Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

2025/05/16 15:53

Compiled by: Felix, PANews

On May 15, two pieces of negative news about Coinbase were released, causing Coinbase's stock price to suffer a "Waterloo."

One is that Coinbase disclosed a cyber attack involving the theft of internal data and customer information, with a potential financial impact of between $180 million and $400 million.

In addition, sources said that the US SEC is still investigating whether Coinbase falsified user data before its listing in 2021.

Under the influence of two pieces of negative news, Coinbase's stock price fell 7.2% during the day.

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

Customer service leaked user data and demanded $ 20 million in ransom

Coinbase said in the report that cyber criminals bribed and recruited a group of malicious customer service staff overseas, who abused their access to the customer support system and stole data from less than 1% of monthly trading users (about 80,000 to 100,000) in the customer support tool. Although no funds, passwords or private keys were stolen, and Coinbase Prime accounts were "unaffected", the attackers used this data to launch targeted social engineering scams against customers.

Regarding this attack method, some crypto experts commented that this type of targeted social engineering attack (using overseas customer support teams) is not uncommon in the crypto industry. Because the information of active users of crypto exchanges is far more valuable than imagined. The average cost of attracting new users for the top exchanges is $5-50 per valid user, while the average cost of attracting new users for small and medium-sized exchanges is $50-300.

After launching a social engineering scam, the Coinbase attackers sent a ransom note demanding $20 million worth of Bitcoin from Coinbase and threatening to release stolen customer data if Coinbase did not pay.

The report states that the attackers obtained:

  • Name, address, phone number and email
  • Masked Social Security Number (last 4 digits only)
  • Blocked bank account numbers and some bank account identifiers
  • Image of government ID (e.g. driver's license, passport)
  • Account data (balance snapshots and transaction history)
  • Limited company data (including documents, training materials, and communications available to customer service personnel)

However, data such as login credentials or two-factor authentication codes, private keys, any ability to transfer or access customer funds, access to Coinbase Prime accounts, and access to any Coinbase or Coinbase customer hot or cold wallets “was not stolen.”

Multiple measures to deal with attacks, refuse to pay ransom and issue bounties

Coinbase took a series of countermeasures after the incident.

First, work closely with law enforcement. The insider who leaked the data was fired on the spot and handed over to US and international law enforcement, and Coinbase said it would file a criminal lawsuit.

Secondly, track the stolen funds. Coinbase worked with industry partners to mark the attacker's address so that authorities can track and recover the assets. And promised to compensate customers who were tricked into sending money to the attacker due to social engineering attacks. To further ensure the security of support operations, Coinbase will open a new support center in the United States and strengthen security controls and monitoring at all locations.

In response to the $20 million ransom demanded by the attacker, Coinbase said it would not pay it. At the same time, Coinbase will set up a $20 million reward fund to reward those who provide clues and help arrest and convict the criminals of this attack.

Coinbase users may be subject to social engineering attacks or have become " normal "

Despite the seemingly positive response measures, security incidents involving Coinbase seem to occur frequently, and the amount of money stolen is also quite large, especially the social engineering scams encountered by users.

In February of this year, on-chain detective ZachXBT disclosed on the X platform that Coinbase users lost more than $65 million due to social engineering scams between December 2024 and January 2025. He said that the estimated $65 million may be "far lower" than the actual amount because it does not take into account the cases submitted to Coinbase support and the police.

ZachXBT cited multiple security incidents and denounced Coinbase for failing to properly handle such scams. “Coinbase needs to make changes urgently because more and more users are being defrauded of tens of millions of dollars every month. Other large exchanges are not experiencing similar situations.”

ZachXBT also urged Coinbase leadership to consider strengthening measures against social engineering attacks, including giving KYC-verified users the option to enter their phone number on the platform, adding a new user account type that limits withdrawals, and increasing community outreach.

These proposals may not have been adopted by Coinbase, but this extortion incident may serve as a wake-up call for Coinbase.

Related reading: Coinbase Q1 financial report explained: Net profit plummeted 94% due to portfolio losses, and the company acquired Deribit to develop derivatives

Aviso legal: Los artículos republicados en este sitio provienen de plataformas públicas y se ofrecen únicamente con fines informativos. No reflejan necesariamente la opinión de MEXC. Todos los derechos pertenecen a los autores originales. Si consideras que algún contenido infringe derechos de terceros, comunícate con service@support.mexc.com para solicitar su eliminación. MEXC no garantiza la exactitud, la integridad ni la actualidad del contenido y no se responsabiliza por acciones tomadas en función de la información proporcionada. El contenido no constituye asesoría financiera, legal ni profesional, ni debe interpretarse como recomendación o respaldo por parte de MEXC.

También te puede interesar

Stablecoin Speculation Triggers Swings, Hong Kong SFC and HKMA Caution Investors

Stablecoin Speculation Triggers Swings, Hong Kong SFC and HKMA Caution Investors

Key Takeaways: Global stablecoin policy approaches vary, creating potential competitive advantages for certain jurisdictions. Issuers may adjust their base of operations based on regulatory timelines and operational flexibility. Cross-border stablecoin adoption could be influenced by regional licensing requirements and compliance costs. The Securities and Futures Commission (SFC) and the Hong Kong Monetary Authority (HKMA) have issued a joint statement cautioning investors about sharp market movements linked to stablecoin-related announcements . The statement , published on August 14, comes amid price swings triggered by corporate disclosures, media coverage, social media posts, and speculation over potential stablecoin licensing in the city. Strict Stablecoin Licensing Criteria in Hong Kong The regulators noted that some claims have referenced recent communications with financial authorities, but stressed that such interactions form only part of the licensing process. The HKMA said approval depends on meeting high thresholds set under its stablecoin issuer framework. “An indication of interest or application for a stablecoin licence, and the HKMA’s communication with the interested entities are just part of the licensing process ,” the HKMA said. “The granting of a licence will be determined by the fulfilment of the licensing criteria.” The SFC and HKMA warned that preliminary plans or licence applications often carry considerable uncertainty. 🚀 GF Securities has teamed up with @HashKeyGroup to roll out tokenized securities denominated in US dollars, Hong Kong dollars, and offshore yuan. #Hashkey #Tokenization https://t.co/6DuiJE1WXl — Cryptonews.com (@cryptonews) June 27, 2025 They said market volatility driven by speculation can prompt irrational investor decisions, leading to unnecessary financial risks. The agencies urged the public to conduct thorough research and avoid basing investment choices on price momentum or market hype. SFC Executive Warns of Volatility SFC Chief Executive Officer Julia Leung said investors should be wary of unsubstantiated claims, particularly on social media. “They should always be mindful of the misleading prospects of gains from short-term price volatility,” she said, adding that the SFC will continue monitoring market activity and take enforcement action against manipulative or deceptive conduct. HKMA Chief Executive Eddie Yue said only a small number of stablecoin licences will be granted initially. He confirmed that the authority has engaged with dozens of parties interested in licensing, but stressed that such contact does not indicate approval or endorsement of any applicant’s prospects. The regulators also reminded market participants to avoid public statements that could mislead investors or create unrealistic expectations, demonstrating that safeguarding market integrity remains a shared priority. With Hong Kong moving forward with its regime, market participants may increasingly compare approval timelines, compliance costs, and operational flexibility across regions—factors that could influence where major issuers choose to base their activities and how cross-border stablecoin use evolves. Frequently Asked Questions (FAQs) How do other major jurisdictions regulate stablecoin issuers? Approaches range from comprehensive licensing regimes in Singapore and the EU to more fragmented state-level oversight in the U.S. Could differing regulations lead to market fragmentation? Yes. Divergent rules may create regional ecosystems with limited interoperability, affecting liquidity and cross-border transaction efficiency. What factors influence where a stablecoin issuer chooses to operate? Issuers typically consider regulatory clarity, licensing speed, capital requirements, and the jurisdiction’s openness to digital asset innovation. How might cross-border adoption evolve? If multiple jurisdictions align on technical and compliance standards, stablecoins could see broader use in international trade and remittances. Do regulatory differences affect investor protection? Yes. Stronger oversight can improve disclosure and safeguard measures, but may also increase operational costs for issuers.
Compartir
CryptoNews2025/08/15 02:29