Coinbase User Data Leaked After Insider Scam, But No Funds Stolen
By: the market periodical|2025/05/16 16:30:07
0
Share
Key Insights:Criminals bribed overseas agents to steal Coinbase user data.Coinbase declined the ransom and launched an internal security overhaul.Social engineering scams cost Coinbase users over $90 Million.A recent security incident exposed critical weaknesses in the overseas customer support operations of Coinbase. Criminals succeeded in accessing personal data belonging to less than 1% of the platform’s monthly transacting users.Source: XThey achieved this by bribing outsourced customer support agents, leading to a targeted social engineering scheme. The attackers then demanded $20 Million in extortion from Coinbase to cover the breach.The company declined to pay the demand, launched an investigation, reinforced its controls, and committed to reimbursing affected customers.Coinbase Data Breach: Insider Threats and Phishing RisksAccording to Coinbase, the attackers specifically targeted foreign-based support agents. Using bribes, they persuaded a limited number of insiders to extract sensitive user data from internal tools.This information included names, addresses, emails, and phone numbers. Attackers accessed masked Social Security numbers and partial bank details. They also obtained government-issued ID images and account data like balance snapshots and transaction history.A small amount of internal corporate material was also compromised, including training documents and communications. However, the attackers failed to access critical security assets.Coinbase confirmed that no passwords, private keys, two-factor authentication codes, or access to funds were compromised.Additionally, the breach did not affect Coinbase Prime clients or the company’s hot and cold wallets. The primary aim was to gather user data to facilitate phishing and impersonation scams.Coinbase Responds With Security OverhaulRather than paying the ransom, Coinbase promised to build an internal security apparatus. Customers who were affected were notified directly. The company promised to reimburse all users tricked into sending money to the attackers.Coinbase strengthened security for at-risk accounts by requiring ID checks for large withdrawals. It also added scam-awareness reminders to help users stay alert during transactions.The firm also opened another customer support hub in the United States. This initiative looks to limit the risk of such insider attacks by moving instruments of sensitive operations in-house.The system also includes improved monitoring, insider-threat detection, and automation of threat simulations. Additionally, Coinbase established a $20 million reward fund for information that can be used to identify the attackers.Law enforcement agencies in the United States and internationally have been alerted. Insider agents found to be involved were terminated and referred for criminal prosecution.Coinbase is working with law enforcement to track stolen funds. The assets have been tagged to monitor their movement.Social Engineering Losses Among Coinbase UsersCoinbase is working to resolve an internal breach. On-chain analyst ZachXBT has highlighted a larger issue affecting its users. His recent findings show that users have lost over $90 Million in just two weeks. These losses resulted from social engineering scams.Source: ZachXBT on XThese schemes specifically target Coinbase customers. They use impersonation, phishing links, and other manipulative tactics to steal sensitive data and access funds.ZachXBT, working with fellow investigator Tanuki42, has tracked this pattern over several months. Coinbase users have been the primary victims of these scams. The estimated annual losses could reach $330 Million.With past alerts, these fraudulent activities have continued to affect users adversely. In one recent example, victims lost $45 Million in a week.A similar case the week prior resulted in an additional $46 million loss. These scams typically involve attackers pretending to be Coinbase representatives, requesting urgent account updates or action from users.Ripple’s CTO, David Schwartz, had warned about a similar phishing attempt in January. He had received an email impersonating Coinbase.DisclaimerIn this article, the views and opinions stated by the author or any people named are for informational purposes only, and they don’t establish the investment, financial, or any other advice. Trading or investing in cryptocurrency assets comes with a risk of financial loss.godfrey mwirigiThe post Coinbase User Data Leaked After Insider Scam, But No Funds Stolen appeared first on The Market Periodical.
You may also like

Inter-generational Prisoner's Dilemma Resolution: The Nomadic Capital and Bitcoin's Inevitable Path
When the Baby Boomer generation collectively sells off, who will be the "bag holder" in the next asset crash?

Upstream and downstream are starting to fight, all for the sake of everyone being able to "Lobster"
「Lobster」 may not be a mature product yet, but it has already ushered in a new era of 「AI Assistants」.

Circle and Mastercard Announce Partnership, the Next Stage for the Crypto Industry Belongs to Payments
Stablecoins are transitioning from a speculative tool to real financial scenarios such as payments, cross-border transfers, and store of value.

From 5 Mao per kWh of Chinese electricity to a $45 API export: Tokens are rewriting currency units
When the same unit can both measure hashing power and facilitate payments, it ceases to be just a term and begins to evolve into a new currency of both value and influence.

Why is OpenAI playing catch-up to Claude Code instead?
Anthropic Bets Earlier on AI Programming, OpenAI Strategic Tempo Misaligned

Vitalik wrote a proposal teaching you how to secretly use AI large models
Vitalik believes that in the AI era, users should not have to sacrifice their identity to use an AI tool.

The doubling of Circle's stock price and the paradigm shift of stablecoins
The initial investments from Circle and Stripe, whether it is the R&D expenses for Arc, the high financing costs associated with Tempo, or the billion-dollar acquisitions of Bridge-type assets, are more akin to "placement fees" rather than commercially recoverable investments in the short term.

Key Market Information Discrepancy on March 13th - A Must-See! | Alpha Morning Report
1. Top News: Latest Developments in US-Iran Conflict, Son of Soleimani Vows Revenge, US Navy Plans to Escort Ships in the Strait of Hormuz
2. Token Unlock: $HTM

On-Chain Options Explosion.ActionEvent
Options are becoming the new anchor in the cryptocurrency market.

《Time》 Magazine Names Anthropic as the World's Most Disruptive Company
The most AI-wary company has created the most dangerous AI

Predictions market gains mainstream traction in the US, Canada, Claude launches Chart Interaction feature, What's the English community talking about today?
What Did Foreigners Care About Most in the Last 24 Hours?

500 Million Dollars, 12 Seconds to Zero: How an Aave Transaction Fed Ethereum's "Dark Forest" Food Chain
Spend $154,000 to buy AAVE at market price of only $111

AI Agent needs Crypto, not Crypto needs AI
It is not Crypto that needs AI to survive, but rather AI Agents that need Crypto to be implemented: when AI truly shifts from "thinking" to "executing," it must seek the boundaries of authority and funding within the programmable primitives of Crypto.

Stablecoins are breaking away from cryptocurrency, becoming the next generation of infrastructure for global payments
The use of stablecoins is shifting from facilitating low-cost cross-border remittances to supporting general commercial activities and inter-company vendor payments.

Web3 teams should stop wasting marketing budgets on the X platform
The announcements from the project party are still very important, but they should no longer be the starting point of promotional activities; instead, they should be the endpoint.

Strive buys Strategy stocks, and Bitcoin treasury companies start nesting each other
When everyone's bets are placed on the same table, the difference between "structured financing" and "concentrated gambling" may just be a few more arrows drawn on the PPT.

Strive to buy Strategy stock, Bitcoin Treasury company starts nesting dolls with each other
Bitcoin hodlers are starting to nested be in each other.

Key Market Intel on March 12th, how much did you miss out on?
1. On-chain Funds: $29.7M inflow to Hyperliquid today; $30.9M outflow from Base
2. Biggest Gainers/Losers: $DRV, $LYN
3. Top News: US plans to release 172M barrels of oil to curb prices, on-chain pre-market crude oil gains narrow by 4%
Inter-generational Prisoner's Dilemma Resolution: The Nomadic Capital and Bitcoin's Inevitable Path
When the Baby Boomer generation collectively sells off, who will be the "bag holder" in the next asset crash?
Upstream and downstream are starting to fight, all for the sake of everyone being able to "Lobster"
「Lobster」 may not be a mature product yet, but it has already ushered in a new era of 「AI Assistants」.
Circle and Mastercard Announce Partnership, the Next Stage for the Crypto Industry Belongs to Payments
Stablecoins are transitioning from a speculative tool to real financial scenarios such as payments, cross-border transfers, and store of value.
From 5 Mao per kWh of Chinese electricity to a $45 API export: Tokens are rewriting currency units
When the same unit can both measure hashing power and facilitate payments, it ceases to be just a term and begins to evolve into a new currency of both value and influence.
Why is OpenAI playing catch-up to Claude Code instead?
Anthropic Bets Earlier on AI Programming, OpenAI Strategic Tempo Misaligned
Vitalik wrote a proposal teaching you how to secretly use AI large models
Vitalik believes that in the AI era, users should not have to sacrifice their identity to use an AI tool.