BREAKING: Coinbase Pledges $20M Bounty Amid Cyberattack; Vows No Ransom Payment
By: the coin republic|2025/05/15 20:45:04
0
Share
Key Insights:Coinbase rejected a $20M ransom demand and offered a $20M bounty instead.Data breach affected less than 1% of Coinbase users, and no wallets were compromised.Bribed India-based agents leaked user data, fueling phishing scams.Coinbase faces a cyberattack where the Criminals demanded a $20 million ransom after bribing overseas customer support agents to steal user data. In response, the leading crypto exchange rejected the demand and instead offered a $20 million reward to anyone who helps authorities arrest and convict the attackers.The company confirmed that the stolen information affected fewer than 1% of its active monthly customers.Coinbase Data Theft Linked to Rogue Support AgentsAccording to Coinbase, the attackers offered bribes to overseas customer support agents, who then provided access to sensitive information. These agents worked in India and were immediately terminated when the breach was discovered. The exchange stated that the stolen data included names, addresses, phone numbers, government ID images, and partial financial information.However, the company clarified that the attackers did not gain access to passwords, 2FA codes, private keys, or wallets. Coinbase Prime accounts were also unaffected. The data breach enabled the criminals to launch targeted social engineering scams by impersonating Coinbase staff.“The insiders abused their access to our internal support tools,” said Philip Martin, Chief Security Officer of the exchange. “They gave attackers data that was later used in phishing attempts.”Social Engineering Used to Scam CustomersUsing the stolen information, attackers contacted the exchange customers while pretending to be legitimate employees. The purpose was to trick users into transferring their cryptocurrency to the attackers’ wallets. The firm has not disclosed how many users were successfully scammed but stated that affected customers would receive full reimbursement.The extortion attempt followed soon after the social engineering scams began. Criminals demanded $20 million in Bitcoin, threatening to leak the stolen data if their demand was not met. The leading exchange refused the ransom and instead decided to turn the situation around by offering the same amount as a bounty.“The knee-jerk reaction of everyone at Coinbase was ‘hell no,’” said Martin. “We do not negotiate with criminals.”Coinbase Strengthens Internal and External DefensesTo prevent similar breaches, the crypto exchange is making several internal changes. Coinbase is setting up a new customer support center in the U.S. while adding stronger security processes for risky activities. As part of this, users must confirm their identity for big withdrawals, and warnings about scams will be more frequent.In addition, the exchange has strengthened its threat-finding systems and tested for these kinds of attacks internally to find any flaws. More monitoring will be applied to accounts that are flagged, and some users could wait longer before withdrawing money.Those impacted by the breach received alerts from the firm, which says it will keep the public updated as it learns new information.Coinbase In Talks With Law Enforcement and Industry PartnersCoinbase has reported the breach to U.S. and international law enforcement. The company is also working with blockchain analytics firms to trace any stolen funds and identify the digital wallets linked to the criminals. Those addresses have now been flagged to prevent further use on major exchanges.The $20 million bounty will be paid to anyone who provides verified information that leads to the arrest and conviction of those responsible. Tipsters can contact the company through a dedicated security email, which has been shared in the company’s blog and official channels.“We are doing everything we can to support the authorities and bring these criminals to justice,” said Martin.Attempted Kidnapping in Paris Raises Security ConcernsIn a separate incident amid rising crypto insecurities, French media reported an attempted kidnapping involving the family of a crypto exchange executive in Paris. According to France 24, four masked men tried to abduct a woman and her child in broad daylight. The attackers beat the woman’s partner during the attempt and tried to force her into a white van.Authorities believe the motive may be connected to her relationship with a known figure in the crypto industry. The case is under investigation by local police. Surveillance footage has been collected, and the suspects remain at large. In addition, recently in a crypto event, some teens targeted an investor, leading to a heist of around $4M after kidnapping them at gunpoint.These events have raised concerns over both digital and physical security for those involved in cryptocurrency, as criminals continue to target individuals and institutions.The post BREAKING: Coinbase Pledges $20M Bounty Amid Cyberattack; Vows No Ransom Payment appeared first on The Coin Republic.
You may also like

Crypto VC, Mass Producing "Fake AI Projects"
Just changing the "loading..." in the product to "thinking..." can transform the company into an AI-adjacent startup.

MEET48 Launches IDOL Token Staking Program on BNB Chain: 90-Day Lockup with 40% APR
This IDOL Token Staking Program will start on March 19, 2026, with a staking cap of 15 million

AI Agent Economic Infrastructure Research Report (Part 1)
The existing infrastructure is hostile to the Agent economy. The Agent is already able to think and act autonomously at the "capability layer," but is still locked into infrastructure designed for humans at the "economic layer."

Gold Plunges 7% in Single-Day Crash, War Fails to Provide Haven|Rewire News Evening Report
Gold Declines for Sixth Consecutive Trading Day, Marking Longest Losing Streak Since Late 2024

The young stock god stages a melodramatic family drama: Huoliao Sen is emptied of 160 million USD in BTC by his partner
The wife secretly installed a hidden camera to capture the mnemonic phrase and directly transferred 2323 BTC.

With an annual income of hundreds of millions and aggressive buybacks, why is Pump.fun still being "shorted" by the market?
Pump.fun real daily average income of 1.25 million dollars vs original sin label + insider selling, who is the real culprit of the valuation discount?

An undisclosed loan reveals the ties between the U.S. Secretary of Commerce and Tether
The Lutnick family owes Tether another favor.

If the first batch of stablecoin licenses in Hong Kong is really only issued to banks, we might miss out on the next decade
This is not about the distribution of benefits from a few licenses, but rather about whether Hong Kong will be at the forefront, sailing smoothly in the digital economy over the next decade, or regrettably just standing on the shore sighing.

After the doubling, how much more "war dividend" can Circle claim?
A company whose product is designed to pursue price stability, why has it become the hottest trading target in the market as the world becomes more turbulent?

Guardian of Billions in Assets, Yet Unable to Sustain Itself: Tally Bows Out After Five Years
Tally chooses to proactively stop loss rather than stubbornly holding onto the token, making unrealistic promises.

Teenage Stock Market Wizard Caught in a Melodramatic Family Drama: Bed Partner Secretly Films Recovery Phrase, Steals $160 Million in BTC
The protagonist of the story is the well-known financial KOL in Hong Kong, Fire Lao Shen, who made a fortune in the early years through stock trading and Bitcoin.

How Bad Are the Midterm Elections for the Crypto Industry?
There is about an 85% chance that the Democratic Party will retain control of the House

An Undisclosed Loan, Tearing Open the Nexus Between the US Commerce Secretary and Tether
The Lutnick family owed Tether another favor.

Transaction Volume Skyrockets 60x: How Next-Gen Financial Infrastructure is Pricing Oil
Where Does the Price Come From When the Market is Closed

LALIGA Preview: Real Madrid Defends the Crown as Atlético Aims to Disrupt the Capital’s Order
[Match Info]
- Fixture: Real Madrid vs. Atlético de Madrid
- Kick-off: March 23, 04:00 AM (Beijing Time)
- Venue: Santiago Bernabéu

LALIGA Preview: Barcelona Eyes Continued Dominance While "The Lightning" Targets a Camp Nou Upset
[Match Info]
- Fixture: FC Barcelona vs. Rayo Vallecano
- Kick-off: March 22, 04:00 AM (Beijing Time)
- Venue: Estadi Olímpic Lluís Companys

What can we expect from the crypto market after the SEC and CFTC join forces?
Regulation is the starting point, and the bull market depends on the entry of traditional capital.

Hawkish Signal in Tightening Mode | Rewire News Brief
Maintaining the interest rate unchanged is within expectations; beyond expectations is the dot plot
Crypto VC, Mass Producing "Fake AI Projects"
Just changing the "loading..." in the product to "thinking..." can transform the company into an AI-adjacent startup.
MEET48 Launches IDOL Token Staking Program on BNB Chain: 90-Day Lockup with 40% APR
This IDOL Token Staking Program will start on March 19, 2026, with a staking cap of 15 million
AI Agent Economic Infrastructure Research Report (Part 1)
The existing infrastructure is hostile to the Agent economy. The Agent is already able to think and act autonomously at the "capability layer," but is still locked into infrastructure designed for humans at the "economic layer."
Gold Plunges 7% in Single-Day Crash, War Fails to Provide Haven|Rewire News Evening Report
Gold Declines for Sixth Consecutive Trading Day, Marking Longest Losing Streak Since Late 2024
The young stock god stages a melodramatic family drama: Huoliao Sen is emptied of 160 million USD in BTC by his partner
The wife secretly installed a hidden camera to capture the mnemonic phrase and directly transferred 2323 BTC.
With an annual income of hundreds of millions and aggressive buybacks, why is Pump.fun still being "shorted" by the market?
Pump.fun real daily average income of 1.25 million dollars vs original sin label + insider selling, who is the real culprit of the valuation discount?