A previously undisclosed security breach has exposed sensitive user data of nearly 70,000 Coinbase customers, following what appears to be an internal compromise involving bribed support staff.
The incident, which occurred back in December but only came to light in early May, involved a small group of customer service agents based overseas who were paid off to leak user data.
The attackers gained access to partial banking and social security details, contact information, ID images, and account-related metadata.
Coinbase became aware of the breach after receiving a Bitcoin ransom demand for $20 million. The company refused to pay and notified affected customers by email on May 15.
CEO Brian Armstrong later confirmed in a public statement that Coinbase would reimburse those impacted, bolster its security defenses, and move some of its customer operations away from high-risk regions.
Cleanup costs are expected to fall between $180 million and $400 million, according to internal estimates.
The fight over whether writing privacy-focused code is a crime is heating up on both sides of the Atlantic, and the crypto community is opening its wallet to defend two key Tornado Cash engineers.
A Boston federal court has shut the book on one of crypto’s longest-running fraud cases, ordering the shuttered platform My Big Coin to hand over almost $26 million.
President Javier Milei has been cleared of any ethical misconduct by Argentina’s Anti-Corruption Office after a controversial memecoin post led to investor losses topping $250 million.
ALEX Protocol, a DeFi platform built on Bitcoin’s Stacks layer, has suffered a second major breach—this time resulting in an estimated $14 million loss.