Although Coinbase has taken a number of measures to respond, user attacks may have become the "norm."Although Coinbase has taken a number of measures to respond, user attacks may have become the "norm."

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

2025/05/16 15:53
4 min read

Compiled by: Felix, PANews

On May 15, two pieces of negative news about Coinbase were released, causing Coinbase's stock price to suffer a "Waterloo."

One is that Coinbase disclosed a cyber attack involving the theft of internal data and customer information, with a potential financial impact of between $180 million and $400 million.

In addition, sources said that the US SEC is still investigating whether Coinbase falsified user data before its listing in 2021.

Under the influence of two pieces of negative news, Coinbase's stock price fell 7.2% during the day.

Coinbase user data was stolen and blackmailed for $20 million. Social attacks have become the norm

Customer service leaked user data and demanded $ 20 million in ransom

Coinbase said in the report that cyber criminals bribed and recruited a group of malicious customer service staff overseas, who abused their access to the customer support system and stole data from less than 1% of monthly trading users (about 80,000 to 100,000) in the customer support tool. Although no funds, passwords or private keys were stolen, and Coinbase Prime accounts were "unaffected", the attackers used this data to launch targeted social engineering scams against customers.

Regarding this attack method, some crypto experts commented that this type of targeted social engineering attack (using overseas customer support teams) is not uncommon in the crypto industry. Because the information of active users of crypto exchanges is far more valuable than imagined. The average cost of attracting new users for the top exchanges is $5-50 per valid user, while the average cost of attracting new users for small and medium-sized exchanges is $50-300.

After launching a social engineering scam, the Coinbase attackers sent a ransom note demanding $20 million worth of Bitcoin from Coinbase and threatening to release stolen customer data if Coinbase did not pay.

The report states that the attackers obtained:

  • Name, address, phone number and email
  • Masked Social Security Number (last 4 digits only)
  • Blocked bank account numbers and some bank account identifiers
  • Image of government ID (e.g. driver's license, passport)
  • Account data (balance snapshots and transaction history)
  • Limited company data (including documents, training materials, and communications available to customer service personnel)

However, data such as login credentials or two-factor authentication codes, private keys, any ability to transfer or access customer funds, access to Coinbase Prime accounts, and access to any Coinbase or Coinbase customer hot or cold wallets “was not stolen.”

Multiple measures to deal with attacks, refuse to pay ransom and issue bounties

Coinbase took a series of countermeasures after the incident.

First, work closely with law enforcement. The insider who leaked the data was fired on the spot and handed over to US and international law enforcement, and Coinbase said it would file a criminal lawsuit.

Secondly, track the stolen funds. Coinbase worked with industry partners to mark the attacker's address so that authorities can track and recover the assets. And promised to compensate customers who were tricked into sending money to the attacker due to social engineering attacks. To further ensure the security of support operations, Coinbase will open a new support center in the United States and strengthen security controls and monitoring at all locations.

In response to the $20 million ransom demanded by the attacker, Coinbase said it would not pay it. At the same time, Coinbase will set up a $20 million reward fund to reward those who provide clues and help arrest and convict the criminals of this attack.

Coinbase users may be subject to social engineering attacks or have become " normal "

Despite the seemingly positive response measures, security incidents involving Coinbase seem to occur frequently, and the amount of money stolen is also quite large, especially the social engineering scams encountered by users.

In February of this year, on-chain detective ZachXBT disclosed on the X platform that Coinbase users lost more than $65 million due to social engineering scams between December 2024 and January 2025. He said that the estimated $65 million may be "far lower" than the actual amount because it does not take into account the cases submitted to Coinbase support and the police.

ZachXBT cited multiple security incidents and denounced Coinbase for failing to properly handle such scams. “Coinbase needs to make changes urgently because more and more users are being defrauded of tens of millions of dollars every month. Other large exchanges are not experiencing similar situations.”

ZachXBT also urged Coinbase leadership to consider strengthening measures against social engineering attacks, including giving KYC-verified users the option to enter their phone number on the platform, adding a new user account type that limits withdrawals, and increasing community outreach.

These proposals may not have been adopted by Coinbase, but this extortion incident may serve as a wake-up call for Coinbase.

Related reading: Coinbase Q1 financial report explained: Net profit plummeted 94% due to portfolio losses, and the company acquired Deribit to develop derivatives

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Galaxy Digital’s 2025 Loss: SOL Bear Market

Galaxy Digital’s 2025 Loss: SOL Bear Market

The post Galaxy Digital’s 2025 Loss: SOL Bear Market appeared on BitcoinEthereumNews.com. Galaxy Digital, a digital assets and artificial intelligence infrastructure
Share
BitcoinEthereumNews2026/02/04 09:49
Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale

Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale

The post Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 20:13 The meme coin market is heating up once again as traders look for the next breakout token. While Shiba Inu (SHIB) continues to build its ecosystem and PEPE holds onto its viral roots, a new contender, Layer Brett (LBRETT), is gaining attention after raising more than $3.7 million in its presale. With a live staking system, fast-growing community, and real tech backing, some analysts are already calling it “the next PEPE.” Here’s the latest on the Shiba Inu price forecast, what’s going on with PEPE, and why Layer Brett is drawing in new investors fast. Shiba Inu price forecast: Ecosystem builds, but retail looks elsewhere Shiba Inu (SHIB) continues to develop its broader ecosystem with Shibarium, the project’s Layer 2 network built to improve speed and lower gas fees. While the community remains strong, the price hasn’t followed suit lately. SHIB is currently trading around $0.00001298, and while that’s a decent jump from its earlier lows, it still falls short of triggering any major excitement across the market. The project includes additional tokens like BONE and LEASH, and also has ongoing initiatives in DeFi and NFTs. However, even with all this development, many investors feel the hype that once surrounded SHIB has shifted elsewhere, particularly toward newer, more dynamic meme coins offering better entry points and incentives. PEPE: Can it rebound or is the momentum gone? PEPE saw a parabolic rise during the last meme coin surge, catching fire on social media and delivering massive short-term gains for early adopters. However, like most meme tokens driven largely by hype, it has since cooled off. PEPE is currently trading around $0.00001076, down significantly from its peak. While the token still enjoys a loyal community, analysts believe its best days may be behind it unless…
Share
BitcoinEthereumNews2025/09/18 02:50
HKMA Launches Fintech Blueprint with AI, DLT, Quantum and Cybersecurity Focus

HKMA Launches Fintech Blueprint with AI, DLT, Quantum and Cybersecurity Focus

The Hong Kong Monetary Authority (HKMA) published a Fintech Promotion Blueprint to support responsible innovation and fintech development in the banking sector.
Share
Fintechnews2026/02/04 10:20