Coinbase Says Cybercriminals Breached User Data, Demanded $20 Million Ransom
By: gadgets 360|2025/05/15 22:15:06
0
Share
Coinbase confirmed a customer data breach on its platform Thursday and claimed a group of rogue overseas support agents recruited by cyber criminals were responsible for the attack. In a video message posted on X, Coinbase CEO Brian Armstrong said cyber attackers wrote to the exchange, claiming they had obtained personal data of a portion of Coinbase users. In exchange for not leaking the data, the attackers allegedly demanded a ransom of $20 million (roughly Rs. 171 crore). The development comes just days after Coinbase became the first crypto firm to have secured a spot on the elite S&P 500 index. The exchange has refused to surrender to the demand of the attackers. No passwords, private keys, or funds were exposed in the breach, the exchange said. Coinbase Prime accounts, too, were unaffected by the attack. Cyber criminals “bribed and recruited” a group of rogue overseas support agents to steal Coinbase customer data, Coinbase said in a blog post published Thursday. “These insiders abused their access to customer support systems to steal the account data for a small subset of customers,” the firm said. According to the exchange, the attackers' aim was to execute social engineering attacks and get individuals to transfer funds. Coinbase said it would reimburse customers who were tricked into sending funds to the attacker, but did not elaborate on the details of the reimbursement process. It said the reimbursements would happen voluntarily via Coinbase after facts were reviewed. As per the exchange, the attackers managed to obtain bank account numbers, government IDs, and the account data of the impacted users. Other details such as names, addresses, emails, and masked social security numbers have also been compromised in the breach. The exchange claims that data of less than one percent of its users was breached as part of the incident. It is uncertain if the data breach only affected Coinbase users in the US or if international users were at risk, as well. The exchange recently acquired its FIU registration in India to mark its re-entry into the country. Addressing the breach, Armstrong said that no ransom would be paid to the attackers. Instead, Coinbase was setting up a $20 million reward fund for information leading to the identification of the attackers. The exchange said it was working closely with law enforcement agencies to ensure the “harshest” penalties on the attackers. Coinbase is also working with industry partners to trace the attackers through their wallet addresses and attempt to recover assets. Coinbase has not disclosed the amount wired to the attackers by unsuspecting users. In the first quarter of this year, Coinbase reported $9.9 billion (roughly Rs. 84,632 crore) in USD resources. The exchange also reported a total revenue of $2 billion between January and March this year, along with a net income of $66 million (roughly Rs. 564 crore). Just this week, the exchange announced the acquisition of Deribit, a renowned crypto derivatives platform. After completing the $2.9 billion acquisition, Armstrong reportedly said the exchange was planning to explore more mergers and acquisitions.
You may also like

Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.

The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.

When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."

The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.

Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.

Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.

Huang Renxun's latest podcast transcript: The future of Nvidia, the development of embodied intelligence and agents, the explosion of inference demand, and the public relations crisis of artificial intelligence
The competition in the future is not just about whose model is larger or whose computing power is stronger, but also about who understands the industry better, who can embed AI more deeply into real processes, and who can organize these capabilities into a runnable and scalable system.

OKX Ventures Research Report: AI Agent Economic Infrastructure Research Report (Part 1)
The existing infrastructure is hostile to the Agent economy. Agents can think and act independently at the "capability level," but at the "economic level," they are still locked into infrastructure designed for humans.

The migration of settlement rights: B18 and the institutional starting point of on-chain banks
In the traditional system, banks decide the settlement; in the on-chain system, code begins to take over this responsibility.

From Tencent and Circle: Looking at the Simple and Difficult Questions of Investment
The AI narrative continues to ferment, but the recent performance of related stocks varies, with some in the midst of summer and others as if in winter.

The second half of stablecoins no longer belongs to the crypto circle
What Coinbase doesn't want, Mastercard is eager to buy.

Cursor "Shell" Kimi Controversy Reversed: From Copyright Infringement Allegations to Authorized Collaboration, China's Open Source Model Once Again Becomes a Global AI Foundation
Cursor was accused of being based on Kimi K2.5, which sparked controversy, and was later confirmed to be compliant through Fireworks AI due diligence.

The Real Reason Tokens Don't Sell: 90% of Crypto Projects Overlook Investor Relations
Provide an Investor Relations Best Practices Guide for Crypto Projects.

Is the income of pump.fun real, earning a million dollars a day despite the market downturn?
If it can really earn this much, what is the reason for the low price of $PUMP?

The real reason why tokens are not selling: 90% of crypto projects neglect investor relations
Investor Relations Practice Guide for Cryptocurrency Projects.

Who is the true winner of the "Tokenization" narrative?
Virtually everyone benefits, but the reason for the benefit, the timing, and the underlying logic are completely different.

Moss: The Era of AI-Traded by Anyone | Project Introduction
AI Trading Agent is rapidly growing its infrastructure.

Chip Smuggling Case Exposes Regulatory Loophole | Rewire News Evening Update
AI chips have become a strategic asset more sensitive than missiles
Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.
The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.
When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."
The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.
Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.
Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.