11 ms·
I have recordings proving Coinbase knew about breach months before disclosure
- jclarkcom 11mo agoIn January 2025, I was targeted by scammers who knew my exact Bitcoin balance, SSN, DL, and other private Coinbase account details. I immediately reported this to Coinbase's Head of Trust & Safety with recordings and technical evidence. Despite repeated follow-ups asking how attackers had my data, Coinbase went silent for 4 months. They only disclosed the breach in May after attackers demanded $20M ransom. The breach involved overseas contractors at TaskUs being bribed for customer data. This article documents the timeline with emails, recordings, and evidence showing Coinbase was aware of the breach months before their official "discovery" date.
- scottiebarnes 11mo agoAre you going to be suing?
- jclarkcom 11mo agoI would consider it but I'm not sure what my options are on this.
- criddell 11mo agoWere you harmed? I've never looked at the Coinbase agreement that's presented when you open an account, but chances are you would have to go through arbitration first. That's not necessarily a bad thing.
- tyre 11mo agoYou’d need to prove harm, which is somewhat nebulous here.* Matt Levine has a prescient and depressing quote about the only recourse for being being shareholder lawsuits: > I find all of this so weird because of how it elevates finance. [Various cases] imply that we are not entitled to be protected from pollution as citizens, or as humans. [Another] implies that we are not entitled to be told the truth as citizens. (Which: is true!) Rather, in each case, we are only entitled to be protected from lies as shareholders. The great harm of pollution, or of political dishonesty, is that it might lower the share prices of the companies we own. * To be clear, I don’t think it is nebulous, and you’re right to feel harmed. But, legally, I don’t know the harm in “they didn’t respond to my emails” after there’s no concrete damage.
- nightpool 11mo agoYou mentioned that the DKIM headers "passed validation for coinbase.com". How could that have been possible, if the email was a phishing email? I'm not sure I understood that part, especially because you didn't provide any examples of the header data you received from the attacker.
- Cantinflas 11mo agoYeah this is very confusing for me too, how could the attackers create a valid DKIM signature for coinbase.com? Either there is a huge misconfiguration or it's not possible. Am I missing something?
- s5ma6n 11mo agoThanks for sharing it, however I have an unrelated comment. Maybe I am in minority here but just wanted to provide this feedback: The background animation of the blog page is really distracting and making it difficult to focus on the actual content.
- jmclnx 11mo agoIsn't there a new law from the Biden era that forces a company disclose breaches to their customers and the SEC within a few weeks ? If so and if the US had a sane administration maybe, this would be acted upon, but these days, anything goes as long as you 'donate' to the ballroom.
- jclarkcom 11mo agoYes, I did briefly touch on that in the article. "SEC rules require timely reporting of material cybersecurity incidents." Looking into this more now I see SEC Rule requiring disclosure within 4 business days of determining a cybersecurity incident is "material" There is a big list of SEC violations as a result: 1. Late Disclosure (Item 1.05) If materiality was determinable in January → 4-day rule violated Penalty: Fines, enforcement actions 2. Misleading Statements/Omissions (Rule 10b-5) Any public statements about security between Jan-May could be problematic Omitting known material risks = securities fraud 3. Inadequate Internal Controls (SOX) Failure to properly investigate and escalate user reports Inadequate breach detection systems 4. Failure to Maintain Adequate Disclosure Controls My report should have triggered disclosure review Going silent suggests broken escalation process
- divvvyy 11mo agoWild tale, but very annoying that he wrote it with an AI. It's horribly jarring to read.
- Grimblewald 11mo agoHow do you know? I'm not trying to be recalcitrant, rather I am genuinly curious. The reason I ask is that no one talks like a LLM, but LLMs do talk like someone. LLMs learned to mimic human speech patterns, and some unlucky soul(s) out there have had their voice stolen. Earlier versions of LLMs of LLMs that more closely followed the pattern and structure of a wikipedia entry were mimicking a style that that was based of someone elses style and given some wiki users had prolific levels of contributions, much of their naturally generated text would register as highly likely to be "AI" via those bullshit ai detector tools. So, given what we know of LLMs (transformers at least) at this stage it seems more likely to me that current speech patterns again are mimicry of someones style rather than an organically grown/developed thing that is personal to the LLM.
- gmzamz 11mo agoLooks like AI to me too. Em dashes (albeit nonstandard) and the ‘it’s not just x, it’s y’ ending phrases were everywhere. Harder to put into words but there’s a sense of grandiosity in the article too. Not saying the article is bad, it seems pretty good. Just that there are indications
- AlexErrant 11mo agoHere's a Reuters report from June 2, which includes a link to a May 14 SEC filing: > Cryptocurrency exchange Coinbase knew as far back as January about a customer data leak at an outsourcing company connected to a larger breach estimated to cost up to $400 million, six people familiar with the matter told Reuters. https://www.reuters.com/sustainability/boards-policy-regulation/coinbase-breach-linked-customer-data-leak-india-sources-say-2025-06-02/ https://www.reuters.com/sustainability/boards-policy-regulat... > On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase Global, Inc. (“Coinbase” or the “Company”), received an email communication from an unknown threat actor claiming to have obtained information about certain Coinbase customer accounts, as well as internal Coinbase documentation, including materials relating to customer-service and account-management systems. https://www.sec.gov/Archives/edgar/data/1679788/000167978825000094/coin-20250514.htm https://www.sec.gov/Archives/edgar/data/1679788/000167978825...
- jclarkcom 11mo agoVery interesting... January 7th is when I reported it to them so that lines up. I suspect I wasn't the very first person, the person I spoke with on the phone had the confidence I wouldn't expect on the first try.
- j-bos 11mo ago> an outsourcing company From what I've seen, this is going to be a common subheading to a lot of these stories.
- johnebgd 11mo agoBusiness process outsourcing firm most likely (BPO). They get contracts for every kind of company you’ve ever heard of, lie about their cybersecurity practices, and then rebrand if they get caught.
- ChrisMarshallNY 11mo agoSound like rich targets for hacking.
- chaps 11mo agoOnce did some programming/networking work for a company that did the networking of a office sharing building that Coinbase was running out of. Early in my work there I noticed that the company had its admin passwords written on a whiteboard -- visible from the hallway because they had glass for walls. So I sent them an email to ask that they remove it (I billed them for it). Their fix was to put a piece of paper over the passwords. What a time.
- Aurornis 11mo ago> So I sent them an email to ask that they remove it (I billed them for it) Sending unsolicited bills for unrequested services is a great way to make sure nobody takes your email seriously
- nightpool 11mo agoGP is saying that they were already one of Coinbase's vendors (they did the networking/IT setup for Coinbase's office). Whether you'd tolerate that kind of behavior from a vendor is one thing, but for an existing vendor relationship I think adding a few billable hours for "I found this issue in your network and documented and reported it for you" to an existing contract is not particularly unreasonable.
- BrenBarn 11mo ago[flagged]
- anonym29 11mo agoYour employer doesn't utilize low-cost overseas labor to pad margins?
- rs186 11mo agoNot parent but mine doesn't let them handle client social security numbers.
- sfblah 11mo agoI've read that blockchain can be used to eliminate the risk of crypto companies doing shady things. /s
- tomhow 11mo ago> shocked, shocked Please omit internet tropes and avoid posting shallow dismissals on HN. Substantive critique is always fine. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- tchalla 11mo agoFounder mode.
- anonym29 11mo agoHas anyone demonstrated that agentic AI systems can be bribed with money, or is that vulnerability still strictly relegated to unrealiable, untrustworthy biological intelligence?
- paulbjensen 11mo agoI got rung in the UK I think a month ago from someone claiming to be from Coinbase. I told them I only had about £5 of Bitcoin cash in my account (which was true), and they immediately lost interest and said a forthcoming email would handle the matter. They also asked if I had cold storage. I told them I had a fridge (also true).
- KetoManx64 11mo agoHahaha, i'm using this next time I get a spam call
- naruhodo 11mo agoAn elderly friend of mine has been receiving Coinbase security alerts. Needless to say, she has never used the site and has no crypto.
- jrm4 11mo agoFWIW, this is why "not your keys, not your coins." Coinbase is good for on-ramping, bad for storage. You know, the entire point of cryptocurrency.
- wmf 11mo agoPeople doing self-custody also get hacked and phished all the time.
- petesergeant 11mo agohttps://imgflip.com/i/acbvxh https://imgflip.com/i/acbvxh
- jclarkcom 11mo agoTrue - but be very careful. Roughly 10–18% of all BTC are believed gone forever due to lost keys/wallets. That is more than all hacks and exchange blowups combined. If you take your wallet offline it can be hard not to lose your keys over a long period of time, including across death to your next of kin.
- mtlynch 11mo agoThis is an extremely clickbaity headline. The "recordings" are of a phisher attempting to get information from the author. It proves nothing about what Coinbase knew. The author turned the information over to Coinbase, but that doesn't prove Coinbase knew about their breach. The customer could have leaked their account details in some other way.
- jclarkcom 11mo agoI sent the phone recording and emails to coinbase, and they acknowledged them saying "This report is super robust and gives us a lot to look into. We are investigating this scammer now."
- mmooss 11mo agoIt seems like you did a great job collecting info and reporting it. Still, how do you know that the info was obtained via Coinbase? Certainly they are a likely vector but you are too, and maybe there are others. Edit: Nevermind; I see you addressed that here: https://news.ycombinator.com/item?id=45948808 https://news.ycombinator.com/item?id=45948808
- mtlynch 11mo agoThe recordings don't prove anything about what Coinbase knew. I stand by my statement that the title is clickbait, as it's misleading on two fronts: - It's the email, not the call recording that proves what Coinbase knew, but "recordings prove" sounds more sensational - The email proves that Coinbase was aware of a sophisticated attack against a single user. You didn't have enough information to prove that there was a large scale leak of Coinbase customer data. There are sophisticated attacks against individual Coinbase users all the time due to the value of the accounts there.
- rs186 11mo agoYou apparently did not read the article. What you are looking for is right there.
- csomar 11mo agoThe article seems to be written by AI and goes into lots of details none of which is about how Coinbase knew about this.
- what-the-grump 11mo agoWe use Coinbase as an org, we were targeted in early Feb 2025. Caught by person handling the accounts who is paranoid enough to reach out to the org contact on the other side.
- fragmede 11mo agoMy Coinbase account got caught up in this and I'm so glad I used something like coinbase_jridi46@example.com as my email address with them because emails to that address can be treated as hostile in the wake of the breach. if I'd just used coinbase@example.com as my email address with them, I'd be fucked.
- immibis 11mo agoWhy couldn't you treat coinbase@example.com as hostile?
- fragmede 11mo agobecause it's guessable. If I sign up with Coinbase@example.com, real Coinbase will send me legitimate emails to that address, as well as scammers, so I have to dig into the headers to make sure the email is or isn't forged.
- immibis 11mo agoOnce the Coinbase database is leaked, that's going to be the case no matter what your address was.
- fragmede 11mo agoyes but I can be sure that coinbase_xyz@ is from evil while coinbase_abc@ (the new address that I changed it to, post-leak) is probably not from the hackers unless there was a second breach.
- happyopossum 11mo agoInteresting timeline, but nothing here proves, or even strongly indicates, that Counbase “knew about the breach” from this one report. Screenscraping malware is fairly common, and it’s not unreasonable for an analyst to look at a report like this and assume that the customer got popped instead of them. Customers get popped all the time, and have a tendency to blame the proximate corporation…
- jclarkcom 11mo agoThat's true, but in this case I got a response from the head of trust and safety after I sent the phone recording, email + email headers, saying "This report is super robust and gives us a lot to look into. We are investigating this scammer now."
- bpt3 11mo agoSo they looked into it and eventually determined the root cause and then took action. I don't know why you think acknowledgement of your report is concrete evidence that coinbase knew about their breach months before it was disclosed.
- anxman 11mo agoNot sure if the op is reading, but I also detected the same Coinbase hack around the same timeline. From what I can tell, literally everything was compromised because even their Discord channel's api keys were compromised and were finally reset around April or May. This means their central secrets manager was likely compromised too.
- 8organicbits 11mo agoThis doesn't seem like proof to me. The author got a phishing call and reported it. Coinbase likely has a deluge of phishing complaints, as criminals know their customers are vulnerable and target their customers regularly. The caller knowing account details is likely not unique in those complaints; customers accidentally leak those all the time. Some of the details the attacker knew could have been sourced from other data breaches. At the time of complaint, the company probably interpreted the report as yet another customer handling their own data poorly. Phishing is so pervasive that I wouldn't be surprised if the author was hit by a different attack.
- jclarkcom 11mo agoMy first thought was someone they tied a blockchain transaction to my name and then traced it backwards. But they also knew my ETH and BTC balances, and date the account was opened. You might be able to figure out the open date by looking at the blockchain but I could never determine how they would know balances for two unrelated cryptos without some kind of coinbase compromise.
- 8organicbits 11mo ago> but I could never determine how they would know balances for two unrelated cryptos There's tons of options. Malware, evil maid, shoulder surfing, email compromise, improper disposal of printouts, prior phishing attack, accidental disclosure.
- jclarkcom 11mo agotrue, I can’t rule those out entirely. I access via iPhone to limit attack surface area, the info was never printed, present in emails, or disclosed to 3rd parties
- smeej 11mo agoPlus, even though YOU obviously know better than to post a screenshot of your Coinbase balances on social media, (tens of?) thousands of their customers do not. With the analysis you provided of the email, your report definitely deserved to be taken seriously, but Coinbase could easily get dozens of emails reporting "compromise" of the personal details you provided that were obtained by good ol' fashioned OSINT and poor personal privacy practices.
- coolThingsFirst 11mo agoThe entire web3 scene is a clusterfuck filled with scammers. Recently i got hacked by web3 interview which is a common vector nowadays. They send github repo and as soon as you run it they send rejection after stealing tokens and installing keylogger. Pretty sophisticated and the frontend of the codebase looked polished as well.
- BergAndCo 11mo agoCoinbase froze everyone's accounts (to prevent a selloff) while cashing in on insider knowledge that they were going to start supporting Bitcoin Cash. Then as soon as they sold off and the market dipped, they unfroze everyone's account. But instead of being in jail, they just keep getting away with it.
- SilverElfin 11mo agoThis type of behavior is what the SEC was made to solve. But to be honest insider trading is behind MOST hedge funds and other firms with unusually gains. And politicians with big gains. It’s a huge problem that won’t get solved. Maybe taxing them is the only way.
- smeej 11mo agoYou (and everyone else ostensibly affected) have had like 7 years to sue over this if you could prove it.
- deleted 11mo ago[deleted]
- WatchDog 11mo agoSo the emails had proper DKIM signatures. Did the support agents have the ability to send arbitrary emails from commerce@coinbase.com? If not, how did the scammers send a properly signed email?
- dwohnitmok 11mo agoYeah what is going on here? What does this mean? > While both amazonses.com and coinbase.com DKIM checks passed, this is exactly how phishing works—attackers can configure Amazon SES to send "from" coinbase.com How does Amazon SES let you sign an email from a domain you don't control? Unless this means that somehow the scammer had access to DNS records for coinbase.com which indicates some really crazy compromise somewhere either of Coinbase or the DNS chain. I'm very confused.
- shakiness3383 11mo ago[dead]
- SilverElfin 11mo agoA related issue: often when there’s a security issue, the wrong people are blamed. In reality it is almost always the CEO’s fault for setting budgets or goals that are unrealistic and force everyone else to cut corners. Even other executives are a victim of this and are ultimately powerless.
- aantix 11mo agoOffshoring support for financial data should be illegal. Even if they find the inside individuals, how could anyone ever present a legal case?
- nalekberov 11mo agoIn July, 2025 I asked Coinbase to delete my account permanently, for which i had a bit of back-and-forth with customer service representatives, in the end I got an email confirming the deletion, then I tried to log into my account, I was still successful - they lied about it. Then I reached out to customer service several times - no answer. Then I contacted dedicated channel for privacy related questions with all proofs of mishandling - radio silence. It’s sad to see these companies mishandle our very personal data and get away with this.
- deleted 11mo ago[deleted]
- garlic-man 11mo agoThat wouldn't surprise me — A few years ago I reported a vulnerability through their bug bounty program that allowed "mandatory" 2FA for crypto withdrawals to be bypassed. They paid a pittance and permanently buried the report even though its release wouldn't have posed a risk anymore.
- garbagewoman 11mo agoYou do realize that chatgpt has a very recognizable and irritating style, right?
- rdos 11mo agoHello, I am interested in this topic. What would you say were the tale tale signs of AI generated text for you? Apart from: - excessive em-dashes - useless words, verbosity
- I_am_tiberius 11mo agoI remember Brian Armstrong saying something like "... and other data" when he communicated the data that was collected and then stolen. That tells a lot about him.
- LatteLazy 11mo agoI have a tradfi background but work in crypto with trading software. The whole industry (except deribit) is a shit show of barely working apis that aren’t reliable or accurate in any way. It’s completely routine to not be able to get an order status for minutes at a time. Or to get fills after an order has been rejected. Or a week after a cancel confirmation message. Coinbase is actually one of the worst offenders for this. Coinbase Prime, their supposed institutional grade offering especially so. So it doesn’t surprise me at all that the same issues are happening more widely. To be clear: deribit have always been efficient, accurate, reliable and generally excellent. If you must trade crypto, do it there so you’re Ops and Support people don’t have to suffer.
- sourgrapes42 11mo agoDid they ever email customers that there was a data breach? I started getting scam messages about my Coinbase account in the beginning of the year and only realized they had a breach because I happened to see their post twitter. I dont remember getting notified about it though.