO Heather Dale hailed Coinbase’s response as a “masterclass in communication,” but Coinbase’s method of tackling the issues was simple: throw as much money at it as possible.

The exchange offered a $20 million bug bounty for anyone who reported information that would lead to an arrest or prosecution. It also committed to voluntarily reimbursing impacted users with between $180 million to $400 million.

What happened?

Before analyzing the fallout of the breach, it’s important to understand how exactly the breach occurred at a publicly traded company that spends millions of dollars per month on security infrastructure.

In February, on-chain sleuth ZachXBT reported a rise in thefts involving Coinbase users. He said that it was “a result of aggressive risk models and Coinbase’s failure to stop its users losing $300 [million] per year to social engineering scams.”

The fear of cybercriminals stealing hundreds of millions of dollars became a reality last week when Coinbase published a blog post revealing that account balances, government ID images, phone numbers, addresses and masked bank account details were stolen.

Unlike other hacks and breaches, which involve attackers exploiting a faulty back-end, these attackers went in through the front door—communicating directly with Coinbase employees and buying access to the information via rogue insiders. Coinbase claimed that it fired all responsible employees on the spot, although it did not reveal the method it used to find those responsible in the blog post.

The issue, however, is not confined to crypto. In 2022, digital bank Revolut confirmed that 50,000 sets of customer data were stolen, while one year later, trading platform Robinhood had up to 5 million email addresses leaked. The latter was fined $45 million by the SEC following the breach after it emerged that a portion of customers had their accounts wiped by attackers.

The BBC reported in October that one particular Revolut user lost £165,000 ($220,0000) following a data breach and that the neobank’s fraud detection system prevented £475 million in fraudulent transactions in 2023.

Coinbase competitors Binance and Kraken said they managed to fend off similar social engineering attacks in recent weeks.

Coinbase CEO Brian Armstrong also posted a video on X last week, stating that he received a “ransom note” for $20 million in bitcoin in exchange for these attackers not releasing some information they claimed to have obtained on Coinbase customers.

ZachXBT added on Thursday that the attackers began obfuscating the stolen funds by swapping BTC for ETH on Thorchain, a venue often used by the infamous North Korean hackers Lazarus Group.

'Major wake-up call'

Andy Zhou, co-founder of blockchain security firm BlockSec, told CoinDesk that Coinbase should have conducted “stricter background checks on employees handling sensitive data " and set up “alarms for weird activity” like someone suddenly downloading thousands of customer profiles.

Zhou added that Coinbase should have implemented several technical solutions. These include strict role-based access, meaning employees only see necessary data, or privacy tools that allow work without exposing raw details (for example, blurring ID photos).

Nick Tausek, lead security automation architect at Swimlane, told CoinDesk that the breach should be a “major wake-up call” for robust insider threat detection.

“As outsourcing scales and operations stretch across time zones, insider threat detection and access governance cannot be afterthoughts. A single insider with the right access, or in this case, the wrong incentives, can punch a hole in even the most fortified security posture. Because, as this breach shows, it only takes 1% of customers breached to make 100% of the headlines.”

However, not everyone is piling onto Coinbase.

Michal Pospieszalk, CEO of MatterFi, said that it “isn’t a Coinbase problem, it’s a systemic vulnerability that’s plagued crypto since day one.”

He argued that the nature of sending crypto without an intermediary means that all platforms are one misstep away from disaster.

Hackers need to engineer a situation that can trick users into sending their funds in an irreversible transaction. In Coinbase's case, attackers gained access to personally identifiable information from a rogue employee.

The root issue, according to Pospieszalsk, is the problem of users not knowing whether they are sending funds to the right recipient, adding that crypto runs on a “trust me, bro” model of identity verification and that is not sustainable.

What happens next?

Coinbase said it would voluntarily reimburse customers who lost funds during the breach and would continue to work with law enforcement to capture those responsible. But for users, it’s a darker road.

The exchange said in a regulatory filing on Wednesday that the breach impacted 69,461 customers. The filing also noted that the breach occurred in December 2024 and was not discovered by Coinbase until May 15.

These details are out on the internet now, and may even be for sale on the dark web and in shady Telegram groups. After the Ledger breach, customer details were published on Raidforums, a nefarious data-sharing platform, which led to a rise in phishing attempts.

Unfortunately, Coinbase can't do anything to prevent the sharing of this leaked information, leaving the affected users to attempt to put in as many safeguards as possible. These include changing wallets, changing deposit addresses on exchanges and even changing home addresses to avoid the risk of real-world robberies. Users whose social security numbers were leaked should also lock their credit to prevent identity theft.

It may be cumbersome, but as seen earlier this year during the attempted kidnapping of Ledger co-founder David Balland (and several other individuals over the past few weeks), criminals will not stop until they extract the maximum amount of funds, even if it means inflicting brutal acts of violence.

This also raises a potential legal question: If a Coinbase customer were to be robbed or assaulted due to the data breach, would Coinbase be liable? Ledger failed to escape a proposed class action lawsuit earlier this year, with plaintiffs alleging that Ledger violated its privacy policy and should have had measures in place to prevent the breach.

Crypto researcher Molly White also pointed out that Coinbase changed its user agreement in April, adding two clauses limiting class action lawsuits and requiring lawsuits to be filed in New York, with changes being applied on May 15, the same day the breach was announced.

Coinbase responded to CoinDesk about White’s claims, stating that the exchange had “notified customers well in advance” of the user agreement change and that it had a class action waiver in place for “years.”

Coinbase did not, however, comment on questions related to whether the breach was preventable or how it will safeguard customers who could be at risk of real-world robberies in the future.

Comments

All Comments

Recommended for you

  • Active Energy, a listed company, announced that it has purchased its first batch of Bitcoin, but the specific amount has not been disclosed

    renewable energy company Active Energy (AIM: AEG, OTCQB: ATGVF) has announced the implementation of its digital asset fund management policy and has completed its first digital asset allocation by purchasing Bitcoin. However, the specific purchase amount was not disclosed. Previously, the company raised £346,000 ($472,000), and its policy allows for a maximum of 30% of its liquid reserves to be invested in digital assets (70% invested in BTC).

  • Arcadia Finance: Please remove Rebalancer permissions immediately

     Arcadia Finance officially stated on X platform that the team has noticed attackers conducting unauthorized transactions through Rebalancer. The official urgently reminds users to immediately remove all Asset Manager permissions and remove all active Rebalancers.

  • Greenland (Asia) Securities has been approved to upgrade its Hong Kong digital asset business license

    according to Greenland Group, recently, Greenland Group's subsidiary Greenland (Asia) Securities has been granted an upgrade of the Hong Kong Securities and Futures Commission's licenses for digital asset advisory services (VA4) and digital asset portfolio management (VA9), marking a new breakthrough for Greenland in compliant operations and the digital asset field. In the future, Greenland will leverage the advantages of these licenses, innovate traditional asset management models through blockchain technology, and launch diversified digital asset products and services covering digital assets, tokenized real assets, digital currencies, and other trading and fund-raising businesses. 

  • BTC falls below $117,000

    the market shows BTC falling below $117,000, now at $116,958, a 24-hour decline of 2.39%. The market is volatile, so please manage your risks.

  • Japan's 10-year bond yield rises to 16-year high, 20-year bond yield rises to highest level since 1999

    the yield on Japan's 10-year government bond rose to a 16-year high, reaching 1.595% at one point. The yield on Japan's 20-year government bond rose to the highest level since 1999.

  • US Democrats call for full disclosure of Epstein case

    Jeffrey, the minority leader of the US House of Representatives and a Democrat, called for the release of all Epstein case files. Businessman Epstein had close ties with a large number of American political and business elites. After being arrested on suspicion of sexual crimes, he died in prison in August 2019, ruled as a "suicide". Trump promised to release the "client list" of Epstein during his presidential campaign, revealing Epstein's crimes and the truth behind his death. Some believe that this list will show that Epstein may have been silenced by blackmailing American political and business elites.

  • Mastercard: There is still a long way to go before stablecoins become a mainstream payment method

    Jorn Lambert, Chief Product Officer of American payment company Mastercard, said that stablecoins still have a long way to go before becoming a viable daily payment tool. Lambert stated that in addition to technical attributes, seamless and predictable user experience, wide coverage, and widespread consumer distribution are also essential for stablecoins to become a payment tool. Lambert stated that Mastercard positions itself as a bridge between digital assets and the traditional financial system, and can provide infrastructure to enable stablecoins to be used on a large scale.

  • Trump threatens 100% secondary tariffs on Russia

    Trump threatened to impose 100% tariffs on Russia.

  • Managing Director of Futu Group: The two Hong Kong licensed entities of the group have obtained the No. 1 license upgrade and virtual asset trading platform license respectively

    Mr. Zeng Yuchao, CEO of Futu Group, expressed his views on the hot topics in the market. Futu successfully upgraded its virtual license in July 2024. Futu Securities, a subsidiary of Futu Group, can now provide virtual asset trading services to Hong Kong investors, including retail investors. In August 2024, Futu Securities officially obtained a license to provide spot trading services for Bitcoin, Ethereum, USD, and HKD to eligible individual investors in Hong Kong. The services will gradually expand to include more trading pairs such as LINK and AVAX, as well as additional features like deposits and withdrawals. In January 2025, Panthertrade, a subsidiary of Futu Group, officially received the Virtual Asset Trading Platform License (VATP) issued by the Hong Kong Securities and Futures Commission, marking another important milestone in the group's compliance operations in the cryptocurrency field.

  • BTC breaks through $123,000

    the market shows BTC breaking through $123,000, now at $123,103.22, with a 24-hour increase of 4.33%. The market is volatile, so please manage risks.