Skip to main content
Breach Signal

Breach report

Crypto

Coinbase

Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom

Criminals paid overseas support contractors to copy Coinbase customer records, including ID images and account balances, then demanded $20 million; Coinbase refused, offered a matching bounty and braced for up to $400 million in costs.

Reported by CNBC

Records exposed

69.5K

69,461 customers

Scale vs. largest on file

When
2025 (insider access began December 2024)
How they got in
Insider bribery of outsourced customer support agents
Sector
Crypto

On May 15, 2025, Coinbase, the largest U.S. cryptocurrency exchange, disclosed that criminals had bribed a small number of customer support agents to steal customer data. The company revealed the breach in a regulatory filing after receiving an email on May 11 from an unknown actor demanding $20 million in exchange for not publishing the information. Coinbase said it refused to pay.

The insiders were contractors and employees working in customer support roles outside the United States, many of them based in India through an outsourcing arrangement. According to Coinbase, the attackers offered cash to persuade them to copy information from internal support tools. Coinbase said it had detected some of the activity earlier and fired the personnel involved, but only understood the full scope once the ransom demand arrived. Later filings indicated the unauthorized access dated back to late December 2024.

A filing with state regulators put the number of affected customers at 69,461, which Coinbase described as less than 1 percent of its monthly transacting users. The stolen records included names, addresses, phone numbers and emails, masked Social Security and bank account numbers, images of government IDs such as driver's licenses and passports, account balances and transaction history. Coinbase stressed that no passwords, private keys or two-factor codes were taken, and that the attackers could not move funds directly.

The real danger was follow-on fraud. With detailed knowledge of who held crypto and how much, criminals could pose as Coinbase staff and persuade victims to move assets into wallets they controlled. Coinbase said it would reimburse customers who were tricked into sending funds as a result, and estimated total costs of roughly $180 million to $400 million. Instead of paying the ransom, it created a $20 million reward fund for information leading to the arrest and conviction of those responsible. Shareholder and customer lawsuits followed the disclosure.

The breach highlighted a growing threat to exchanges and fintech firms: attackers bypassing technical defenses by buying access from low-paid, outsourced staff. It also underscored why crypto-related data is uniquely sensitive, since exposed balances and home addresses can invite not only phishing but physical threats against holders.

More from the wire

More in Crypto.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.