Coinbase Faces User Backlash Over Data Leak Allegations Amid Privacy Concerns and Delayed Disclosure
By: en coinotag|2025/05/16 16:45:05
0
Share
Coinbase faces backlash after an insider leaked user records, exposing sensitive data like IDs and addresses to phishing scams. Allegations claim Coinbase knew of the breach since January but delayed disclosure, leaving users vulnerable to impersonation and fraud. The leak raises severe risks, highlighting failures in internal controls and fueling fears of centralized data becoming a target for criminals. Coinbase’s data leak exposes user vulnerabilities, revealing serious internal failures and raising concerns about customer safety amidst ongoing scams. Users Outraged as Data Leak Happened Months Before Disclosure The insider breach, which reportedly affected “less than 1%” of Coinbase’s monthly active users, has sparked widespread outrage across the crypto community. Users report being targeted in sophisticated phishing and impersonation scams. Among them is QwQiao, an alleged targeted victim who recounts the scam’s chilling precision. QwQiao, who works in customer support at Alliance DAO, said he almost fell victim but outsmarted the bad actors. “...I called them out at the end of the call telling them they need to step up their game because this scam is retarded. They told me that they had made $7 million that day,” he stated. Adam Cochran, a renowned X (Twitter) figure, condemned Coinbase’s failure to protect data like government IDs and physical addresses. He says this shortfall poses risks that far exceed financial loss. “Coinbase’s disclosure here focuses on the stolen funds, but that’s irrelevant...No element of KYC/AML policy requires this kind of stuff to be accessible to your customer support agents. I don’t want to hear about what Coinbase is doing to recover funds – I want to hear what they are doing to better deal with private data,” he expressed. The outrage comes amid allegations that the breach occurred as far back as January. Users and analysts say Coinbase’s supposed silence left users vulnerable for months. “Coinbase knew they got their user data stolen since January, but said nothing until now? We’ve had endless reports of Coinbase users being drained by impersonators. Now we know why,” wrote Duo Nine, a renowned analyst. According to Duo Nine, Coinbase’s supposed oversight puts even institutional holdings at a concentrated risk. Coinbase plays a dominant role in the crypto spot ETF (exchange-traded fund) market. Specifically, it provides custody services for eight of 11 Bitcoin ETFs and eight of nine Ethereum ETFs. Coinbase exchange also offers trading execution and market surveillance services. Notably, this is not the first time its dominance in custody services has led to concerns about its position as a potential single point of failure. “It doesn’t bode well that nearly all crypto ETF issuers have the same custodian for all their BTC and ETH. This makes Coinbase a potential single point of failure, and that’s scary,” Eleanor Terret said recently. Coinbase did not immediately respond to COINOTAG’s request for comment. Risks of the Leak Are Unpredictable and Dangerous Meanwhile, concerns arise that this breach is uniquely disturbing because Coinbase was not hacked. Instead, it was betrayed from within. A support employee accessed and sold customer data on the black market. To some, this presents as a glaring failure of internal controls. Bob Loukas, a position trader, spoke plainly, calling out the exchange for a lack of proper disclosure. “You know you’re sitting on the most sought-after data, and you allowed support agents to access it in bulk. That’s unacceptable,” Loukas stated. The implications go beyond financial theft, with Rotki founder Lefteris Karapetsas warning that centralizing real-life identity data alongside crypto balances is a “disaster waiting to happen.” “Coinbase just proved again why centralized data honeypots are a disaster waiting to happen. KYC means handing over your identity to be leaked, sold, or extorted. The combination of data exposed here (real-life addresses, crypto addresses, and amount and real-life ID documents) is lethal,” he posted. Rotki is a portfolio tracking app, with Karapetsas, a data protection expert, referencing a recent kidnapping attempt involving a Paris crypto leader’s family. Ariel Givner, a corporate attorney specializing in fintech, confirmed the real-world fears. “I’ve had five individuals contact me today. They are scared for their and their family’s safety. It can get worse,” she wrote. Intelligence experts say the incident may be part of a larger dark web sale. According to cybersecurity sources, a threat actor recently offered an 18-million-record trove from US crypto platforms. Among them, over 432,000 Coinbase user records for $10,000, featuring names, emails, phone numbers, addresses, and more. Coinbase has yet to address the user outrage, but it is offering a $20 million reward fund for information leading to the arrest and conviction of bad actors. The exchange said it contacted all affected victims. “If your data was accessed, you have already received an email from [email protected]; all notifications went out at 7:20 a.m. ET to affected customers,” Coinbase Support said on X Conclusion In light of these events, Coinbase’s breaches raise significant concerns regarding data security and internal controls. As users face ongoing phishing risks, the exchange must implement stringent measures to restore trust.
You may also like

Inter-generational Prisoner's Dilemma Resolution: The Nomadic Capital and Bitcoin's Inevitable Path
When the Baby Boomer generation collectively sells off, who will be the "bag holder" in the next asset crash?

Upstream and downstream are starting to fight, all for the sake of everyone being able to "Lobster"
「Lobster」 may not be a mature product yet, but it has already ushered in a new era of 「AI Assistants」.

Circle and Mastercard Announce Partnership, the Next Stage for the Crypto Industry Belongs to Payments
Stablecoins are transitioning from a speculative tool to real financial scenarios such as payments, cross-border transfers, and store of value.

From 5 Mao per kWh of Chinese electricity to a $45 API export: Tokens are rewriting currency units
When the same unit can both measure hashing power and facilitate payments, it ceases to be just a term and begins to evolve into a new currency of both value and influence.

Why is OpenAI playing catch-up to Claude Code instead?
Anthropic Bets Earlier on AI Programming, OpenAI Strategic Tempo Misaligned

Vitalik wrote a proposal teaching you how to secretly use AI large models
Vitalik believes that in the AI era, users should not have to sacrifice their identity to use an AI tool.

The doubling of Circle's stock price and the paradigm shift of stablecoins
The initial investments from Circle and Stripe, whether it is the R&D expenses for Arc, the high financing costs associated with Tempo, or the billion-dollar acquisitions of Bridge-type assets, are more akin to "placement fees" rather than commercially recoverable investments in the short term.

Key Market Information Discrepancy on March 13th - A Must-See! | Alpha Morning Report
1. Top News: Latest Developments in US-Iran Conflict, Son of Soleimani Vows Revenge, US Navy Plans to Escort Ships in the Strait of Hormuz
2. Token Unlock: $HTM

On-Chain Options Explosion.ActionEvent
Options are becoming the new anchor in the cryptocurrency market.

《Time》 Magazine Names Anthropic as the World's Most Disruptive Company
The most AI-wary company has created the most dangerous AI

Predictions market gains mainstream traction in the US, Canada, Claude launches Chart Interaction feature, What's the English community talking about today?
What Did Foreigners Care About Most in the Last 24 Hours?

500 Million Dollars, 12 Seconds to Zero: How an Aave Transaction Fed Ethereum's "Dark Forest" Food Chain
Spend $154,000 to buy AAVE at market price of only $111

AI Agent needs Crypto, not Crypto needs AI
It is not Crypto that needs AI to survive, but rather AI Agents that need Crypto to be implemented: when AI truly shifts from "thinking" to "executing," it must seek the boundaries of authority and funding within the programmable primitives of Crypto.

Stablecoins are breaking away from cryptocurrency, becoming the next generation of infrastructure for global payments
The use of stablecoins is shifting from facilitating low-cost cross-border remittances to supporting general commercial activities and inter-company vendor payments.

Web3 teams should stop wasting marketing budgets on the X platform
The announcements from the project party are still very important, but they should no longer be the starting point of promotional activities; instead, they should be the endpoint.

Strive buys Strategy stocks, and Bitcoin treasury companies start nesting each other
When everyone's bets are placed on the same table, the difference between "structured financing" and "concentrated gambling" may just be a few more arrows drawn on the PPT.

Strive to buy Strategy stock, Bitcoin Treasury company starts nesting dolls with each other
Bitcoin hodlers are starting to nested be in each other.

Key Market Intel on March 12th, how much did you miss out on?
1. On-chain Funds: $29.7M inflow to Hyperliquid today; $30.9M outflow from Base
2. Biggest Gainers/Losers: $DRV, $LYN
3. Top News: US plans to release 172M barrels of oil to curb prices, on-chain pre-market crude oil gains narrow by 4%
Inter-generational Prisoner's Dilemma Resolution: The Nomadic Capital and Bitcoin's Inevitable Path
When the Baby Boomer generation collectively sells off, who will be the "bag holder" in the next asset crash?
Upstream and downstream are starting to fight, all for the sake of everyone being able to "Lobster"
「Lobster」 may not be a mature product yet, but it has already ushered in a new era of 「AI Assistants」.
Circle and Mastercard Announce Partnership, the Next Stage for the Crypto Industry Belongs to Payments
Stablecoins are transitioning from a speculative tool to real financial scenarios such as payments, cross-border transfers, and store of value.
From 5 Mao per kWh of Chinese electricity to a $45 API export: Tokens are rewriting currency units
When the same unit can both measure hashing power and facilitate payments, it ceases to be just a term and begins to evolve into a new currency of both value and influence.
Why is OpenAI playing catch-up to Claude Code instead?
Anthropic Bets Earlier on AI Programming, OpenAI Strategic Tempo Misaligned
Vitalik wrote a proposal teaching you how to secretly use AI large models
Vitalik believes that in the AI era, users should not have to sacrifice their identity to use an AI tool.