Coinbase Security Breach Scandal: $20 Million Hunt for Data Thieves

Key Takeaways

  • The Coinbase breach, driven by bribed support agents, highlights the vulnerability of centralized exchanges to insider threats, with hackers stealing personal data but not funds.

  • Despite Coinbase’s $20 million bounty and reimbursement pledge, recurring security incidents and a potential $400 million cost could erode user confidence and invite stricter regulations.

Coinbase Security Breach Scandal: $20 Million Hunt for Data Thieves

Coinbase, the largest U.S. cryptocurrency exchange, disclosed a significant data breach in May 2025, affecting less than 1% of its users. Hackers bribed overseas support agents to steal personal data, prompting Coinbase to offer a $20 million bounty for information leading to the culprits’ arrest. The breach could cost the company up to $400 million, raising concerns about centralized exchange security.

$400M Coinbase Breach Hits Less Than 97,000 Users

On May 15, 2025, Coinbase revealed a major cybersecurity incident involving the theft of personal data from a small subset of its customers, estimated at less than 1% of its monthly transacting users (MTUs),  approximately 97,000 customers based on the company’s 9.7 million MTUs reported in its March 2025 annual report.

Hackers orchestrated the breach by bribing and recruiting rogue overseas support agents and contractors, who leaked sensitive information, including names, phone numbers, addresses, government IDs, partial Social Security numbers, and account details. No passwords, private keys, or funds were compromised, and Coinbase’s Prime accounts remained unaffected. The company estimates the financial impact could range from $180 million to $400 million, covering customer reimbursements and recovery efforts.

Read more: Coinbase Caught in $15M Rug Pull Scandal – Is Base Still Safe?

The attackers demanded a $20 million ransom to withhold the stolen data from public release, which Coinbase refused to pay. Instead, the exchange fired the involved staff, announced plans to press criminal charges, and established a $20 million reward fund for information leading to the perpetrators’ arrest and conviction. 

Coinbase Security Breach Scandal: $20 Million Hunt for Data Thieves

Coinbase’s Security Track Record Under Scrutiny

This breach adds to Coinbase’s history of security challenges.

Read more: Is Coinbase Safe?

The exchange has faced prior incidents, including a 2021 hack affecting over 6,000 users, where hackers exploited a flaw in SMS-based two-factor authentication (2FA) through phishing scams, and a 2023 attempt by the Octopus hacker group that did not compromise user funds. 

Despite robust security measures – such as storing 98% of assets in offline cold storage, AES-256 encryption, and insurance for hot wallets – Coinbase has struggled with technical issues like server crashes during high-traffic periods and account recovery vulnerabilities. These incidents fuel user skepticism, with some reporting difficulties obtaining timely support.

coinbase

User Score

9.8

Coinbase Promotion

Get Bonus Up to $600

The 2025 breach, attributed to insider threats rather than a direct system hack, underscores the risks of human error in centralized exchanges. TechCrunch reported that the hackers targeted support staff, exploiting their access to sensitive systems. This tactic echoes a 2023 phishing attack linked to the 0ktapus group, which briefly compromised Coinbase’s systems. 

According to blockchain investigator ZackXBT, over $45 million was stolen from Coinbase users in early May 2025 through social engineering scams. These incidents suggest that organized crime groups are increasingly targeting crypto platforms and their users.

Olivia Chen

Olivia Chen

As a graduate of journalism and a crypto enthusiast, Olivia Chen has been writing in this field for almost 7 years now. She specialized in breaking news about cryptocurrencies, especially Bitcoin. Her sharp eye for detail and quick wit ensure our readers are always up-to-date with the real-time events of the always-changing market.

READ FULL BIO

Disclaimer

NFTevening is an award-nominated media outlet that covers NFTs and the cryptocurrency industry. Opinions expressed on NFTevening are not investment advice. Before making any high-risk investments in cryptocurrency or digital assets, investors should conduct thorough research. Please be aware that any transfers and transactions are done at your own risk, and any losses incurred are entirely your responsibility. NFTevening does not endorse the purchase or sale of any cryptocurrencies or digital assets and is not an investment advisor. Additionally, please note that NFTevening participates in affiliate marketing.

Related posts