Although Coinbase has taken a number of measures to respond, user attacks may have become the "norm."Although Coinbase has taken a number of measures to respond, user attacks may have become the "norm."

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

2025/05/16 15:53

Compiled by: Felix, PANews

On May 15, two pieces of negative news about Coinbase were released, causing Coinbase's stock price to suffer a "Waterloo."

One is that Coinbase disclosed a cyber attack involving the theft of internal data and customer information, with a potential financial impact of between $180 million and $400 million.

In addition, sources said that the US SEC is still investigating whether Coinbase falsified user data before its listing in 2021.

Under the influence of two pieces of negative news, Coinbase's stock price fell 7.2% during the day.

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

Customer service leaked user data and demanded $ 20 million in ransom

Coinbase said in the report that cyber criminals bribed and recruited a group of malicious customer service staff overseas, who abused their access to the customer support system and stole data from less than 1% of monthly trading users (about 80,000 to 100,000) in the customer support tool. Although no funds, passwords or private keys were stolen, and Coinbase Prime accounts were "unaffected", the attackers used this data to launch targeted social engineering scams against customers.

Regarding this attack method, some crypto experts commented that this type of targeted social engineering attack (using overseas customer support teams) is not uncommon in the crypto industry. Because the information of active users of crypto exchanges is far more valuable than imagined. The average cost of attracting new users for the top exchanges is $5-50 per valid user, while the average cost of attracting new users for small and medium-sized exchanges is $50-300.

After launching a social engineering scam, the Coinbase attackers sent a ransom note demanding $20 million worth of Bitcoin from Coinbase and threatening to release stolen customer data if Coinbase did not pay.

The report states that the attackers obtained:

  • Name, address, phone number and email
  • Masked Social Security Number (last 4 digits only)
  • Blocked bank account numbers and some bank account identifiers
  • Image of government ID (e.g. driver's license, passport)
  • Account data (balance snapshots and transaction history)
  • Limited company data (including documents, training materials, and communications available to customer service personnel)

However, data such as login credentials or two-factor authentication codes, private keys, any ability to transfer or access customer funds, access to Coinbase Prime accounts, and access to any Coinbase or Coinbase customer hot or cold wallets “was not stolen.”

Multiple measures to deal with attacks, refuse to pay ransom and issue bounties

Coinbase took a series of countermeasures after the incident.

First, work closely with law enforcement. The insider who leaked the data was fired on the spot and handed over to US and international law enforcement, and Coinbase said it would file a criminal lawsuit.

Secondly, track the stolen funds. Coinbase worked with industry partners to mark the attacker's address so that authorities can track and recover the assets. And promised to compensate customers who were tricked into sending money to the attacker due to social engineering attacks. To further ensure the security of support operations, Coinbase will open a new support center in the United States and strengthen security controls and monitoring at all locations.

In response to the $20 million ransom demanded by the attacker, Coinbase said it would not pay it. At the same time, Coinbase will set up a $20 million reward fund to reward those who provide clues and help arrest and convict the criminals of this attack.

Coinbase users may be subject to social engineering attacks or have become " normal "

Despite the seemingly positive response measures, security incidents involving Coinbase seem to occur frequently, and the amount of money stolen is also quite large, especially the social engineering scams encountered by users.

In February of this year, on-chain detective ZachXBT disclosed on the X platform that Coinbase users lost more than $65 million due to social engineering scams between December 2024 and January 2025. He said that the estimated $65 million may be "far lower" than the actual amount because it does not take into account the cases submitted to Coinbase support and the police.

ZachXBT cited multiple security incidents and denounced Coinbase for failing to properly handle such scams. “Coinbase needs to make changes urgently because more and more users are being defrauded of tens of millions of dollars every month. Other large exchanges are not experiencing similar situations.”

ZachXBT also urged Coinbase leadership to consider strengthening measures against social engineering attacks, including giving KYC-verified users the option to enter their phone number on the platform, adding a new user account type that limits withdrawals, and increasing community outreach.

These proposals may not have been adopted by Coinbase, but this extortion incident may serve as a wake-up call for Coinbase.

Related reading: Coinbase Q1 financial report explained: Net profit plummeted 94% due to portfolio losses, and the company acquired Deribit to develop derivatives

Market Opportunity
MAY Logo
MAY Price(MAY)
$0.01383
$0.01383$0.01383
-1.56%
USD
MAY (MAY) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cardano Eyes $1.50, While $0.0058 Layer Brett Targets $1 in 2025

Cardano Eyes $1.50, While $0.0058 Layer Brett Targets $1 in 2025

The post Cardano Eyes $1.50, While $0.0058 Layer Brett Targets $1 in 2025 appeared on BitcoinEthereumNews.com. Crypto News 24 September 2025 | 14:42 Crypto is heating up again, and traders are hunting for the next 100x altcoin before the 2025 crypto bull run really kicks in. Right now, two names keep coming up: ADA and Layer Brett ($LBRETT). The hype around ADA price prediction has investors cautiously optimistic, while Layer Brett’s crypto presale has created full-blown FOMO. At just $0.0058, $LBRETT has already raised over $4m, offering early backers a rare shot at life-changing returns in a short window. Historical performance: How ADA and Layer Brett compare When you look at ADA alongside memecoin projects like Dogecoin, Shiba Inu, and the original Brett, the differences stand out. ADA has been in the top altcoins conversation for years, with an all-time high of $3.10 that still gives long-term holders confidence. But meme token projects have mostly pumped without any real substance. This is where Layer Brett flips the script. Instead of being just another meme token, it’s an Ethereum Layer 2 project built for real utility, fast transactions, low gas fees, and staking crypto rewards. With speed topping 10,000 TPS, it delivers what congested chains can’t. Compared to ADA’s slower, research-heavy roadmap, $LBRETT is built to move fast and capture immediate opportunities. Technology and use cases driving Layer Brett The backbone of Layer Brett is its Layer 2 blockchain design. Transactions are anchored to Ethereum for security but processed off-chain for scale and low gas fees. That means users can buy and stake in seconds using ETH, USDT, or BNB, no KYC required. The staking rewards are where things get wild. Early participants are seeing around 630% APY, with incentives expected to cool as more tokens are locked. On top of that, features like NFT integrations and cross-chain bridging are already planned, giving $LBRETT both meme energy…
Share
BitcoinEthereumNews2025/09/24 20:06
Washington Faces New Dilemma Over Venezuela’s Alleged BTC Reserves

Washington Faces New Dilemma Over Venezuela’s Alleged BTC Reserves

The issue surfaced after the dramatic removal of Venezuela’s longtime leader, Nicolás Maduro, who was captured by U.S. forces and […] The post Washington Faces
Share
Coindoo2026/01/13 10:14
US Senate Prepares For Crypto Market Structure Bill Markup This Week — Here’s What to Expect

US Senate Prepares For Crypto Market Structure Bill Markup This Week — Here’s What to Expect

After months of intense negotiations involving both political parties, as well as representatives from the crypto industry and traditional banking sectors, the
Share
Bitcoinist2026/01/13 10:00