/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Source: Coinbase's hackers had bribed enough customer service representatives to achieve effectively on-demand access to customer info in the past five months

On the long list of crypto companies that have been hacked, there are plenty of examples of financial losses that are much more painful …

Bloomberg

Context & Ripple Effects

Coinbase’s disclosure that a small subset of user data was accessed, alongside an expected $180 million to $400 million cost and a rejected ransom demand, established the financial and operational scope of the incident. This report adds a critical mechanism: compromised customer-service access rather than a purely technical intrusion.

The episode also sits against earlier Coinbase security and support strains, including a 2021 theft affecting 6,000 customers through an SMS MFA vulnerability and reported customer-service failures tied to account access. The immediate issue is whether support operations are treated as a privileged security boundary.

First-order effects

  • Coinbase must contain and investigate access obtained through bribed representatives, while tightening who can view customer records and how that access is monitored.
  • Customers whose information was exposed face heightened risk of targeted impersonation and social-engineering attempts, even if credentials were not accessed in the company’s initial breach disclosure.

Second-order effects

  • Other crypto platforms that rely on outsourced or distributed support teams will face pressure to review contractor screening, data permissions, and escalation workflows rather than focusing only on credential defenses.
  • Support vendors become a more consequential part of exchange risk management: clients may demand narrower access, stronger audit trails, and clearer liability for insider-enabled incidents.

Third-order effects

  • If insider recruitment continues to bypass technical perimeter defenses, security investment will shift further toward least-privilege customer-data systems and controls over human workflows.
  • For crypto platforms seeking broader institutional trust, repeated incidents involving user protection can deepen the industry’s record of fraud-prevention challenges, making operational resilience as important as custody technology.

The trend: Crypto platforms are increasingly being judged on whether their human support and vendor systems can meet the security standard expected of financial infrastructure.

Discussion

  • @troutgirl Joyce Park on bluesky
    I've worked at two “unicorn” fintechs, and that is why I keep my money on the largest and most heavily regulated financial institutions I can find.  [embedded post]
  • @quinnypig.com Corey Quinn on bluesky
    You will pay market rate for the talent you hire—whether you want to, or not.  [embedded post]
  • @suchprotech.com Paul Spencer on bluesky
    Start working this into your tabletops and threat models for all critical vendors now.  [embedded post]
  • @mychaelp Michael on bluesky
    They should go to jail.  But I bet they won't.
  • @mychaelp Michael on bluesky
    Might be why I've received 100s of Coinbase emails to reset my account or change password or confirm new email.
  • @samblum Sam Blum on bluesky
    It's gonna be sick when we have a national Bitcoin reserve.  [embedded post]
  • @adamscochran Adam Cochran on x
    Wow, apparently the hackers had access since January! Why are we only hearing about it now? Has Coinbase confirmed that they've even informed impacted users yet?
  • @zerohedge @zerohedge on x
    Maybe next time vet your Bangladesh call centers better
  • @freddyriz Fred Rispoli on x
    “recruited rogue overseas support agents” “recruited the agents we pay pennies a day” FIFY
  • @lsdinmycoffee @lsdinmycoffee on x
    @defisexbot @coinbase maybe that's exactly HOW you manage to get a hold of customer support
  • @beausecurity Beau on x
    Have you been getting Coinbase scams recently? This is why: Support agents stole very sensitive customer data (see screenshot) and sold it to scammers. Scammers use this data to conduct very targeted scams - and can impersonate Coinbase support since they have all this info! [ima…
  • @functi0nzer0 Laurence on x
    I'm more surprised that anyone at Coinbase customer service was online and available to be bribed
  • @jendn Jennifer Dudley-Nicholson on bluesky
    This explains the weirdly professional phone call I got from ‘Coinbase support’ a while ago!  (No money lost.) www.reuters.com/business/coi...
  • @joemenn Joseph Menn on bluesky
    Exemplary response from #Coinbase to a bribery, scam and extortion play.  Full disclosure, no ransom paid, $20 million for help catching the perps.  More like this, please. www.coinbase.com/blog/protect...
  • @brunojnavarro Bruno J. Navarro on bluesky
    Coinbase on Thursday reported that cybercriminals bribed overseas support agents to steal customer data to use in social engineering attacks.  The incident may cost Coinbase up to $400 million to fix, the company estimated.
  • @zackwhittaker.com Zack Whittaker on bluesky
    More: Coinbase CEO says the hacker demanded $20 million in a ransom payment not to publish the stolen data.  —  A Coinbase spokesperson tells me that less than 1% of its monthly customers are affected.  Per its latest figures out in March 2025, that's still around ~100k people wh…
  • @zackwhittaker.com Zack Whittaker on bluesky
    BREAKING: Coinbase says it was breached, and customers' personal information stolen.  —  The crypto giant said the hacker was “paying multiple contractors or employees working in support roles,” and contacted Coinbase with a ransom demand this week with stolen data, which Coinbas…
  • @self.agency Daniel Sieradski on bluesky
    even the top tier crypto platform, under more scrutiny and more stringently regulated than all others, has gaping security holes that enable the theft of customers' assets [embedded post]
  • @brian_armstrong Brian Armstrong on x
    [Video: “Hey, everyone.  I wanna make you aware of a disturbing email that we received recently at Coinbase.  It was a ransom note demanding $20 million in Bitcoin in exchange for this attackers not releasing some information they claimed to have obtained on our customers..."]
  • @coinbase @coinbase on x
    Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on <1% of Coinbase MTUs. No passwords, private keys, or funds were exposed. Prime accounts are untouched. We will reimburse impacted customers. More here: https://coinbase.com/...
  • @qwqiao @qwqiao on x
    was likely victim of this data breach.  got a number of calls from scammers pretending to be coinbase.  the scam roughly goes like this 1) they text/call u to tell u ur coinbase account got compromised 2) pretend to do a bunch of a personal info verification, including how much m…
  • @coinbase @coinbase on x
    We will pursue the harshest penalties possible and will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible for this attack.
  • @evgenygaevoy @evgenygaevoy on x
    Coinbase not disclosing this (much much much...) earlier notwithstanding, this is the dark side of the idiotic and nonsensical kyc/aml regime we live in making life marginally convenient for law enforcement and geopolitical games, while sacrificing our privacy, imposing a massive…
  • @adamscochran Adam Cochran on x
    ...Coinbase's disclosure here focuses on the stolen funds.  But that's irrelevant.  They got physical addresses, and government IDs.  Things you can't change, and things that put customers at physical risk.  No element of KYC/AML policy requires this kind of stuff to be accessibl…
  • @zachxbt @zachxbt on x
    @deltaxbt Threat actors were targeting users with 7-8 figs on Coinbase so that's how $200-400M was stolen since Dec 2024. If you are that rich tbh you should have a second passport and just use it basically as a wrapper for KYC while not using your main passport.
  • @asvanevik Alex Svanevik on x
    It's time for @realDonaldTrump to dismantle the KYC/AML complex. All it does is compromise personal data for regular people - at an immense cost. Meanwhile practically no real criminals are caught. We need bold leadership to make it happen.
  • @andrewdarmacap Andrew Keys on x
    @brian_armstrong I was attempted to be socially engineered. Reported to @coinbase security last night. They threatened a physical attacker to be at an address for $25,000. Still haven't heard from Coinbase @brian_armstrong. Should be including authorities when physical harm is th…
  • @zachxbt @zachxbt on x
    @mrjasonchoi The issue is there's simply a lot of Coinbase targeted scams and a lot are unrelated to the incident disclosed today by Coinbase. The threat actors paying off employees were targeting users with 7-8 figs in their accounts. They pretended to be Coinbase support using …
  • @mrjasonchoi Jason Choi on x
    I have a lot of admiration for @brian_armstrong and what Coinbase stands for, but reimbursement for address dox is simply insufficient. 1% of monthly transacting users for Coinbase is ~100,000 people. Those people now face a real risk of kidnappings and home invasions, or at
  • @randhindi Rand Hindi on x
    KYC / AML puts millions of people at risk. It should be encrypted. No company should have to store personal data for such long periods. Coinbase is by far one the best companies in terms of cybersecurity. If it could happen to them, imagine all the other companies that have your
  • @boldleonidas Bold on x
    @brian_armstrong ZachXBT about to make 20m in an hour.
  • @boldleonidas Bold on x
    This happened 4 hours ago... if only there was some kind of specific candle available on Coinbase Pro that allowed me to see the effects on the charts during this time period.
  • @twobitidiot Ryan Selkis on x
    This is an 11/10 crisis PR response. Political disagreements aside, Coinbase's security has always been its cornerstone, and @brian_armstrong weathers crises at a world-class level.
  • @erikvoorhees Erik Voorhees on x
    Now imagine instead of just your ID, it's years of private conversations, medical records, legal records, financial records, business secrets, proprietary code, deep and dark thoughts you've struggled with, controversial questions you've asked, a hundred thoughts you'd be
  • @johnedeaton1 John E Deaton on x
    To every person who has an account on @coinbase @krakenfx @Gemini @UpholdInc or any other exchange, the hackers are very sophisticated. You may get an email from Coinbase Support or UpHold Support, but it really isn't from them. I've had these emails sent to me and they look
  • @adamscochran Adam Cochran on x
    The number of Coinbase employees who liked this tweet is telling. (Don't worry, won't doxx you!) Often when startups grow rapidly, especially in a mission driven company in a niche industry, they develop a lot of group-think. When they clamp down on some values, or encourage
  • @charlesarthur Charles Arthur on x
    Marvellous how this is exactly the same playbook as used against regular people with normal bank accounts. Scams are scams are scams.
  • @0xbreadguy @0xbreadguy on x
    I received a call from a “Coinbase agent” earlier this week. Knew my name, email, phone (obviously) and spoke in perfect English. Tried to tell me my email was changed to some random Muhammad account to scare me. It pissed me off so much to know that this person could sit [image]
  • @deeze @deeze on x
    I refuse to believe it is less than 1% because of how many people I know who get daily scam texts from people trying to get into their coinbase accounts tbh
  • @pumatheuma Uma Roy on x
    The best way to not leak personal data is for orgs to not have it in the first place. ZK allows KYC/compliance without sharing of sensitive information. Incidents like these will catalyze ZK adoption—privacy is not just ideological but also reduces risk for businesses.
  • @greg16676935420 Greg on x
    So you're telling me this text I got yesterday was fake and I shouldn't have called and given them my SSN, favorite color, dogs middle name, and favorite type of ice cream? [image]
  • @trading_axe @trading_axe on x
    @coinbase We forgive you. So what if everyone got their personal data leaked, At least you added 4 hour candles. ❤️ Makes it even in my books! ~ Dr. Axius. Retar Dio.
  • @defisexbot Gustl on x
    @coinbase gotta hand it to these criminals that they were able to get ahold of coinbase customer support in the first place
  • @lefterisjp Lefteris Karapetsas on x
    @coinbase How do coinbase customers know if they are affected? How do I know if I am in that 1%?
  • @crypt0e Shaquille O'Atmeal on x
    @coinbase This explains the wave of phishing emails and scam calls I've been getting. The scammers address me by name and clearly know who I am. While I didn't fall for any of the phishing attempts, it's still unsettling that my data was exposed. Given that this breach involved i…
  • @molly0xfff Molly White on x
    coinbase announces it's joining the S&P 500 and then announces a serious data breach two days later oof
  • @cobie @cobie on x
    @R89Capital People who fell for social engineering attacks and thus sent money to the attackers “voluntarily” Social engineering attacks are getting pretty convincing and if they have all your personal info, then much easier to be convincing that it's actually Coinbase
  • @arthur_0x Arthur on x
    Coinbase really need to get their shit fixed, there is no ground to ask for constant KYC refresh when it just end up as a honeypot of user's important information. Hyperliquid
  • @monetsupply @monetsupply on x
    if you live in a low trust country, you cant safely refuse a bribe from criminal syndicates coinbase can try to shift blame to bad apple cs staff, but this is structurally guaranteed to happen if you give high value data to offshore cs 100% coinbase's fault
  • @arthurb Arthur B. on x
    Regarding the Coinbase attack. Hiring US support staff instead of offshore support staff only increases the cost of the bribes. If the attackers did indeed take $400M, is it going to move the needle? Access to that information should be extremely limited and tightly monitored.
  • @antoniogm Antonio García Martínez on x
    “Millions for defense, but not a penny for tribute.” Coinbase refusing to pay a hacker's ransom, and instead offering it as a bounty for their capture.
  • @cmsholdings @cmsholdings on x
    The real trade is how much TRUMP does Coinbase have to buy now
  • @zerohedge @zerohedge on x
    Coinbase files 8K saying they were hacked https://www.sec.gov/...
  • @jeffjohnroberts Jeff Roberts on x
    Never seen this before: a smart way to fight back against hackers — and a masterclass in PR Crooks bribed support agents in India to steal @coinbase customer data—and then tried to blackmail the firm for $20M to stay quiet https://fortune.com/...
  • @mayazi Maya Zehavi on x
    The biggest attack vector that exposed ppl are the centralized honey pots that aggregate various PiI under one roof & then fail to protect it. Boggles my mind why crypto native companies haven't found a way to integrate decentralize directory primitives to protect their users. [i…
  • @atabarrok Alex Tabarrok on x
    Brian Armstrong just pulled a Mel Gibson on Coinbase ransomers. I love this guy, https://m.youtube.com/...
  • @cobie @cobie on x
    @Arthur_0x Happens at every exchange. Most of them don't disclose it publicly
  • @arthur_0x Arthur on x
    Coinbase really need to get their shit fixed, there is no ground to ask for constant KYC refresh when it just end up as a honeypot of user's important information.
  • @lemiscate @lemiscate on x
    The only effective way to safeguard users from data breaches is to refrain from collecting and storing data. Aave is a 40 billion dollar protocol that has no idea of who you are. Just use Aave.
  • @federicotenga Federico Tenga on x
    Can these huge platforms with thousands of CS people have any hope of keeping the users' data safe? KYC laws not only are ineffective, but they also require trust assumptions towards employees that can only work at a small scale
  • @r89capital Rex on x
    If no funds were exposed, what are they reimbursing?
  • @phildaian @phildaian on x
    addresses and IDs leaked? with everything that is going on in crypto right now? federal investigation now. this is a life or death matter. unacceptable. -a coinbase customer
  • @mdudas Mike Dudas on x
    i'm humbled to be part of the 1% [image]
  • @inversebrah @inversebrah on x
    💀💀💀 [image]
  • @tmnxeq @tmnxeq on x
    oh wow, CB also filed an update with the SEC formally discloses a “Material Cybersecurity Incident” & related estimated expenses of approximately “$180 million to $400 million” [image]
  • @tmnxeq @tmnxeq on x
    kyc docs (partially) leaked too... sounds like a huge data access issue at CB [image]
  • @tmnxeq @tmnxeq on x
    fascinating that Coinbase did *not* disclose this $180m-400m Cybersecurity Incident as part of past week's 10-Q it took the “extortion email” (dated May 11, Sunday) to file disclosures 🤨 [image]
  • @tmnxeq @tmnxeq on x
    guess this weird story around a “$20 million ransom demand” is a PR spin to hide the true nature of the announcement (disclosing the data breach to cb users) blog is titled: > Protecting Our Customers - Standing Up to Extortionists 🤡 https://x.com/...
  • @tmnxeq @tmnxeq on x
    coinbase admits data leak (rogue employees) impacted: “less than 1% of Coinbase monthly transacting users” what a weird way to measure the scope of the leak probably to sugarcoat the scope — coinbase does not provide the total amount of accounts impacted
  • r/CryptoCurrency r on reddit
    Crypto exchange Coinbase faces up to $400m hit from cyber attack - now I understand why I was receiving so many scam emails !
  • r/news r on reddit
    Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • r/Bitcoin r on reddit
    Data Hack At Coinbase: names, addresses, phone numbers and emails; masked bank account numbers and identifiers as well as the last four digits …
  • r/cybersecurity r on reddit
    Coinbase warns of up to $400 million hit from cyber attack
  • r/ProtonMail r on reddit
    Update your email alias on Coinbase, if applicable.
  • r/ScottGalloway r on reddit
    Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • r/CryptoMarkets r on reddit
    Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • r/hacking r on reddit
    Coinbase data breach exposes customer info and government IDs
  • r/cybersecurity r on reddit
    Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • r/Buttcoin r on reddit
    Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • r/technology r on reddit
    Coinbase says customers' personal information stolen in data breach