Coinbase faces $400M bill after insider phishing attack
By: the crypto news wire|2025/05/15 20:45:04
0
Share
Coinbase, the world’s third-largest cryptocurrency exchange, was hit by a $20 million extortion attempt after cybercriminals recruited overseas support agents to leak user data, the company said. According to a May 15 blog post, Coinbase said a group of external actors bribed and coordinated with several customer support contractors to access internal systems and steal limited user account data. “These insiders abused their access to customer support systems to steal the account data for a small subset of customers,” Coinbase said, adding that no passwords, private keys, funds or Coinbase Prime accounts were affected. Less than 1% of Coinbase’s monthly transacting users’ data was affected by the attack, the company said. Source: Coinbase After stealing the data, the attackers attempted to extort $20 million from Coinbase in exchange for not disclosing the breach. Coinbase refused the demand. Related: Ukraine strategic Bitcoin reserve bill reportedly in final stages Instead, the company offered a $20 million reward for information leading to the arrest and conviction of those responsible for the scheme. Scammers often masquerade as recognizable brands to inspire a false sense of trust in their victims. US brands impersonated by scammers the most. Source: Mailsuite In 2024, Coinbase was the most impersonated cryptocurrency brand by scammers. Related: Top South Korean presidential hopefuls support legalizing Bitcoin ETFs Coinbase will reimburse phishing attack victims Coinbase said it will reimburse users who were tricked into sending cryptocurrency to phishing scammers, with expected remediation and reimbursement expenses ranging from $180 million to $400 million. The crypto exchange disclosed the estimate in an 8-K filing with the US Securities and Exchange Commission on May 15, noting the expenses relate to “voluntary customer reimbursements” and other remediation efforts. The attackers have been approaching the exchange’s overseas customer support agents for months, aiming to “bribe” them in exchange for customer information, said Coinbase co-founder and CEO Brian Armstrong in a May 15 X post . Source: Brian Armstrong Following the attack, the exchange will strengthen its internal data management processes and relocate some of its customer support operations to avoid similar incidents. Social engineering schemes are a growing concern for Coinbase users. Blockchain security analyst ZachXBT estimated that users lost around $45 million to phishing schemes in the week leading up to May 7. Source: ZachXBT The blockchain security analyst previously claimed that social engineering scams cost Coinbase users over $300 million annually , Cointelegraph reported on Feb. 4. Magazine: Crypto wanted to overthrow banks, now it’s becoming them in stablecoin fight
You may also like

Huang Renxun's Latest Podcast: Will NVIDIA Reach $1 Trillion? Will the Number of Programmers Increase Instead of Decrease? How to Deal with AI Anxiety?
Hashpower will determine everything; human work will only be restructured, not disappear

Besides Resolv Hack, This DeFi Vulnerability Type Has Occurred Four Times
17 minutes, 100k turned into 25M.

Trump Cries Peace, $1.5 Billion Dash | Rewire News Evening Brief
In the first 15 minutes of trading, $1.5 billion in futures trades have already taken place

From x402 to MPP: Cloudflare's crucial vote, will it go to Coinbase or Stripe?
Cloudflare is both building walls and opening windows. It provides both blocking tools and paid access tools. They decide what is kept out, what is allowed in, and under what conditions it can enter.

BlackRock CEO issues annual open letter: The wave of tokenization has arrived, and we will lead this trend
Rebuild capitalism that belongs to everyone.

When Backpack backstabs the community
Once a fundamental rift in trust appears, the cost that Backpack must pay to repair it is likely far more expensive than the profits previously "harvested" through service fees.

When gold is no longer a safe haven, and Bitcoin continues to panic
The whole world is waiting for the Strait of Hormuz to reopen. Why not guess which type of asset will return to pre-war levels first?

Trump, the World's Largest Oil Trader
No matter the outcome, he will not lose money.

If the US and Iran have not reached an agreement in 5 days, what other cards does Trump have?
A $100 Brent implies an approximate 30-40% "strike probability".

Tether Whale Dumps £12 Million, Backing Crypto’s ‘British Trump’
In the US, the crypto industry's big-money push to back Trump and reclaim regulatory control has already played out. In the UK, the same script is unfolding once again.

Ethereum Foundation Post: Rethinking the Division of Work Between L1 and L2 to Build the Ultimate Ethereum Ecosystem
Five years in the making, the Ethereum Foundation has updated the L1 and L2 ecosystem positioning and overarching guidance.

Two Major Prediction Market Platforms Unite Rarely, What Is the Story Behind This New Fund?
When Klashi's early employees went out to raise funds, the two CEOs chose to appear together on the investor list.

Dragonfly Partners: Most agents will not engage in autonomous trading, how can crypto payments prevail?
Although the scale of the agent economy will be very large, the proportion of agents actually conducting transactions will not be that high.

US AI Startup Goes All In on Chinese Mega-Model | Rewire News Morning Brief
The open-source ecosystem and manufacturing data form a dual circulation, allowing progress towards the cutting edge even under chip constraints

Trump Lies Again: A "Five-Day Pause" Psyop, How Wall Street, Bitcoin, and Polymarket Insiders Synced Uposciogen
Five days from now, the market will once again face Trump's "final deadline." Will this be the real endgame, or just another round of back-and-forth?

When a Token Becomes Labor, People Become the Interface
In 2023, having a Card is king. In 2026, having a Token is king.

Ceasefire News Leaked Ahead of Time? Large Polymarket Bets on Outcome Before Trump's Tweet
Minutes before Trump's market-moving social media post, S&P 500 futures and crude oil futures also saw abnormal trading volume.

BlackRock CEO's Annual Shareholder Letter: How is Wall Street Using AI to Keep Profiting from National Pension Funds?
AI is creating enormous wealth, but wealth distribution and risk exposure are replaying in a familiar pattern
Huang Renxun's Latest Podcast: Will NVIDIA Reach $1 Trillion? Will the Number of Programmers Increase Instead of Decrease? How to Deal with AI Anxiety?
Hashpower will determine everything; human work will only be restructured, not disappear
Besides Resolv Hack, This DeFi Vulnerability Type Has Occurred Four Times
17 minutes, 100k turned into 25M.
Trump Cries Peace, $1.5 Billion Dash | Rewire News Evening Brief
In the first 15 minutes of trading, $1.5 billion in futures trades have already taken place
From x402 to MPP: Cloudflare's crucial vote, will it go to Coinbase or Stripe?
Cloudflare is both building walls and opening windows. It provides both blocking tools and paid access tools. They decide what is kept out, what is allowed in, and under what conditions it can enter.
BlackRock CEO issues annual open letter: The wave of tokenization has arrived, and we will lead this trend
Rebuild capitalism that belongs to everyone.
When Backpack backstabs the community
Once a fundamental rift in trust appears, the cost that Backpack must pay to repair it is likely far more expensive than the profits previously "harvested" through service fees.
