Although Coinbase has taken a number of measures to respond, user attacks may have become the "norm."Although Coinbase has taken a number of measures to respond, user attacks may have become the "norm."

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

2025/05/16 15:53
4 min read

Compiled by: Felix, PANews

On May 15, two pieces of negative news about Coinbase were released, causing Coinbase's stock price to suffer a "Waterloo."

One is that Coinbase disclosed a cyber attack involving the theft of internal data and customer information, with a potential financial impact of between $180 million and $400 million.

In addition, sources said that the US SEC is still investigating whether Coinbase falsified user data before its listing in 2021.

Under the influence of two pieces of negative news, Coinbase's stock price fell 7.2% during the day.

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

Customer service leaked user data and demanded $ 20 million in ransom

Coinbase said in the report that cyber criminals bribed and recruited a group of malicious customer service staff overseas, who abused their access to the customer support system and stole data from less than 1% of monthly trading users (about 80,000 to 100,000) in the customer support tool. Although no funds, passwords or private keys were stolen, and Coinbase Prime accounts were "unaffected", the attackers used this data to launch targeted social engineering scams against customers.

Regarding this attack method, some crypto experts commented that this type of targeted social engineering attack (using overseas customer support teams) is not uncommon in the crypto industry. Because the information of active users of crypto exchanges is far more valuable than imagined. The average cost of attracting new users for the top exchanges is $5-50 per valid user, while the average cost of attracting new users for small and medium-sized exchanges is $50-300.

After launching a social engineering scam, the Coinbase attackers sent a ransom note demanding $20 million worth of Bitcoin from Coinbase and threatening to release stolen customer data if Coinbase did not pay.

The report states that the attackers obtained:

  • Name, address, phone number and email
  • Masked Social Security Number (last 4 digits only)
  • Blocked bank account numbers and some bank account identifiers
  • Image of government ID (e.g. driver's license, passport)
  • Account data (balance snapshots and transaction history)
  • Limited company data (including documents, training materials, and communications available to customer service personnel)

However, data such as login credentials or two-factor authentication codes, private keys, any ability to transfer or access customer funds, access to Coinbase Prime accounts, and access to any Coinbase or Coinbase customer hot or cold wallets “was not stolen.”

Multiple measures to deal with attacks, refuse to pay ransom and issue bounties

Coinbase took a series of countermeasures after the incident.

First, work closely with law enforcement. The insider who leaked the data was fired on the spot and handed over to US and international law enforcement, and Coinbase said it would file a criminal lawsuit.

Secondly, track the stolen funds. Coinbase worked with industry partners to mark the attacker's address so that authorities can track and recover the assets. And promised to compensate customers who were tricked into sending money to the attacker due to social engineering attacks. To further ensure the security of support operations, Coinbase will open a new support center in the United States and strengthen security controls and monitoring at all locations.

In response to the $20 million ransom demanded by the attacker, Coinbase said it would not pay it. At the same time, Coinbase will set up a $20 million reward fund to reward those who provide clues and help arrest and convict the criminals of this attack.

Coinbase users may be subject to social engineering attacks or have become " normal "

Despite the seemingly positive response measures, security incidents involving Coinbase seem to occur frequently, and the amount of money stolen is also quite large, especially the social engineering scams encountered by users.

In February of this year, on-chain detective ZachXBT disclosed on the X platform that Coinbase users lost more than $65 million due to social engineering scams between December 2024 and January 2025. He said that the estimated $65 million may be "far lower" than the actual amount because it does not take into account the cases submitted to Coinbase support and the police.

ZachXBT cited multiple security incidents and denounced Coinbase for failing to properly handle such scams. “Coinbase needs to make changes urgently because more and more users are being defrauded of tens of millions of dollars every month. Other large exchanges are not experiencing similar situations.”

ZachXBT also urged Coinbase leadership to consider strengthening measures against social engineering attacks, including giving KYC-verified users the option to enter their phone number on the platform, adding a new user account type that limits withdrawals, and increasing community outreach.

These proposals may not have been adopted by Coinbase, but this extortion incident may serve as a wake-up call for Coinbase.

Related reading: Coinbase Q1 financial report explained: Net profit plummeted 94% due to portfolio losses, and the company acquired Deribit to develop derivatives

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Michael Saylor’s Strategy follows Metaplanet, adding 6,269 BTC worth $729 million

Michael Saylor’s Strategy follows Metaplanet, adding 6,269 BTC worth $729 million

The post Michael Saylor’s Strategy follows Metaplanet, adding 6,269 BTC worth $729 million appeared on BitcoinEthereumNews.com. The two giant BTC holders, Strategy and Metaplanet, have stirred the waters despite the FUD in the Bitcoin market by acquiring a total of 6,269 Bitcoins. According to reports, Strategy has acquired 850 BTC while Metaplanet has acquired a bumper 5,419 tokens. Michael Saylor’s Strategy, the world’s largest corporate Bitcoin holder, purchased BTC worth $99.7 million at $117,344 per Bitcoin. This has brought its total Bitcoin holdings to 639,835 BTC, acquired for about $47.3 billion at $73,971 per Bitcoin. JUST IN: Strategy buys 850 BTC for $99.7M at $117,344 per BTC. Now holds 639,835 $BTCTotal spent: $47.33B Avg cost: $73,971 per BTCYTD BTC yield: 26.0% https://t.co/7iv2difHzR pic.twitter.com/O8WfDpJDxQ — Cryptopolitan (@CPOfficialtx) September 22, 2025 On the other hand, as reported by Cryptopolitan, Metaplanet purchased BTC worth $632.53 million at an average price of roughly $116,724 per Bitcoin. This has brought its total BTC holdings to 25,555 BTC, which was acquired for approximately $2.7 billion and purchased at an average price of $106,065 per BTC. Strategy slows down BTC purchase while Metaplanet adds speed The US company’s most recent Bitcoin purchase is in line with a recent trend of small purchases, showing a slowdown compared to the big purchases seen earlier this year. Strategy bought 3330 Bitcoin in September, which is a big drop from the 7,714 BTC it bought in August and a 75% drop from the 31,466 BTC it bought in July. In line with Bitcoin, Strategy’s stock has dropped about 2% in the last 30 days. Starting in 2020, the company put most of its money into Bitcoin. It used a mix of debt and stock to buy huge amounts of BTC, which turned the business intelligence software company into a Bitcoin giant. Still, the stock has gone up 2,200% since it started buying BTC. On the other hand,…
Share
BitcoinEthereumNews2025/09/22 22:54
Payward Revenue Hits $2.2 Billion as Kraken Exchange Reports Strong 2025 Growth

Payward Revenue Hits $2.2 Billion as Kraken Exchange Reports Strong 2025 Growth

TLDR Payward, Kraken’s parent company, earned $2.2 billion in 2025, a 33% increase from 2024’s $1.6 billion Trading revenue and asset-based services each contributed
Share
Blockonomi2026/02/04 20:11
Super Micro Computer (SMCI) Stock: Revenue Soars Past $12B on AI Server Boom

Super Micro Computer (SMCI) Stock: Revenue Soars Past $12B on AI Server Boom

TLDR Revenue hit $12.7 billion, crushing $10.42 billion estimate and up 123.4% year-over-year EPS of $0.69 beat consensus $0.49 by 40.8% in fiscal Q2 Q3 guidance
Share
Blockonomi2026/02/04 20:36