Coinbase Rejects $20M Ransom, Pledges Same Bounty After Insider Leak Hits 1% of Users
By: crypto news|2025/05/15 23:17:05
0
Share
$20 million ransom demand flipped into a matching bounty when Coinbase disclosed this week that bribed overseas support staff leaked partial data on less than 1% of its users, reigniting fears of insider threats across crypto exchanges.Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on https://t.co/SidVn59JCV— Coinbase (@coinbase) May 15, 2025The crypto exchange says a group of rogue agents were bribed by cybercriminals to copy sensitive data, which was then used in a social engineering campaign to impersonate Coinbase and defraud users.Although no customer funds, passwords, or private keys were accessed, the attackers obtained partial personal information, including names, contact details, masked Social Security and bank account numbers, and in some cases, images of government-issued IDs. Coinbase emphasized that Coinbase Prime users were not impacted and that no direct access to hot or cold wallets was ever at risk.“We’re committed to full transparency,” Coinbase said in a public statement, “and instead of giving in to the $20 million ransom demand, we’re establishing a $20 million reward fund to bring the criminals to justice.”The Anatomy of the AttackAccording to Coinbase, the breach occurred when criminals targeted overseas support agents and offered them financial incentives to participate in the scheme. A small number of insiders accepted the bribes and abused their privileged access to copy data stored in customer support tools.The attackers then attempted to extort the company, threatening to release the stolen information unless Coinbase paid a $20 million ransom. The exchange declined the demand, opting instead to notify affected users and bolster its internal and external security infrastructure.The stolen data included transaction histories, account balances, and some internal documentation accessible to support agents. However, the attackers did not obtain passwords, two-factor authentication codes, private keys, or access to any wallets, thus preventing direct theft of funds.Coinbase’s Response and Customer SupportIn response to the breach, Coinbase has pledged to reimburse retail customers who were tricked into sending funds to scammers through social engineering tactics. These reimbursements will be made after a thorough review process. Affected accounts are now subject to increased withdrawal security protocols, including additional ID checks and scam-awareness prompts.Coinbase said it is also taking steps to reinforce its global support operations. For example, a new customer support hub is being established in the United States, and enhanced insider-threat detection systems are being rolled out across all service locations.The company has intensified internal simulations to stress-test its security infrastructure and isolate potential vulnerabilities.All impacted users have received direct communication, and Coinbase is working closely with law enforcement agencies both in the U.S. and internationally. The rogue employees involved were immediately terminated and referred for criminal prosecution.A Call for AccountabilityRather than succumbing to extortion, Coinbase said it is offering a $20 million reward for information that leads to the arrest and conviction of those responsible for the breach. Anyone with credible information is encouraged to contact the company at security@coinbase.com. In parallel, Coinbase and its partners have tagged crypto wallet addresses associated with the attackers to aid in asset recovery.Coinbase is also reminding users to stay vigilant against scams and impersonators. Customers are urged to never share passwords or 2FA codes, and to lock their accounts immediately if something seems suspicious.“Trust is foundational to crypto adoption,” Coinbase said in its closing statement. “We’re sorry for the concern this incident caused and remain committed to transparency and protecting our users at every step.”Huge Blow for the CompanyCommenting on the cyber attack on Coinbase, Nick Jones, founder and CEO at Zumo, said: “Unfortunately, as our nascent industry grows rapidly, it draws the eye of bad actors, who are becoming increasingly sophisticated in the scope of their attacks and harnessing new AI tools and techniques to bypass fraud prevention measures.”“This is understandably a huge blow for a company that has had a pivotal few weeks, announcing the acquisition of Deribit in the digital market’s largest deal to date, and then joining the S&P 500.”“This attack underlines the critical importance of robust cybersecurity measures. The European Union (EU) introduced its Digital Operational Resilience Act (DORA) earlier this year with an emphasis on financial institutions ensuring the resilience of their supply chain, promoting better data hygiene, and sharing usable insights on attacks they have experienced to strengthen the industry’s perimeter. This seems particularly pertinent as it emerges that the hack occurred when attackers bribed overseas support staff,” Jones added.The post Coinbase Rejects $20M Ransom, Pledges Same Bounty After Insider Leak Hits 1% of Users appeared first on Cryptonews.
You may also like

Key Market Information Discrepancy on March 13th - A Must-See! | Alpha Morning Report
1. Top News: Latest Developments in US-Iran Conflict, Son of Soleimani Vows Revenge, US Navy Plans to Escort Ships in the Strait of Hormuz
2. Token Unlock: $HTM

On-Chain Options Explosion.ActionEvent
Options are becoming the new anchor in the cryptocurrency market.

《Time》 Magazine Names Anthropic as the World's Most Disruptive Company
The most AI-wary company has created the most dangerous AI

Predictions market gains mainstream traction in the US, Canada, Claude launches Chart Interaction feature, What's the English community talking about today?
What Did Foreigners Care About Most in the Last 24 Hours?

500 Million Dollars, 12 Seconds to Zero: How an Aave Transaction Fed Ethereum's "Dark Forest" Food Chain
Spend $154,000 to buy AAVE at market price of only $111

AI Agent needs Crypto, not Crypto needs AI
It is not Crypto that needs AI to survive, but rather AI Agents that need Crypto to be implemented: when AI truly shifts from "thinking" to "executing," it must seek the boundaries of authority and funding within the programmable primitives of Crypto.

Stablecoins are breaking away from cryptocurrency, becoming the next generation of infrastructure for global payments
The use of stablecoins is shifting from facilitating low-cost cross-border remittances to supporting general commercial activities and inter-company vendor payments.

Web3 teams should stop wasting marketing budgets on the X platform
The announcements from the project party are still very important, but they should no longer be the starting point of promotional activities; instead, they should be the endpoint.

Strive buys Strategy stocks, and Bitcoin treasury companies start nesting each other
When everyone's bets are placed on the same table, the difference between "structured financing" and "concentrated gambling" may just be a few more arrows drawn on the PPT.

Strive to buy Strategy stock, Bitcoin Treasury company starts nesting dolls with each other
Bitcoin hodlers are starting to nested be in each other.

Key Market Intel on March 12th, how much did you miss out on?
1. On-chain Funds: $29.7M inflow to Hyperliquid today; $30.9M outflow from Base
2. Biggest Gainers/Losers: $DRV, $LYN
3. Top News: US plans to release 172M barrels of oil to curb prices, on-chain pre-market crude oil gains narrow by 4%

The new center of Crypto
But the market is constantly evolving. By 2026, companies that can adapt to the new environment will survive, while those that continue to rely on the old script may face the fate of elimination.

Former Coinbase CPO's lengthy article: I have regrets, but I still firmly believe in Crypto
People often fantasize that wealth comes from catching every new wave. Sometimes this is true. But more often, wealth comes from riding a real wave and not blindly paddling away every time the water splashes around.

Hormuz Strait Triggers Oil War, Will the Fed Blink with a Rate Cut in June?
Polymarket data shows that the current market is betting a 64% probability of an interest rate cut in June this year, with the probability rising to 81% for September.

After Law Enforcement in the US and the UK Seized Cryptocurrency, ‘Asset Return’ Never Really Happened
The digital assets that should have been returned to the victims have quietly flowed into government treasuries, strategic reserve funds, and law enforcement agencies' operational budgets.

Why Does Everyone Hate AI?
AI and Silicon Valley's PR Crisis

Kyle Samani Returns to Crypto? Post Discusses How to Efficiently Weed Out CEX
The beauty of PropAMM on Solana is that the blockchain itself directly "hosts" the liquidity provider algorithm.

What are the chances of a 5X MOONSHOT for HYPE?
Hyperliquid is building a new growth logic
Key Market Information Discrepancy on March 13th - A Must-See! | Alpha Morning Report
1. Top News: Latest Developments in US-Iran Conflict, Son of Soleimani Vows Revenge, US Navy Plans to Escort Ships in the Strait of Hormuz
2. Token Unlock: $HTM
On-Chain Options Explosion.ActionEvent
Options are becoming the new anchor in the cryptocurrency market.
《Time》 Magazine Names Anthropic as the World's Most Disruptive Company
The most AI-wary company has created the most dangerous AI
Predictions market gains mainstream traction in the US, Canada, Claude launches Chart Interaction feature, What's the English community talking about today?
What Did Foreigners Care About Most in the Last 24 Hours?
500 Million Dollars, 12 Seconds to Zero: How an Aave Transaction Fed Ethereum's "Dark Forest" Food Chain
Spend $154,000 to buy AAVE at market price of only $111
AI Agent needs Crypto, not Crypto needs AI
It is not Crypto that needs AI to survive, but rather AI Agents that need Crypto to be implemented: when AI truly shifts from "thinking" to "executing," it must seek the boundaries of authority and funding within the programmable primitives of Crypto.