Coinbase Rejects $20M Ransom, Pledges Same Bounty After Insider Leak Hits 1% of Users
By: crypto news|2025/05/15 23:17:05
0
Share
$20 million ransom demand flipped into a matching bounty when Coinbase disclosed this week that bribed overseas support staff leaked partial data on less than 1% of its users, reigniting fears of insider threats across crypto exchanges.Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on https://t.co/SidVn59JCV— Coinbase (@coinbase) May 15, 2025The crypto exchange says a group of rogue agents were bribed by cybercriminals to copy sensitive data, which was then used in a social engineering campaign to impersonate Coinbase and defraud users.Although no customer funds, passwords, or private keys were accessed, the attackers obtained partial personal information, including names, contact details, masked Social Security and bank account numbers, and in some cases, images of government-issued IDs. Coinbase emphasized that Coinbase Prime users were not impacted and that no direct access to hot or cold wallets was ever at risk.“We’re committed to full transparency,” Coinbase said in a public statement, “and instead of giving in to the $20 million ransom demand, we’re establishing a $20 million reward fund to bring the criminals to justice.”The Anatomy of the AttackAccording to Coinbase, the breach occurred when criminals targeted overseas support agents and offered them financial incentives to participate in the scheme. A small number of insiders accepted the bribes and abused their privileged access to copy data stored in customer support tools.The attackers then attempted to extort the company, threatening to release the stolen information unless Coinbase paid a $20 million ransom. The exchange declined the demand, opting instead to notify affected users and bolster its internal and external security infrastructure.The stolen data included transaction histories, account balances, and some internal documentation accessible to support agents. However, the attackers did not obtain passwords, two-factor authentication codes, private keys, or access to any wallets, thus preventing direct theft of funds.Coinbase’s Response and Customer SupportIn response to the breach, Coinbase has pledged to reimburse retail customers who were tricked into sending funds to scammers through social engineering tactics. These reimbursements will be made after a thorough review process. Affected accounts are now subject to increased withdrawal security protocols, including additional ID checks and scam-awareness prompts.Coinbase said it is also taking steps to reinforce its global support operations. For example, a new customer support hub is being established in the United States, and enhanced insider-threat detection systems are being rolled out across all service locations.The company has intensified internal simulations to stress-test its security infrastructure and isolate potential vulnerabilities.All impacted users have received direct communication, and Coinbase is working closely with law enforcement agencies both in the U.S. and internationally. The rogue employees involved were immediately terminated and referred for criminal prosecution.A Call for AccountabilityRather than succumbing to extortion, Coinbase said it is offering a $20 million reward for information that leads to the arrest and conviction of those responsible for the breach. Anyone with credible information is encouraged to contact the company at security@coinbase.com. In parallel, Coinbase and its partners have tagged crypto wallet addresses associated with the attackers to aid in asset recovery.Coinbase is also reminding users to stay vigilant against scams and impersonators. Customers are urged to never share passwords or 2FA codes, and to lock their accounts immediately if something seems suspicious.“Trust is foundational to crypto adoption,” Coinbase said in its closing statement. “We’re sorry for the concern this incident caused and remain committed to transparency and protecting our users at every step.”Huge Blow for the CompanyCommenting on the cyber attack on Coinbase, Nick Jones, founder and CEO at Zumo, said: “Unfortunately, as our nascent industry grows rapidly, it draws the eye of bad actors, who are becoming increasingly sophisticated in the scope of their attacks and harnessing new AI tools and techniques to bypass fraud prevention measures.”“This is understandably a huge blow for a company that has had a pivotal few weeks, announcing the acquisition of Deribit in the digital market’s largest deal to date, and then joining the S&P 500.”“This attack underlines the critical importance of robust cybersecurity measures. The European Union (EU) introduced its Digital Operational Resilience Act (DORA) earlier this year with an emphasis on financial institutions ensuring the resilience of their supply chain, promoting better data hygiene, and sharing usable insights on attacks they have experienced to strengthen the industry’s perimeter. This seems particularly pertinent as it emerges that the hack occurred when attackers bribed overseas support staff,” Jones added.The post Coinbase Rejects $20M Ransom, Pledges Same Bounty After Insider Leak Hits 1% of Users appeared first on Cryptonews.
You may also like

Aster Chain officially launches: defining a new era of on-chain privacy and transparency
The privacy-focused trading ecosystem Aster, supported by YZi Labs, announced today that the Aster Chain mainnet is officially launched.

Stargate Debut Illustrated: The 1.4 Trillion Computing Power Empire Dream, Awakened
One Year Plus, Zero Employees, Zero Code

A Billion-Dollar Life Buy Threat Triggered by an Iranian Missile
One Word Change by a Reporter Can Make Gambler Win Millions

BlackRock Launches ETHB: Ethereum ETF Enters 'Interest-Bearing Age'
The BlackRock ETHB is not the first Ethereum ETF in the United States, but it is taking the most standard route.

Nvidia Starts Putting Chips in the Road | Rewire News Evening Update
Huang Renxun said this is the "ChatGPT Moment of Autonomous Driving"

RootData: February 2026 Cryptocurrency Exchange Transparency Research Report
This month's cumulative spot trading volume on cryptocurrency exchanges has decreased slightly by 4.7% compared to January, which is the result of multiple factors including market conditions, the macro environment, and the Spring Festival holiday in Chinese-speaking regions.

「One and Done SEA」, so OpenSea chooses to wait a little longer
It's already Q1 2026, and we're still waiting for OpenSea to launch its token.

Ray Dalio: The Resolution of the US-Iran Conflict Is In the Strait of Hormuz
In war, the ability to endure pain is often more important than the ability to inflict pain.

In just 70 days, Polymarket easily raked in tens of millions in fees
The money printer is running, and the future ceiling only depends on two main variables.

Matrixdock is launching the Silver Token XAGm, built on the FRS standard as an on-chain silver-backed asset.
In the future, Matrixdock will continue to expand to include more high-quality real-world assets, driving the development of a more transparent and robust on-chain reserve asset system.

a16z: The Hardest Enterprise Software, and the Greatest Opportunity in AI
The world will continue to run on SAP, but AI will reshape it

Polymarket Market-Making Bible: Pricing Spread Formula
This article presents a comprehensive market-making pricing framework that will elevate you from "guesstimate pricing spread" to "formula-based pricing spread."

Ray Dalio: If the United States loses Hormuz, it will lose more than just a war
In war, who can endure pain better is often more important than who can inflict pain better.
How to Earn Up to 40% Rebates on Crypto Futures Trading (WEEX Trade to Earn IV Guide)
WEEX Trade to Earn IV lets traders earn up to 40% fee rebates in real time through a tiered miner system tied to trading activity. With additional boosts from referrals, it offers a more reliable alternative to airdrops as the crypto market gains momentum.

NVIDIA Plays Trillion-Dollar Chess Game | Rewire News Morning Edition
DGX Station, a desktop workstation capable of running trillion-parameter models

Real-time Update | NVIDIA GTC 2026 Conference Highlights Galore
The most anticipated annual event in the AI field, NVIDIA's GTC 2026 Conference, kicked off today in San Jose, California, USA.

People Behind Pokémon Go: Started with CIA's Money, Now Mapping the World for the Military AI
The security of data depends on whose hands it ends up in.

Huang Renxun GTC Speech Full Text: By 2027, Market Demand Will Exceed $1 Trillion; Everyone Should Develop an OpenClaw Strategy
The underlying business logic driving future growth will be the "Tokenomics of a Platform Factory."
Aster Chain officially launches: defining a new era of on-chain privacy and transparency
The privacy-focused trading ecosystem Aster, supported by YZi Labs, announced today that the Aster Chain mainnet is officially launched.
Stargate Debut Illustrated: The 1.4 Trillion Computing Power Empire Dream, Awakened
One Year Plus, Zero Employees, Zero Code
A Billion-Dollar Life Buy Threat Triggered by an Iranian Missile
One Word Change by a Reporter Can Make Gambler Win Millions
BlackRock Launches ETHB: Ethereum ETF Enters 'Interest-Bearing Age'
The BlackRock ETHB is not the first Ethereum ETF in the United States, but it is taking the most standard route.
Nvidia Starts Putting Chips in the Road | Rewire News Evening Update
Huang Renxun said this is the "ChatGPT Moment of Autonomous Driving"
RootData: February 2026 Cryptocurrency Exchange Transparency Research Report
This month's cumulative spot trading volume on cryptocurrency exchanges has decreased slightly by 4.7% compared to January, which is the result of multiple factors including market conditions, the macro environment, and the Spring Festival holiday in Chinese-speaking regions.