Coinbase revealed its Q2 earnings took a $307 million hit from a major data breach, as spot trading volumes fell and revenue declined; the breach involved cybercriminals bribing offshore customer service staff to access user data, with total losses initially estimated up to $400 million.

Coinbase revealed its Q2 earnings took a $307 million hit from a major data breach, as spot trading volumes fell and revenue declined; the breach involved cybercriminals bribing offshore customer service staff to access user data, with total losses initially estimated up to $400 million.
The Block
Revision history

8 recorded changes

Want your article here?

Promote with Leviathan News

Coinbase disclosed in its second-quarter 2025 earnings that a late‑2024/early‑2025 data theft incident tied to bribed offshore support staff resulted in an estimated $307 million impact on its Q2 results, within a broader projected loss range of $180 million to $400 million tied to the breach. The company said cybercriminals paid multiple non‑U.S. contractors and employees in support roles to improperly access internal systems and harvest sensitive customer information, including names, addresses, phone numbers, emails, partial Social Security numbers, masked bank account details, images of government IDs, and limited account data, but not passwords or private keys. Coinbase received an email from a threat actor on May 11, 2025 claiming to hold this data and demanding a $20 million ransom, which the company refused to pay, instead cooperating with law enforcement and offering a matching $20 million reward for information leading to the attackers’ arrest. The incident affected roughly 70,000 customers globally—less than 1% of Coinbase’s monthly transacting users—but has had outsized financial, legal, and reputational consequences. According to Coinbase’s SEC filing, the bulk of the projected cost stems from remediation efforts and voluntary reimbursements to customers whose funds were stolen after scammers used the leaked data to impersonate Coinbase support and socially engineer victims into sending crypto. The episode has intensified scrutiny of Coinbase’s reliance on offshore outsourcing partners such as TaskUs, since the attack exploited insider access rather than a direct compromise of Coinbase’s core trading or custody systems. In response, Coinbase says it has cut ties with the involved overseas agents, tightened monitoring and access controls, expanded U.S.-based support operations, notified affected users, and provided credit monitoring and additional security checks on high‑risk accounts. The breach underscores growing regulatory and investor focus on insider threats and vendor risk management in large crypto platforms, at a time when Coinbase is also contending with declining spot trading volumes and revenue pressure.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Revenue

Comments