Koinly, a popular cryptocurrency tax optimization software application, has warned users of a possible data breach of email addresses in the aftermath of a securityKoinly, a popular cryptocurrency tax optimization software application, has warned users of a possible data breach of email addresses in the aftermath of a security

Koinly Warning: Third-Party Breach Exposes User Emails – Is Your Tax Data Safe?

2025/12/24 03:47
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Koinly, a popular cryptocurrency tax optimization software application, has warned users of a possible data breach of email addresses in the aftermath of a security breach by a third-party service provider.

The company reported that the problem was not through its systems, and it insisted that sensitive financial and tax-related information is safe.

Source: degeneratenews

Koinly, in an email to the customers, claimed that the incident was based on Mixpanel, an analytics service it had been using to understand how the products were being used and ways of enhancing user experience.

What Was Exposed—and What Wasn’t: Koinly Addresses Third-Party Breach Fallout

Third-party breaches are a type of attack in which the attackers target vendors or service providers who have access to user information, and in most cases, they are using less secure security controls to indirectly gain access to information.

These attacks are prevalent in both crypto and non-crypto industries.

In these instances, Koinly said that Mixpanel had announced in November that one of its hackers had accessed some user accounts of Mixpanel and data belonging to these accounts.

Information disclosed could have contained names, email addresses, rough position details like city or country, and device data like the operating system and version of a browser.

Koinly reported that, according to its internal inquiries, it did not share any wallet information, transaction history, tax filings, or portfolio data with Mixpanel.

The company also stated that its main systems were not compromised, and it did not leave people with access to user accounts and financial records stored in Koinly.

Since then, it stopped using Mixpanel and initiated a larger exercise of auditing other third-party tools that process user information.

The company has failed to provide the number of users that could have been impacted and a specific timeframe in which the data exposure took place. It claimed that it is still in the process of collaborating with Mixpanel in order to know the extent of the incident.

Although Koinly asserted that it had no evidence that the information revealed had been abused, it gave a warning that users should be wary of potential exploitation by phishing.

The company also suggested that they confirm that any message that claims to be from Koinly originates from its official domain.

As Crypto Theft Hits $3.4B, Third-Party Vulnerabilities Come Into Focus

Koinly has a user base of over 1.5 million in the world, and it is active in over 20 countries.

The platform automatically imports transaction data from more than 900 exchanges, wallets, and blockchains and classifies the transactions, determines the gains and losses, and produces tax filings for tax authorities.

Source: Koinly

The size and reach of it ensure that even a small data exposure can concern the users who use it to store sensitive financial data.

The recent attacks in the crypto market and the technological industry in general demonstrate how harmful third-party hacks can be.

In September, Swiss crypto platform SwissBorg lost over $41 million of Solana tokens because attackers hacked an API provider of one of its partners’ services.

In October, Discord affirmed that they had unauthorized access to their third-party Zendesk system of support following their announcement that hackers had stolen millions of government ID pictures.

DeFi protocol Abracadabra also experienced numerous exploits this year because of code-level vulnerabilities, pointing out the scope of vulnerabilities to attacks on infrastructure.

Chainalysis industry data reveal that thefts involving crypto reached more than 3.4 billion US dollars in 2025, and the losses are growing more and more concentrated in a few more extreme cases.

시장 기회
일드파밍.인슈어 로고
일드파밍.인슈어 가격(SAFE)
$0.1431
$0.1431$0.1431
-1.91%
USD
일드파밍.인슈어 (SAFE) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.