Coinbase says hackers accessed data of a “small subset” of users, but not credentials, expects to incur $180M-$400M in costs, and refuses to pay a $20M ransom
and the investigators who saw it coming Sead Fadilpašić / TechRadar : Personal information leaked in Coinbase cyberattack, cost could be $400 million Bloomberg : Coinbase Hack Could Cost Company $400 Million Steven Ehrlich / Unchained : Coinbase Is Being Extorted. What Does That Mean for Its Stock? The Paypers : Coinbase forecasts a USD 400 million hit from cyberattack Bitcoinist.com : Coinbase Hack Shocks the Crypto World: Choose Non-Custodial Wallets like Best Wallet Instead Nicole Mousicos / Tech.co : Coinbase Forecasts Up To $400 Million Hit From Cyberattack Financial Express : Coinbase hacked: Hackers demand $20 million in Bitcoin, threaten to leak customer data Skye Jacobs / TechSpot : Inside job at Coinbase leads to massive data breach, $20 million ransom demanded Reuters : Crypto giant Coinbase warns of US$400 million hit from cyberattack, refuses to pay ransom Ikemefula Aruogu / Coin Edition : Coinbase Data Breach: Brian Armstrong Offers $20 Million Bounty for Intel on Attackers Jacob Lyon / Protos : Coinbase says staff leaked customer data, refuses to pay $20M ransom Josh Scott / BetaKit : Coinbase Canada CEO pushes for crypto-friendly government just as company reveals hack that could cost up to $400 million USD Oliver Knight / CoinDesk : Coinbase Could Pay Customers Up to $400M for Data Breach Bluesky: Jennifer Dudley-Nicholson / @jendn : This explains the weirdly professional phone call I got from ‘Coinbase support’ a while ago! (No money lost.) www.reuters.com/business/coi... Joseph Menn / @joemenn : Exemplary response from #Coinbase to a bribery, scam and extortion play. Full disclosure, no ransom paid, $20 million for help catching the perps. More like this, please. www.coinbase.com/blog/protect... Bruno J. Navarro / @brunojnavarro : Coinbase on Thursday reported that cybercriminals bribed overseas support agents to steal customer data to use in social engineering attacks. The incident may cost Coinbase up to $400 million to fix, the company estimated. Zack Whittaker / @zackwhittaker.com :
Context & Ripple Effects
Coinbase had previously disclosed an account-takeover incident in which a vulnerability in SMS-based multi-factor authentication led to cryptocurrency being taken from 6,000 customer accounts. The latest disclosure shifts attention from credential compromise to the exposure of customer information and the cost of remediation.
Related reporting identifies a likely operational weak point: attackers allegedly gained sustained access by bribing customer-service representatives for customer information on demand. That makes the incident a test of controls around outsourced or frontline support access, not just login security.
First-order effects
- Coinbase faces an estimated $180 million to $400 million in breach-related costs and potential customer reimbursements while declining the attackers’ $20 million demand.
- Affected users face exposure of personal information even though Coinbase says credentials were not accessed; the company must investigate, notify, and support those customers.
Second-order effects
- Coinbase and comparable crypto platforms are likely to tighten access privileges, monitoring, and screening for support personnel, particularly where agents can retrieve sensitive customer records.
- The projected remediation bill makes breach losses a more material operating cost for custodial platforms, increasing pressure to determine which costs can be absorbed versus passed through in service pricing or coverage terms.
Third-order effects
- If insider-enabled access becomes a recurring attack path, security investment will increasingly move from account-authentication controls toward governance of human access across support and contractor networks.
- The episode underscores a broader shift in which consumer-finance and crypto platforms treat customer-data protection and post-breach reimbursement capacity as linked parts of their trust model.
The trend: Cybersecurity risk is moving beyond stolen passwords toward the governance of privileged human access, with breach costs extending from incident response to customer restitution.
Related: Downstream Cost Transmission · Coinbase breach disclosure · Alleged bribery of Coinbase support staff · Coinbase's 2021 SMS MFA incident
Related Coverage
- Leading crypto firm Coinbase faces up to $400m hit from cyber attack BBC
- Coinbase data breach exposes customer info and government IDs BleepingComputer
- Coinbase suffers data breach, exposing customer information to hackers SiliconANGLE
- Protecting Our Customers - Standing Up to Extortionists Coinbase
- Coinbase says customers' personal information stolen in data breach TechCrunch
- Coinbase attack leaves exchange on the hook for $400m. Here's everything we know DL News
- Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom CNBC
- Coinbase Offers $20m Bounty to Take Down Cybercrime Ring Behind Hack Infosecurity
- Coinbase Breach Exposes Risks of Digital ID Reclaim The Net
- Coinbase Rejects $20M Ransom After Insider Data Leak, Faces Up to $400M in Fallout eSecurity Planet
- Coinbase stock could jump 20% after overblown sell-off Cryptopolitan
- The Coinbase hack that shadowed its S&P rise — and the investigators who saw it coming crypto.news
- Personal information leaked in Coinbase cyberattack, cost could be $400 million TechRadar
- Coinbase Hack Could Cost Company $400 Million Bloomberg
- Coinbase Is Being Extorted. What Does That Mean for Its Stock? Unchained
- Coinbase forecasts a USD 400 million hit from cyberattack The Paypers
- Coinbase Hack Shocks the Crypto World: Choose Non-Custodial Wallets like Best Wallet Instead Bitcoinist.com
- Coinbase Forecasts Up To $400 Million Hit From Cyberattack Tech.co
- Coinbase hacked: Hackers demand $20 million in Bitcoin, threaten to leak customer data Financial Express
- Inside job at Coinbase leads to massive data breach, $20 million ransom demanded TechSpot
- Crypto giant Coinbase warns of US$400 million hit from cyberattack, refuses to pay ransom Reuters
- Coinbase Data Breach: Brian Armstrong Offers $20 Million Bounty for Intel on Attackers Coin Edition
- Coinbase says staff leaked customer data, refuses to pay $20M ransom Protos
- Coinbase Canada CEO pushes for crypto-friendly government just as company reveals hack that could cost up to $400 million USD BetaKit
- Coinbase Could Pay Customers Up to $400M for Data Breach CoinDesk
- As much as I don't like Armstrong in general and as weird as this webcam video is, this compromise seems very understandable and the response very reasonable. — CEOs: get an eye-level webcam and some plants, especially if your head is the color of the wall. — RE: https://www.threads.com/... @parkert
- The Coinbase Uno Reverse card of taking the extortion demand price and instead making that same price a bounty on the threat actor themselves is amazing chess moves. … Frank McGovern
- Criminals: Coinbase pay us 20m in ransom. — Coinbase: No. — Coinbase: Takes 20m and uses it to go after the criminals in a bounty. … Lloyd Evans
- Crazy story: A criminal gang bribed Coinbase customer support agents in India to share customer data (name, address, partial bank info), which they used to pose as employees in phishing scams. … Jeff John Roberts
- Coinbase announced how cyber criminals bribed and recruited a group of rogue overseas support agents to steal their customer data to facilitate social engineering attacks. … Gianluca Varisco
Discussion
-
@jendn
Jennifer Dudley-Nicholson
on bluesky
This explains the weirdly professional phone call I got from ‘Coinbase support’ a while ago! (No money lost.) www.reuters.com/business/coi...
-
@joemenn
Joseph Menn
on bluesky
Exemplary response from #Coinbase to a bribery, scam and extortion play. Full disclosure, no ransom paid, $20 million for help catching the perps. More like this, please. www.coinbase.com/blog/protect...
-
@brunojnavarro
Bruno J. Navarro
on bluesky
Coinbase on Thursday reported that cybercriminals bribed overseas support agents to steal customer data to use in social engineering attacks. The incident may cost Coinbase up to $400 million to fix, the company estimated.
-
@zackwhittaker.com
Zack Whittaker
on bluesky
More: Coinbase CEO says the hacker demanded $20 million in a ransom payment not to publish the stolen data. — A Coinbase spokesperson tells me that less than 1% of its monthly customers are affected. Per its latest figures out in March 2025, that's still around ~100k people wh…
-
@zackwhittaker.com
Zack Whittaker
on bluesky
BREAKING: Coinbase says it was breached, and customers' personal information stolen. — The crypto giant said the hacker was “paying multiple contractors or employees working in support roles,” and contacted Coinbase with a ransom demand this week with stolen data, which Coinbas…
-
@self.agency
Daniel Sieradski
on bluesky
even the top tier crypto platform, under more scrutiny and more stringently regulated than all others, has gaping security holes that enable the theft of customers' assets [embedded post]
-
@brian_armstrong
Brian Armstrong
on x
[Video: “Hey, everyone. I wanna make you aware of a disturbing email that we received recently at Coinbase. It was a ransom note demanding $20 million in Bitcoin in exchange for this attackers not releasing some information they claimed to have obtained on our customers..."]
-
@coinbase
@coinbase
on x
Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on <1% of Coinbase MTUs. No passwords, private keys, or funds were exposed. Prime accounts are untouched. We will reimburse impacted customers. More here: https://coinbase.com/...
-
@qwqiao
@qwqiao
on x
was likely victim of this data breach. got a number of calls from scammers pretending to be coinbase. the scam roughly goes like this 1) they text/call u to tell u ur coinbase account got compromised 2) pretend to do a bunch of a personal info verification, including how much m…
-
@coinbase
@coinbase
on x
We will pursue the harshest penalties possible and will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible for this attack.
-
@evgenygaevoy
@evgenygaevoy
on x
Coinbase not disclosing this (much much much...) earlier notwithstanding, this is the dark side of the idiotic and nonsensical kyc/aml regime we live in making life marginally convenient for law enforcement and geopolitical games, while sacrificing our privacy, imposing a massive…
-
@adamscochran
Adam Cochran
on x
...Coinbase's disclosure here focuses on the stolen funds. But that's irrelevant. They got physical addresses, and government IDs. Things you can't change, and things that put customers at physical risk. No element of KYC/AML policy requires this kind of stuff to be accessibl…
-
@zachxbt
@zachxbt
on x
@deltaxbt Threat actors were targeting users with 7-8 figs on Coinbase so that's how $200-400M was stolen since Dec 2024. If you are that rich tbh you should have a second passport and just use it basically as a wrapper for KYC while not using your main passport.
-
@asvanevik
Alex Svanevik
on x
It's time for @realDonaldTrump to dismantle the KYC/AML complex. All it does is compromise personal data for regular people - at an immense cost. Meanwhile practically no real criminals are caught. We need bold leadership to make it happen.
-
@andrewdarmacap
Andrew Keys
on x
@brian_armstrong I was attempted to be socially engineered. Reported to @coinbase security last night. They threatened a physical attacker to be at an address for $25,000. Still haven't heard from Coinbase @brian_armstrong. Should be including authorities when physical harm is th…
-
@zachxbt
@zachxbt
on x
@mrjasonchoi The issue is there's simply a lot of Coinbase targeted scams and a lot are unrelated to the incident disclosed today by Coinbase. The threat actors paying off employees were targeting users with 7-8 figs in their accounts. They pretended to be Coinbase support using …
-
@mrjasonchoi
Jason Choi
on x
I have a lot of admiration for @brian_armstrong and what Coinbase stands for, but reimbursement for address dox is simply insufficient. 1% of monthly transacting users for Coinbase is ~100,000 people. Those people now face a real risk of kidnappings and home invasions, or at
-
@randhindi
Rand Hindi
on x
KYC / AML puts millions of people at risk. It should be encrypted. No company should have to store personal data for such long periods. Coinbase is by far one the best companies in terms of cybersecurity. If it could happen to them, imagine all the other companies that have your
-
@boldleonidas
Bold
on x
@brian_armstrong ZachXBT about to make 20m in an hour.
-
@boldleonidas
Bold
on x
This happened 4 hours ago... if only there was some kind of specific candle available on Coinbase Pro that allowed me to see the effects on the charts during this time period.
-
@twobitidiot
Ryan Selkis
on x
This is an 11/10 crisis PR response. Political disagreements aside, Coinbase's security has always been its cornerstone, and @brian_armstrong weathers crises at a world-class level.
-
@erikvoorhees
Erik Voorhees
on x
Now imagine instead of just your ID, it's years of private conversations, medical records, legal records, financial records, business secrets, proprietary code, deep and dark thoughts you've struggled with, controversial questions you've asked, a hundred thoughts you'd be
-
@johnedeaton1
John E Deaton
on x
To every person who has an account on @coinbase @krakenfx @Gemini @UpholdInc or any other exchange, the hackers are very sophisticated. You may get an email from Coinbase Support or UpHold Support, but it really isn't from them. I've had these emails sent to me and they look
-
@adamscochran
Adam Cochran
on x
The number of Coinbase employees who liked this tweet is telling. (Don't worry, won't doxx you!) Often when startups grow rapidly, especially in a mission driven company in a niche industry, they develop a lot of group-think. When they clamp down on some values, or encourage
-
@charlesarthur
Charles Arthur
on x
Marvellous how this is exactly the same playbook as used against regular people with normal bank accounts. Scams are scams are scams.
-
@0xbreadguy
@0xbreadguy
on x
I received a call from a “Coinbase agent” earlier this week. Knew my name, email, phone (obviously) and spoke in perfect English. Tried to tell me my email was changed to some random Muhammad account to scare me. It pissed me off so much to know that this person could sit [image]
-
@deeze
@deeze
on x
I refuse to believe it is less than 1% because of how many people I know who get daily scam texts from people trying to get into their coinbase accounts tbh
-
@pumatheuma
Uma Roy
on x
The best way to not leak personal data is for orgs to not have it in the first place. ZK allows KYC/compliance without sharing of sensitive information. Incidents like these will catalyze ZK adoption—privacy is not just ideological but also reduces risk for businesses.
-
@greg16676935420
Greg
on x
So you're telling me this text I got yesterday was fake and I shouldn't have called and given them my SSN, favorite color, dogs middle name, and favorite type of ice cream? [image]
-
@trading_axe
@trading_axe
on x
@coinbase We forgive you. So what if everyone got their personal data leaked, At least you added 4 hour candles. ❤️ Makes it even in my books! ~ Dr. Axius. Retar Dio.
-
@defisexbot
Gustl
on x
@coinbase gotta hand it to these criminals that they were able to get ahold of coinbase customer support in the first place
-
@lefterisjp
Lefteris Karapetsas
on x
@coinbase How do coinbase customers know if they are affected? How do I know if I am in that 1%?
-
@crypt0e
Shaquille O'Atmeal
on x
@coinbase This explains the wave of phishing emails and scam calls I've been getting. The scammers address me by name and clearly know who I am. While I didn't fall for any of the phishing attempts, it's still unsettling that my data was exposed. Given that this breach involved i…
-
@molly0xfff
Molly White
on x
coinbase announces it's joining the S&P 500 and then announces a serious data breach two days later oof
-
@cobie
@cobie
on x
@R89Capital People who fell for social engineering attacks and thus sent money to the attackers “voluntarily” Social engineering attacks are getting pretty convincing and if they have all your personal info, then much easier to be convincing that it's actually Coinbase
-
@arthur_0x
Arthur
on x
Coinbase really need to get their shit fixed, there is no ground to ask for constant KYC refresh when it just end up as a honeypot of user's important information. Hyperliquid
-
@monetsupply
@monetsupply
on x
if you live in a low trust country, you cant safely refuse a bribe from criminal syndicates coinbase can try to shift blame to bad apple cs staff, but this is structurally guaranteed to happen if you give high value data to offshore cs 100% coinbase's fault
-
@arthurb
Arthur B.
on x
Regarding the Coinbase attack. Hiring US support staff instead of offshore support staff only increases the cost of the bribes. If the attackers did indeed take $400M, is it going to move the needle? Access to that information should be extremely limited and tightly monitored.
-
@antoniogm
Antonio García Martínez
on x
“Millions for defense, but not a penny for tribute.” Coinbase refusing to pay a hacker's ransom, and instead offering it as a bounty for their capture.
-
@cmsholdings
@cmsholdings
on x
The real trade is how much TRUMP does Coinbase have to buy now
-
@zerohedge
@zerohedge
on x
Coinbase files 8K saying they were hacked https://www.sec.gov/...
-
@jeffjohnroberts
Jeff Roberts
on x
Never seen this before: a smart way to fight back against hackers — and a masterclass in PR Crooks bribed support agents in India to steal @coinbase customer data—and then tried to blackmail the firm for $20M to stay quiet https://fortune.com/...
-
@mayazi
Maya Zehavi
on x
The biggest attack vector that exposed ppl are the centralized honey pots that aggregate various PiI under one roof & then fail to protect it. Boggles my mind why crypto native companies haven't found a way to integrate decentralize directory primitives to protect their users. [i…
-
@atabarrok
Alex Tabarrok
on x
Brian Armstrong just pulled a Mel Gibson on Coinbase ransomers. I love this guy, https://m.youtube.com/...
-
@cobie
@cobie
on x
@Arthur_0x Happens at every exchange. Most of them don't disclose it publicly
-
@arthur_0x
Arthur
on x
Coinbase really need to get their shit fixed, there is no ground to ask for constant KYC refresh when it just end up as a honeypot of user's important information.
-
@lemiscate
@lemiscate
on x
The only effective way to safeguard users from data breaches is to refrain from collecting and storing data. Aave is a 40 billion dollar protocol that has no idea of who you are. Just use Aave.
-
@federicotenga
Federico Tenga
on x
Can these huge platforms with thousands of CS people have any hope of keeping the users' data safe? KYC laws not only are ineffective, but they also require trust assumptions towards employees that can only work at a small scale
-
@r89capital
Rex
on x
If no funds were exposed, what are they reimbursing?
-
@phildaian
@phildaian
on x
addresses and IDs leaked? with everything that is going on in crypto right now? federal investigation now. this is a life or death matter. unacceptable. -a coinbase customer
-
@mdudas
Mike Dudas
on x
i'm humbled to be part of the 1% [image]
-
@inversebrah
@inversebrah
on x
💀💀💀 [image]
-
@tmnxeq
@tmnxeq
on x
oh wow, CB also filed an update with the SEC formally discloses a “Material Cybersecurity Incident” & related estimated expenses of approximately “$180 million to $400 million” [image]
-
@tmnxeq
@tmnxeq
on x
kyc docs (partially) leaked too... sounds like a huge data access issue at CB [image]
-
@tmnxeq
@tmnxeq
on x
fascinating that Coinbase did *not* disclose this $180m-400m Cybersecurity Incident as part of past week's 10-Q it took the “extortion email” (dated May 11, Sunday) to file disclosures 🤨 [image]
-
@tmnxeq
@tmnxeq
on x
guess this weird story around a “$20 million ransom demand” is a PR spin to hide the true nature of the announcement (disclosing the data breach to cb users) blog is titled: > Protecting Our Customers - Standing Up to Extortionists 🤡 https://x.com/...
-
@tmnxeq
@tmnxeq
on x
coinbase admits data leak (rogue employees) impacted: “less than 1% of Coinbase monthly transacting users” what a weird way to measure the scope of the leak probably to sugarcoat the scope — coinbase does not provide the total amount of accounts impacted
-
r/CryptoCurrency
r
on reddit
Crypto exchange Coinbase faces up to $400m hit from cyber attack - now I understand why I was receiving so many scam emails !
-
r/news
r
on reddit
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
-
r/Bitcoin
r
on reddit
Data Hack At Coinbase: names, addresses, phone numbers and emails; masked bank account numbers and identifiers as well as the last four digits …
-
r/cybersecurity
r
on reddit
Coinbase warns of up to $400 million hit from cyber attack
-
r/ProtonMail
r
on reddit
Update your email alias on Coinbase, if applicable.
-
r/ScottGalloway
r
on reddit
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
-
r/CryptoMarkets
r
on reddit
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
-
r/hacking
r
on reddit
Coinbase data breach exposes customer info and government IDs
-
r/cybersecurity
r
on reddit
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
-
r/Buttcoin
r
on reddit
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
-
r/technology
r
on reddit
Coinbase says customers' personal information stolen in data breach