Coinbase is now facing mounting scrutiny after it allegedly sat on a serious data breach for over four months, exposing the personal information of nearly 70,000 users before taking action.
The breach, which reportedly began with insiders at an overseas customer support center leaking sensitive data, was discovered in January 2025. However, users and regulators were not informed until May. The compromised data included partial Social Security numbers, home addresses, and account activity tied to support tickets.
The vendor at the center of the leak, TaskUs, is said to have had staff in India who accepted bribes in exchange for screenshots of Coinbase customer information. The exchange has since cut ties with the firm and is reportedly implementing stricter oversight of all third-party partners.
Coinbase now estimates the incident could cost up to $400 million in legal and remediation expenses. Meanwhile, a class-action lawsuit accuses the company of withholding critical information that might have affected its stock performance. A separate case has been filed against TaskUs for negligence.
By March, the stolen data had surfaced in Telegram groups known for crypto fraud, with attackers eventually attempting to extort $20 million from Coinbase in exchange for deleting the files. The company refused and instead offered the same amount as a bounty for leads on the culprits.
Regulatory agencies are now investigating whether Coinbase’s failure to disclose the breach sooner violated SEC rules for public companies.
A former National Crime Agency (NCA) officer has been sentenced to five years and six months in prison after stealing 50 BTC—now worth over £4.4 million—from a criminal investigation he was helping to lead.
The U.S. Securities and Exchange Commission (SEC) has filed emergency enforcement actions against First Liberty Building & Loan, LLC and its founder, Edwin Brant Frost IV, alleging they operated a $140 million Ponzi scheme that spanned more than a decade and defrauded around 300 investors.
A legal clash between Coin Center and the U.S. Treasury Department over sanctions imposed on Tornado Cash has officially come to an end, following a joint decision to dismiss the case.
A sophisticated cyberattack targeting Brazil’s central bank reserve accounts has resulted in the theft of over $140 million (R$800 million), much of which was swiftly funneled through cryptocurrency channels.