Skip to main content
Network Now
BTC Price
Network Hashrate
Difficulty
Next Halving
Back to Blog

The Coinbase data breach: What was stolen and how

July 1, 20254 min read
the-coinbase-data-breach-what-was-stolen-and-how

TLDR;

.

  • Indian customer service agents gave malicious actors sensitive Coinbase users

.

  • The malicious actors demanded $20 million as ransom not to release or sell the data to the highest bidder

.

  • Coinbase terminated the agents and promised to compensate affected users in case they lose funds due to the stolen data

.

Apart from directly compromising the security of crypto accounts and stealing crypto, malicious actors are devising new methods. Some of the methods include hacking social media accounts of prominent figures or crypto platforms, promoting malicious links, and connecting with crypto platform employees to obtain user data. The latter befell leading cryptocurrency exchange Coinbase, resulting in malicious actors gaining access to data belonging to over 69,000 Coinbase users.

.

Although 69,000 users are a small fraction of Coinbase�s over 100 million users and over 10 million monthly active users, how did bad actors lay their hands on the data, what kind of information was contained in the stolen data, and what did Coinbase do about it? Below, we answer all these questions.

What was stolen in the Coinbase data breach

The stolen user data included:

 .

  • Full names

.

  • Phone numbers

.

  • Home addresses

.

  • Email addresses

.

  • Sections of Social Security numbers (SSNs)

.

  • Sections of bank account numbers

.

  • Bank account-specific information

.

  • Scanned copies of passports and driver�s licenses

.

  • Transaction history on the exchange

.

  • Crypto account balances

What was not stolen in the Coinbase data breach

.

  • Any other cryptocurrency

.

  • Passwords

.

  • Private keys to users� wallets

How did malicious actors access Coinbase users� records?

The human element. Bad actors paid India-based Coinbase customer service agents. The agents were employees of TaskUs, an American outsourcing company operating under contract with the exchange. The employees transferred the data they had access to the cybercriminals. 

.

Apart from user data, the agents also leaked other documents detailing the exchange�s account management and customer service systems. TaskUs notified Coinbase about the incident

.

In May 2025, the malicious actors reached out to Coinbase via email, confirming that they hold critical information about users and the exchange�s internal processes. They then demanded $20 million as ransom.

Coinbase notifies law enforcement agencies

Instead of paying the ransom, Coinbase involved law enforcement agencies and offered the $20 million as a payout for anyone with credible and actionable information about the cybercriminals. Coinbase filed a formal report with the Maine Attorney General's office. In the filing, the exchange officially admitted that a total of 69,461 persons were affected in the Coinbase data breach. Out of this, 217 persons were Maine residents.

.

The exchange also revealed that the breach occurred on December 26, 2024, but was discovered on May 11, 2025, and cited �insider wrongdoing� as the cause of the incident.

Was the Coinbase data breach really discovered in May 2025?

Although Coinbase told Maine Attorney General that it discovered the data breach in May 2025, reports shows that the exchange may have known about the incident a few days after breach in January 2025. According to a TaskUs spokesperson, the company immediately reported the employees� behavior to its client, Coinbase.

.

The spokesperson noted that the employees involved are likely part of a �much broader, coordinated criminal campaign against this client that also impacted a number of other providers servicing .�

.

Blockchain sleuth ZachXBT has also been warning against social engineering scams targeting Coinbase users, a sign that the threat actors may have obtained the data much earlier than was reported. ZachXBT disclosed that scammers stole more than $60 million from Coinbase users between December 2024 and January 2025. According to him, the losses are likley much higher noting that Coinbase users lose roughly $300 million yearly to these types of scams.

The Coinbase data breach: How did the exchange respond?

Apart from notifying affected users and cutting ties with TaskUs employees involved in the incident, the exchange promised to reimburse affected users in case they lose funds. Coinbase told the Maine Attorney General that it will also offer:

�All impacted individuals one year of free credit monitoring and identity protection services provided by IDX. The services include credit monitoring, a $1,000,000 insurance reimbursement policy and identity restoration, and dark web monitoring to identify if any information is made available through illegal online forums.�

Coinbase estimated that it�ll use up to $400 million to reimburse affected users

Conclusion

In this digital age, personal information is king. Although the threat actors in the Coinbase data breach didn�t directly steal crypto from the exchange, the users� information they hold can get them the same amount, or even more, of money compared to directly compromising the users' accounts. The stolen information exposes the victims to social engineering scams, identity theft, and phishing attacks. With social engineering tactics, however, the victim willingly gives hackers or scammers access to their crypto wealth.

Share

Stay Updated

Fresh guides and market signal in your inbox. No spam, unsubscribe anytime.

Comments (0)

No comments yet — be the first to share your thoughts!

Log in to leave a comment.

The Coinbase data breach: What was stolen and how | Endless Mining