Coinbase says bribed overseas support agents leaked customer data
- Organization
- Coinbase Global, Inc.
- Exploit
- Malicious Insider
- Industry
- Financial Services
Coinbase, the largest cryptocurrency exchange in the United States, disclosed on 15 May 2025 that criminals had paid a small group of overseas customer support contractors to extract data on its users. The company said it had detected agents accessing customer information without a business need and had dismissed them, but not before records were taken.
According to Coinbase, the stolen material included names, postal addresses, phone numbers and email addresses, masked bank account details, the last four digits of Social Security numbers, images of government identification documents, and account data such as balance snapshots and transaction history. A limited amount of internal corporate documentation and training material was also taken. The company said no passwords, private keys or customer funds were exposed and that Coinbase Prime accounts were untouched.
Coinbase said the attackers emailed the company on 11 May demanding $20 million in bitcoin to suppress the data. It refused, and instead established a $20 million fund to reward information leading to the arrest and conviction of those responsible. The exchange put the affected population at fewer than 1% of its monthly transacting users. A later filing with the Maine attorney general listed 69,461 individuals.
In its securities filing Coinbase estimated remediation costs and voluntary customer reimbursements of between $180 million and $400 million, and said it would repay customers who were tricked into sending funds to the attackers through follow-on social engineering. It also tightened identity checks on large withdrawals. The company's shares fell more than 4% after the disclosure.
Updates
-
A filing with the Maine attorney general put the number of affected customers at 69,461. At disclosure Coinbase had described the group only as fewer than 1% of its monthly transacting users.