Coinbase disclosed in a May 14, 2025 Form 8‑K filing with the U.S. Securities and Exchange Commission that it expects to incur between $180 million and $400 million in total costs related to a recent data breach and associated customer remediation. The incident, detailed further in the filing and in a May 15, 2025 Coinbase blog post, involved an extortion attempt following unauthorized access to customer data through bribed overseas customer support contractors, affecting roughly 69,000–70,000 users, or less than 1% of its monthly transacting users. The compromised data included personal information such as names, addresses, contact details, partial Social Security numbers, masked bank details, images of government IDs, and account/transaction data, but not passwords, private keys, or direct wallet access. According to summaries of the SEC filing by law firms tracking the case, Coinbase’s estimated $180–$400 million exposure encompasses reimbursements and remediation for customers who were tricked into sending funds to scammers leveraging the stolen data, as well as broader incident‑response costs. Coinbase refused a $20 million ransom demand from the attackers, instead creating a separate $20 million reward fund for information leading to their arrest, and committed to voluntarily reimbursing retail customers who lost funds as a direct result of the social‑engineering scams tied to the breach. The scale of the projected payout and ongoing class‑action litigation underscore the legal, financial, and reputational stakes for one of the largest U.S. cryptocurrency exchanges, and highlight how insider‑enabled data leaks and social‑engineering attacks remain a critical systemic risk in the crypto trading ecosystem.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Coinbase

Comments