Coinbase disclosed a data breach that occurred between May and June 2025, resulting in the theft of customer information. The incident affected 69,461 individuals and prompted the company to reject a $20M ransom demand.
Data Breach Incident
Coinbase reported a significant data breach caused by bribed overseas agents who gained access to customer PII. The breach affected 69,461 individuals and included theft of data such as bank details and government IDs. "While the breach involved the theft of sensitive customer information, I want to reassure our users that no passwords, private keys, or seed phrases were compromised," said Emilie Choi, President and COO of Coinbase.
Coinbase's Response to the Incident
In response to this incident, Coinbase took decisive measures to enhance its security. The company plans to open a new support hub in the U.S. and increase its fraud detection capabilities to prevent similar situations in the future.
Financial Consequences and Future Steps
The financial implications of this breach can be substantial, with remediation costs potentially reaching $400 million. Coinbase has also set up a $20 million reward fund to assist in the prosecution of those responsible. The refusal to pay the ransom emphasizes the company's long-term focus on enhancing user data security.
Coinbase's decision to refuse the ransom and the measures taken to improve security highlight the importance of data protection in the cryptocurrency industry and the need for increased vigilance among users.