Cointime

Download App
iOS & Android

'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

What to know:

  • Coinbase said it will reimburse impacted users with up to $400 million following last week's data breach.
  • Security experts say the breach could have been prevented by imposing stricter background checks on staff and warning systems.
  • The breach draws comparisons to the Ledger incident in 2021, which led to a surge in real-world robberies.

Last week's highly organized breach of cryptocurrency exchange Coinbase (COIN) left behind more questions than answers.

While some hailed Coinbase's response as a "really great example" in dealing with a crisis, the breach has now caused a potentially massive privacy issue that mirrors the Ledger data breach in 2021 — which led to a spate of real-world robberies as criminals were able to get a hold of names and addresses of crypto holders. Coinbase has already acknowledged that its customers may have lost close to half a billion U.S. dollars as a result of its breach.

Cybercriminals accessed Coinbase user data by bribing and convincing Coinbase support employees to share that data, but this was entirely preventable, according to numerous experts that spoke to CoinDesk.

“A failsafe system would make stealing data technically impossible, but Coinbase clearly didn't prioritize these measures, leaving the door wide open,” Andy Zhou, co-founder of blockchain security firm BlockSec told CoinDesk.

Allowing these criminals to access personal data, whether through a hack or, in this case, social engineering, is a major blight on an exchange that facilitates billions of dollars worth of volume every day. The breach created a myriad of issues, including user privacy and trust. How could Coinbase, a publicly traded company, allow attackers to steal personal information and money through the front door? And could it have been prevented?

Hackett Communications CEO Heather Dale hailed Coinbase’s response as a “masterclass in communication,” but Coinbase’s method of tackling the issues was simple: throw as much money at it as possible.

The exchange offered a $20 million bug bounty for anyone who reported information that would lead to an arrest or prosecution. It also committed to voluntarily reimbursing impacted users with between $180 million to $400 million.

What happened?

Before analyzing the fallout of the breach, it’s important to understand how exactly the breach occurred at a publicly traded company that spends millions of dollars per month on security infrastructure.

In February, on-chain sleuth ZachXBT reported a rise in thefts involving Coinbase users. He said that it was “a result of aggressive risk models and Coinbase’s failure to stop its users losing $300 [million] per year to social engineering scams.”

The fear of cybercriminals stealing hundreds of millions of dollars became a reality last week when Coinbase published a blog post revealing that account balances, government ID images, phone numbers, addresses and masked bank account details were stolen.

Unlike other hacks and breaches, which involve attackers exploiting a faulty back-end, these attackers went in through the front door—communicating directly with Coinbase employees and buying access to the information via rogue insiders. Coinbase claimed that it fired all responsible employees on the spot, although it did not reveal the method it used to find those responsible in the blog post.

The issue, however, is not confined to crypto. In 2022, digital bank Revolut confirmed that 50,000 sets of customer data were stolen, while one year later, trading platform Robinhood had up to 5 million email addresses leaked. The latter was fined $45 million by the SEC following the breach after it emerged that a portion of customers had their accounts wiped by attackers.

The BBC reported in October that one particular Revolut user lost £165,000 ($220,0000) following a data breach and that the neobank’s fraud detection system prevented £475 million in fraudulent transactions in 2023.

Coinbase competitors Binance and Kraken said they managed to fend off similar social engineering attacks in recent weeks.

Coinbase CEO Brian Armstrong also posted a video on X last week, stating that he received a “ransom note” for $20 million in bitcoin in exchange for these attackers not releasing some information they claimed to have obtained on Coinbase customers.

ZachXBT added on Thursday that the attackers began obfuscating the stolen funds by swapping BTC for ETH on Thorchain, a venue often used by the infamous North Korean hackers Lazarus Group.

'Major wake-up call'

Andy Zhou, co-founder of blockchain security firm BlockSec, told CoinDesk that Coinbase should have conducted “stricter background checks on employees handling sensitive data " and set up “alarms for weird activity” like someone suddenly downloading thousands of customer profiles.

Zhou added that Coinbase should have implemented several technical solutions. These include strict role-based access, meaning employees only see necessary data, or privacy tools that allow work without exposing raw details (for example, blurring ID photos).

Nick Tausek, lead security automation architect at Swimlane, told CoinDesk that the breach should be a “major wake-up call” for robust insider threat detection.

“As outsourcing scales and operations stretch across time zones, insider threat detection and access governance cannot be afterthoughts. A single insider with the right access, or in this case, the wrong incentives, can punch a hole in even the most fortified security posture. Because, as this breach shows, it only takes 1% of customers breached to make 100% of the headlines.”

However, not everyone is piling onto Coinbase.

Michal Pospieszalk, CEO of MatterFi, said that it “isn’t a Coinbase problem, it’s a systemic vulnerability that’s plagued crypto since day one.”

He argued that the nature of sending crypto without an intermediary means that all platforms are one misstep away from disaster.

Hackers need to engineer a situation that can trick users into sending their funds in an irreversible transaction. In Coinbase's case, attackers gained access to personally identifiable information from a rogue employee.

The root issue, according to Pospieszalsk, is the problem of users not knowing whether they are sending funds to the right recipient, adding that crypto runs on a “trust me, bro” model of identity verification and that is not sustainable.

What happens next?

Coinbase said it would voluntarily reimburse customers who lost funds during the breach and would continue to work with law enforcement to capture those responsible. But for users, it’s a darker road.

The exchange said in a regulatory filing on Wednesday that the breach impacted 69,461 customers. The filing also noted that the breach occurred in December 2024 and was not discovered by Coinbase until May 15.

These details are out on the internet now, and may even be for sale on the dark web and in shady Telegram groups. After the Ledger breach, customer details were published on Raidforums, a nefarious data-sharing platform, which led to a rise in phishing attempts.

Unfortunately, Coinbase can't do anything to prevent the sharing of this leaked information, leaving the affected users to attempt to put in as many safeguards as possible. These include changing wallets, changing deposit addresses on exchanges and even changing home addresses to avoid the risk of real-world robberies. Users whose social security numbers were leaked should also lock their credit to prevent identity theft.

It may be cumbersome, but as seen earlier this year during the attempted kidnapping of Ledger co-founder David Balland (and several other individuals over the past few weeks), criminals will not stop until they extract the maximum amount of funds, even if it means inflicting brutal acts of violence.

This also raises a potential legal question: If a Coinbase customer were to be robbed or assaulted due to the data breach, would Coinbase be liable? Ledger failed to escape a proposed class action lawsuit earlier this year, with plaintiffs alleging that Ledger violated its privacy policy and should have had measures in place to prevent the breach.

Crypto researcher Molly White also pointed out that Coinbase changed its user agreement in April, adding two clauses limiting class action lawsuits and requiring lawsuits to be filed in New York, with changes being applied on May 15, the same day the breach was announced.

Coinbase responded to CoinDesk about White’s claims, stating that the exchange had “notified customers well in advance” of the user agreement change and that it had a class action waiver in place for “years.”

Coinbase did not, however, comment on questions related to whether the breach was preventable or how it will safeguard customers who could be at risk of real-world robberies in the future.

Comments

All Comments

Recommended for you

  • Iran and Gulf States to Hold Meeting Next Week to Advance Strait of Hormuz Agreement

    On September 11, the Financial Times reported that foreign ministers from Gulf states plan to meet with the Iranian foreign minister in response to initiatives from Oman and Iran, seeking support for an agreement on the temporary management of shipping in the Strait of Hormuz. Meanwhile, countries in the region are looking for ways to ease the hostile situation surrounding this waterway. This meeting, proposed by Oman, will be the first between senior diplomats from the Gulf Cooperation Council, consisting of six member states, and Iranian officials since the outbreak of the U.S.-Iran conflict at the end of February. According to sources, the meeting is scheduled to take place next Monday in Salalah, a coastal city in Oman. Details have not been finalized, but several countries have confirmed that the meeting is expected to proceed as planned. If the meeting takes place, it will highlight the region's urgency to attempt to reopen the strait and ease U.S.-Iran tensions.

  • Iran and Gulf States to Hold Meeting Next Week to Advance Hormuz Strait Agreement

    On September 11, the Financial Times reported that foreign ministers from Gulf states plan to meet with the Iranian foreign minister in response to initiatives from Oman and Iran, seeking support for an agreement on the temporary management of shipping in the Hormuz Strait. Meanwhile, countries in the region are looking for ways to ease the hostile situation surrounding this waterway. This meeting, proposed by Oman, will be the first encounter between senior diplomats from the Gulf Cooperation Council, comprising six member states, and high-ranking Iranian officials since the outbreak of U.S.-Iran conflicts in late February. According to sources, the meeting is scheduled to take place next Monday in Salalah, a coastal city in Oman. Details have yet to be finalized, but several countries have confirmed their participation, and the meeting is expected to proceed as planned. If the meeting takes place, it will underscore the region's urgency in attempting to reopen the strait and de-escalate U.S.-Iran hostilities.

  • US Spot Bitcoin ETF Sees $282.7 Million Net Outflow

    According to monitoring data from Farside Investors, the US spot Bitcoin ETF experienced a net outflow of $282.7 million yesterday, September 11.

  • US Spot Bitcoin ETF Sees $282.7 Million Net Outflow

    According to monitoring data from Farside Investors, the US spot Bitcoin ETF experienced a net outflow of $282.7 million on September 11.

  • US Spot Ethereum ETF Sees Net Outflow of $29.9 Million Yesterday

    On September 11, according to monitoring data from Farside Investors, the US spot Ethereum ETF experienced a net outflow of $29.9 million yesterday.

  • US Spot Ethereum ETF Sees Net Outflow of $29.9 Million Yesterday

    On September 11, according to monitoring data from Farside Investors, the US spot Ethereum ETF experienced a net outflow of $29.9 million yesterday.

  • Sources: Bank of Japan Expected to Raise Rates by 25bps Next Week with No Predefined View on Terminal Rate

    On September 11, sources revealed that the Bank of Japan is expected to raise interest rates next week, most likely by 25 basis points, and may indicate a faster tightening pace if inflationary pressures increase. Raising rates to 1.25% would mark the highest policy rate for the Bank of Japan in 31 years. The move comes just three months after the last rate hike in June, signaling an acceleration in tightening measures. Many within the central bank believe that as the economy enters a moderate recovery and price pressures build, the conditions for another rate hike are becoming favorable. The central bank also anticipates that even if rates rise to 1.25%, financial conditions will remain accommodative. The market is closely watching Governor Ueda's comments after the meeting for any clues regarding the future pace of rate hikes and the potential peak rate in this tightening cycle. Sources indicated that the Bank of Japan may have no predefined view on the terminal rate, which will depend on how past rate hikes affect the economy and the extent to which businesses pass on rising costs to households. There is also no consensus within the Bank of Japan on the speed of rate hikes. Ueda is expected to avoid committing to a specific timeline for future rate increases but may reiterate the July statement that if financial conditions are deemed too loose, the Bank of Japan may accelerate rate hikes.

  • Sources: BOJ Expected to Raise Rates by 25bps Next Week Without Predefined Terminal Rate View

    On September 11, sources revealed that the Bank of Japan (BOJ) is expected to raise interest rates next week, most likely by 25 basis points, and may hint at a faster tightening pace if inflationary pressures increase. Raising the rate to 1.25% would mark a 31-year high for the BOJ's policy rate. This move comes just three months after the last hike in June, indicating a quicker tightening pace. Many within the central bank believe that conditions for another rate increase are forming as the economy enters a moderate recovery and price pressures build. The BOJ also anticipates that even with rates rising to 1.25%, financial conditions will remain accommodative. The market is closely watching Governor Kazuo Ueda for any clues regarding the future pace of rate hikes and the potential peak rate in this tightening cycle. Sources indicate that the BOJ may not have a predefined view on the terminal rate, as it depends on how past rate hikes affect the economy and the extent to which businesses pass on rising costs to households. There is also no consensus within the BOJ on the speed of rate hikes. Ueda is expected to avoid committing to a specific timeline for future rate increases but may reiterate his July statement that the BOJ could accelerate rate hikes if it believes financial conditions are too loose.

  • SEC Proposes Amendments to Transfer Agent Rules, Allowing Blockchain Ledgers as Official Records of Securities Ownership

    On September 11, the U.S. Securities and Exchange Commission (SEC) proposed a new rule that aims to comprehensively amend the transfer agent rules that have been in place for decades. For the first time, the proposal explicitly allows electronic databases, including blockchain ledgers, to serve as official records of securities ownership. If approved, blockchain could become the 'primary securities document,' replacing the off-chain parallel ownership records that tokenized securities currently rely on. Currently, many tokenized securities operate on two sets of records: an on-chain token ledger and an official shareholder register. Once the proposal is passed, issuers and transfer agents may no longer need to maintain duplicate records and reconcile them after each transfer, thereby reducing operational friction and the risk of inconsistencies between on-chain records and legally recognized records. Eli Cohen, Chief Legal Officer of the tokenized fund platform Centrifuge, stated that this proposal could transform the current 'two-step' process into a 'one-step' process, allowing the blockchain itself to act as the primary securities document. However, the proposal does not imply that tokenized securities will be completely 'permissionless.' Joris Delanoue, CEO of the SEC-registered on-chain transfer agent Fairmint, pointed out that while the blockchain can remain open, assets must still comply with ownership and transfer rules, and regulatory controls such as identity verification and transfer restrictions will still be embedded in the tokens. Transfer agents will still need to handle administrative matters such as shareholder death, inheritance, and legal notifications, with processing times potentially reduced from 3-5 days to 1 day. The 60-day public comment period for the proposal will end in early November.

  • SEC Proposes Amendments to Transfer Agent Rules, Allowing Blockchain Ledgers as Official Securities Ownership Records

    On September 11, the U.S. Securities and Exchange Commission (SEC) proposed a new rule last week aimed at comprehensively revising the transfer agent rules that have been in place for decades. For the first time, it explicitly allows electronic databases, including blockchain ledgers, to serve as official records of securities ownership. If approved, blockchain is expected to become the 'primary securities document,' replacing the off-chain parallel ownership records that tokenized securities currently rely on. Currently, many tokenized securities operate on two sets of records: an on-chain token ledger and an official shareholder register. Once the proposal is passed, issuers and transfer agents may no longer need to maintain duplicate records and reconcile them after each transfer, thereby reducing operational friction and the risk of inconsistencies between on-chain records and legally recognized records. Eli Cohen, Chief Legal Officer of the tokenized fund platform Centrifuge, stated that the proposal could transform the current 'two-step' process into a 'one-step' process, allowing the blockchain itself to serve as the primary securities document. However, the proposal does not mean that tokenized securities will be completely 'permissionless.' Joris Delanoue, CEO of Fairmint, a registered on-chain transfer agent, pointed out that while the blockchain can remain open, assets must still comply with ownership and transfer rules, and regulatory controls such as identity verification and transfer restrictions will still be embedded in the tokens. Transfer agents will still need to handle administrative matters such as shareholder death, inheritance, and legal notifications, with processing times potentially reduced from 3-5 days to 1 day. The 60-day public comment period for the proposal will end in early November.