Coinbase CEO confirms data breach: Users targeted by rogue support agents
By: cryptosheadlines|2025/05/15 22:15:06
0
Share
Airdrop Is Live CaryptosHeadlines Media Has Launched Its Native Token CHT. Airdrop Is Live For Everyone, Claim Instant 5000 CHT Tokens Worth Of $50 USDT. Join the Airdrop at the official website, CryptosHeadlinesToken.com Coinbase has shared a security incident about cybercriminals bribing its overseas customer support agents to access user data. According to the company’s official statement, the breach affected less than 1% of monthly transacting users and did not expose passwords, private keys, or provide access to customer funds. The attackers attempted to extort Coinbase for $20 million to prevent the release of the stolen information. Instead, CEO Brian Armstrong announced that the exchange would establish a $20 million reward fund for information leading to the arrest and conviction of those responsible.Attackers target and compromise customer supportThe security breach happened when cybercriminals targeted Coinbase’s worldwide customer support activities. They offered agents cash bribes to reproduce information from customer support aids.According to the firm’s report, the attackers accessed several types of customer data, including names, addresses, phone numbers, and email addresses. They also accessed masked Social Security numbers (last four digits), masked bank account numbers, some bank account identifiers, government ID photos such as driver’s licenses and passports, snapshots of account balances, and transaction histories.https://t.co/evpIBMFvRW pic.twitter.com/f6UPdkL5R0— Brian Armstrong (@brian_armstrong) May 15, 2025Apart from that, sanctioned corporate data was also utilized by the attackers. These include reports, training materials, and communications that were given to aid agents. However, Coinbase reiterated that the attack did not violate a number of fundamental information categories.Armstrong addressed the hackers, who attempted to blackmail Coinbase for a payment of $20 million in exchange for not releasing the stolen information in his video. “I’m going to respond publicly to these attackers by saying no, we are not going to pay your ransom.”Coinbase launches mitigation measuresCoinbase issued a detailed report of the security incident. This encompasses short-term consumer protections and longer-term security enhancements. Coinbase pledged to “make customers whole” by reimbursing users that were deceived into sending funds to attackers in social engineering attacks via stolen credentials.Coinbase also announced it is opening a new support hub in the United States and implementing stronger security controls and monitoring across all locations. Armstrong specifically mentioned “relocating some of our customer support operations as a result of this” in his video statement.The company is also hardening defenses by increasing investment in insider-threat detection, automated response systems, and security simulations to identify potential vulnerabilities in internal systems. Coinbase confirmed that the compromised insiders “were fired on the spot and referred to U.S. and international law enforcement.”Coinbase issues guidelines to help usersCoinbase has issued specific guidance to help customers protect themselves from potential social engineering attempts that may result from the data breach. The company warns users to be vigilant about imposters who may pose as Coinbase employees and attempt to pressure them into transferring funds.In its safety advisory, Coinbase emphasized several key points about their legitimate communication practices: “Coinbase will never ask for your password, 2FA codes, or for you to transfer assets to a specific or new address, account, vault or wallet. We will never call or text you to give you a new seed phrase or wallet address to move your funds to.” The company advises customers to hang up immediately if they receive such calls.The company has already sent impact notices to affected users and plans to keep the community updated as the investigation progresses. For those customers whose data was compromised, the primary risk comes from potential social engineering attacks where scammers leverage the stolen personal information to appear legitimate when contacting victims.In his video statement, CEO Brian Armstrong delivered a stern message to the attackers and others who might consider targeting the exchange in the future: “For these would-be extortionists or anyone seeking to harm Coinbase customers, know that we will prosecute you and bring you to justice.”KEY Difference Wire: the secret tool crypto projects use to get guaranteed media coverageSource link
You may also like

Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.

The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.

When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."

The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.

Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.

Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.

Huang Renxun's latest podcast transcript: The future of Nvidia, the development of embodied intelligence and agents, the explosion of inference demand, and the public relations crisis of artificial intelligence
The competition in the future is not just about whose model is larger or whose computing power is stronger, but also about who understands the industry better, who can embed AI more deeply into real processes, and who can organize these capabilities into a runnable and scalable system.

OKX Ventures Research Report: AI Agent Economic Infrastructure Research Report (Part 1)
The existing infrastructure is hostile to the Agent economy. Agents can think and act independently at the "capability level," but at the "economic level," they are still locked into infrastructure designed for humans.

The migration of settlement rights: B18 and the institutional starting point of on-chain banks
In the traditional system, banks decide the settlement; in the on-chain system, code begins to take over this responsibility.

From Tencent and Circle: Looking at the Simple and Difficult Questions of Investment
The AI narrative continues to ferment, but the recent performance of related stocks varies, with some in the midst of summer and others as if in winter.

The second half of stablecoins no longer belongs to the crypto circle
What Coinbase doesn't want, Mastercard is eager to buy.

Cursor "Shell" Kimi Controversy Reversed: From Copyright Infringement Allegations to Authorized Collaboration, China's Open Source Model Once Again Becomes a Global AI Foundation
Cursor was accused of being based on Kimi K2.5, which sparked controversy, and was later confirmed to be compliant through Fireworks AI due diligence.

The Real Reason Tokens Don't Sell: 90% of Crypto Projects Overlook Investor Relations
Provide an Investor Relations Best Practices Guide for Crypto Projects.

Is the income of pump.fun real, earning a million dollars a day despite the market downturn?
If it can really earn this much, what is the reason for the low price of $PUMP?

The real reason why tokens are not selling: 90% of crypto projects neglect investor relations
Investor Relations Practice Guide for Cryptocurrency Projects.

Who is the true winner of the "Tokenization" narrative?
Virtually everyone benefits, but the reason for the benefit, the timing, and the underlying logic are completely different.

Moss: The Era of AI-Traded by Anyone | Project Introduction
AI Trading Agent is rapidly growing its infrastructure.

Chip Smuggling Case Exposes Regulatory Loophole | Rewire News Evening Update
AI chips have become a strategic asset more sensitive than missiles
Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.
The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.
When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."
The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.
Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.
Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.