Cointime

Download App
iOS & Android

'Major Wake-Up Call': How $400M Coinbase Breach Exposes Crypto's Dark Side

What to know:

  • Coinbase said it will reimburse impacted users with up to $400 million following last week's data breach.
  • Security experts say the breach could have been prevented by imposing stricter background checks on staff and warning systems.
  • The breach draws comparisons to the Ledger incident in 2021, which led to a surge in real-world robberies.

Last week's highly organized breach of cryptocurrency exchange Coinbase (COIN) left behind more questions than answers.

While some hailed Coinbase's response as a "really great example" in dealing with a crisis, the breach has now caused a potentially massive privacy issue that mirrors the Ledger data breach in 2021 — which led to a spate of real-world robberies as criminals were able to get a hold of names and addresses of crypto holders. Coinbase has already acknowledged that its customers may have lost close to half a billion U.S. dollars as a result of its breach.

Cybercriminals accessed Coinbase user data by bribing and convincing Coinbase support employees to share that data, but this was entirely preventable, according to numerous experts that spoke to CoinDesk.

“A failsafe system would make stealing data technically impossible, but Coinbase clearly didn't prioritize these measures, leaving the door wide open,” Andy Zhou, co-founder of blockchain security firm BlockSec told CoinDesk.

Allowing these criminals to access personal data, whether through a hack or, in this case, social engineering, is a major blight on an exchange that facilitates billions of dollars worth of volume every day. The breach created a myriad of issues, including user privacy and trust. How could Coinbase, a publicly traded company, allow attackers to steal personal information and money through the front door? And could it have been prevented?

Hackett Communications CEO Heather Dale hailed Coinbase’s response as a “masterclass in communication,” but Coinbase’s method of tackling the issues was simple: throw as much money at it as possible.

The exchange offered a $20 million bug bounty for anyone who reported information that would lead to an arrest or prosecution. It also committed to voluntarily reimbursing impacted users with between $180 million to $400 million.

What happened?

Before analyzing the fallout of the breach, it’s important to understand how exactly the breach occurred at a publicly traded company that spends millions of dollars per month on security infrastructure.

In February, on-chain sleuth ZachXBT reported a rise in thefts involving Coinbase users. He said that it was “a result of aggressive risk models and Coinbase’s failure to stop its users losing $300 [million] per year to social engineering scams.”

The fear of cybercriminals stealing hundreds of millions of dollars became a reality last week when Coinbase published a blog post revealing that account balances, government ID images, phone numbers, addresses and masked bank account details were stolen.

Unlike other hacks and breaches, which involve attackers exploiting a faulty back-end, these attackers went in through the front door—communicating directly with Coinbase employees and buying access to the information via rogue insiders. Coinbase claimed that it fired all responsible employees on the spot, although it did not reveal the method it used to find those responsible in the blog post.

The issue, however, is not confined to crypto. In 2022, digital bank Revolut confirmed that 50,000 sets of customer data were stolen, while one year later, trading platform Robinhood had up to 5 million email addresses leaked. The latter was fined $45 million by the SEC following the breach after it emerged that a portion of customers had their accounts wiped by attackers.

The BBC reported in October that one particular Revolut user lost £165,000 ($220,0000) following a data breach and that the neobank’s fraud detection system prevented £475 million in fraudulent transactions in 2023.

Coinbase competitors Binance and Kraken said they managed to fend off similar social engineering attacks in recent weeks.

Coinbase CEO Brian Armstrong also posted a video on X last week, stating that he received a “ransom note” for $20 million in bitcoin in exchange for these attackers not releasing some information they claimed to have obtained on Coinbase customers.

ZachXBT added on Thursday that the attackers began obfuscating the stolen funds by swapping BTC for ETH on Thorchain, a venue often used by the infamous North Korean hackers Lazarus Group.

'Major wake-up call'

Andy Zhou, co-founder of blockchain security firm BlockSec, told CoinDesk that Coinbase should have conducted “stricter background checks on employees handling sensitive data " and set up “alarms for weird activity” like someone suddenly downloading thousands of customer profiles.

Zhou added that Coinbase should have implemented several technical solutions. These include strict role-based access, meaning employees only see necessary data, or privacy tools that allow work without exposing raw details (for example, blurring ID photos).

Nick Tausek, lead security automation architect at Swimlane, told CoinDesk that the breach should be a “major wake-up call” for robust insider threat detection.

“As outsourcing scales and operations stretch across time zones, insider threat detection and access governance cannot be afterthoughts. A single insider with the right access, or in this case, the wrong incentives, can punch a hole in even the most fortified security posture. Because, as this breach shows, it only takes 1% of customers breached to make 100% of the headlines.”

However, not everyone is piling onto Coinbase.

Michal Pospieszalk, CEO of MatterFi, said that it “isn’t a Coinbase problem, it’s a systemic vulnerability that’s plagued crypto since day one.”

He argued that the nature of sending crypto without an intermediary means that all platforms are one misstep away from disaster.

Hackers need to engineer a situation that can trick users into sending their funds in an irreversible transaction. In Coinbase's case, attackers gained access to personally identifiable information from a rogue employee.

The root issue, according to Pospieszalsk, is the problem of users not knowing whether they are sending funds to the right recipient, adding that crypto runs on a “trust me, bro” model of identity verification and that is not sustainable.

What happens next?

Coinbase said it would voluntarily reimburse customers who lost funds during the breach and would continue to work with law enforcement to capture those responsible. But for users, it’s a darker road.

The exchange said in a regulatory filing on Wednesday that the breach impacted 69,461 customers. The filing also noted that the breach occurred in December 2024 and was not discovered by Coinbase until May 15.

These details are out on the internet now, and may even be for sale on the dark web and in shady Telegram groups. After the Ledger breach, customer details were published on Raidforums, a nefarious data-sharing platform, which led to a rise in phishing attempts.

Unfortunately, Coinbase can't do anything to prevent the sharing of this leaked information, leaving the affected users to attempt to put in as many safeguards as possible. These include changing wallets, changing deposit addresses on exchanges and even changing home addresses to avoid the risk of real-world robberies. Users whose social security numbers were leaked should also lock their credit to prevent identity theft.

It may be cumbersome, but as seen earlier this year during the attempted kidnapping of Ledger co-founder David Balland (and several other individuals over the past few weeks), criminals will not stop until they extract the maximum amount of funds, even if it means inflicting brutal acts of violence.

This also raises a potential legal question: If a Coinbase customer were to be robbed or assaulted due to the data breach, would Coinbase be liable? Ledger failed to escape a proposed class action lawsuit earlier this year, with plaintiffs alleging that Ledger violated its privacy policy and should have had measures in place to prevent the breach.

Crypto researcher Molly White also pointed out that Coinbase changed its user agreement in April, adding two clauses limiting class action lawsuits and requiring lawsuits to be filed in New York, with changes being applied on May 15, the same day the breach was announced.

Coinbase responded to CoinDesk about White’s claims, stating that the exchange had “notified customers well in advance” of the user agreement change and that it had a class action waiver in place for “years.”

Coinbase did not, however, comment on questions related to whether the breach was preventable or how it will safeguard customers who could be at risk of real-world robberies in the future.

Comments

All Comments

Recommended for you

  • U.S. Military Strikes Iran for the 11th Consecutive Night

    On July 22, the U.S. Central Command announced that airstrikes against military targets in Iran began at 7 PM Eastern Time tonight, marking the 11th consecutive night of such actions. The strikes aim to continuously weaken Iran's ability to threaten commercial shipping in the Strait of Hormuz.

  • USD/JPY Breaks Above 163 Level

    On July 21, USD/JPY broke above the 163 level, reaching a new high since 1986, up 0.34% on the day.

  • Moonshot AI Reportedly in Pre-IPO Funding Talks at $50 Billion Valuation

    July 21, market news: Moonshot AI is reportedly in Pre-IPO funding talks at a $50 billion valuation.

  • Crypto Bank Augustus Completes $180 Million Funding Round, Led by Tiger Global

    On July 21, Augustus, a startup building a federally chartered clearing bank, announced it has raised $180 million to expand its dollar payment infrastructure as stablecoins reshape the global financial system. The funding round values Augustus at $1 billion. The round was led by Tiger Global Management, with participation from Hummingbird Ventures, QED Investors, and founders of Nubank, Ramp, Circle, and Deel, among other investors.

  • U.S. Trade Representative Greer Says U.S. Is Preparing New Tariffs

    July 21, according to the Wall Street Journal: U.S. Trade Representative Greer said the U.S. is preparing new tariffs.

  • US-listed crypto concept stocks surge; Circle jumps over 10%

    On July 21, Bitcoin returned to above $66,000, and US-listed crypto concept stocks collectively surged. Circle jumped over 10%, Coinbase rose over 9%, Robinhood gained over 6%, TeraWulf and Strategy increased over 4%, while Riot Platforms and CleanSpark rose over 2%.

  • Kalshi Applies to CFTC for Gold-Linked Perpetual Futures

    On July 21, prediction market platform Kalshi submitted an application to the U.S. Commodity Futures Trading Commission (CFTC) to launch gold-linked perpetual futures. (Jin Shi)

  • Official Meeting Between Interior Ministers of Iran and Pakistan Has Begun

    On July 21, according to the Iranian Students' News Agency, the official meeting between the Interior Minister of Iran and the Interior Minister of Pakistan began a few minutes ago.

  • Beijing: In-depth Implementation of 'AI+' Action Plan in the Second Half of the Year with Special Support Policies for Embodied Intelligence Enterprises

    On July 21, according to the Beijing News, the Beijing Municipal Bureau of Economy and Information Technology announced that in the second half of the year, it will focus on the annual key tasks of building a benchmark city for the digital economy and deeply implement the 'AI+' action plan to fully unleash new momentum for the intelligent economy. The plan aims to advance the comprehensive empowerment of artificial intelligence. It will promote AI-enabled new industrialization, establish R&D and pilot platforms for AI in the industrial sector, and enhance the application level of AI in core industrial production processes. Special support policies for computing power and datasets for embodied intelligence enterprises will be introduced to accelerate the iteration of core technologies such as embodied large models and motion control, leveraging embodied intelligence to drive industrial transformation and improve quality of life. The construction of a national (medical) AI application pilot base will be expedited, linking top-tier hospitals, research institutions, and technology companies to address the bottlenecks in the translation of medical intelligence from the laboratory to clinical application. The application of intelligent translation and simultaneous interpretation in the cultural and tourism consumption sectors will be promoted, expanding the range of languages and achieving hardware-software synergy. Additionally, a non-site intelligent supervision system for food safety will be improved to form a complete regulatory chain of intelligent early warning, remote inspection, and rapid response.

  • Beijing to Establish Token Factories in the Second Half of the Year

    On July 21, the Beijing Municipal Bureau of Economy and Information Technology reported that in the first half of the year, the city's digital economy grew by 7.8%, with the core industries of the digital economy increasing by 9.8%, significantly contributing to the city's GDP growth. In the second half of the year, Beijing will promote comprehensive empowerment through artificial intelligence, advancing applications such as intelligent translation and simultaneous interpretation in the cultural and tourism consumption sectors. The Bureau will focus on the annual key tasks for building a benchmark city for the digital economy, implementing the 'Artificial Intelligence +' action plan, and fully unleashing new momentum for the intelligent economy. Policies for the development of the Token economy will be formulated, focusing on key aspects such as Token production, distribution, and application, with plans to establish Token factories and distribution platforms, promoting innovative applications in key areas such as industry, education, and cultural tourism. An 'Innovate for the Future' OPC special roadshow event will be held to stimulate the creative energy of super individuals in AI applications. High-quality training courses on AIGC aimed at OPC will be developed to unlock the value of AIGC technology. Leveraging the Open Source Chip Research Institute and the Beijing Tongminghu Information Technology Application Innovation Center, a 'RISC-V + AI OS' open-source ecosystem will be created, building a full-stack autonomous technology system from chip instruction sets to operating systems to intelligent applications. (Xinjingbao)