What happened
Coinbase disclosed on May 15, 2025 that criminals had bribed a small group of overseas customer support agents, based in India, to pull customer data from its support systems. The data was used to run social engineering attacks against Coinbase customers. The attackers demanded $20 million on May 11 to suppress the breach; Coinbase refused and posted a $20 million reward instead. The breach originated on December 26, 2024, and a Maine Attorney General filing put the affected total at 69,461 people.
How the deception worked
The attackers recruited rather than intruded, paying overseas support agents who already had legitimate access to customer records. Those agents pulled names, addresses, phone numbers, email addresses, masked Social Security digits, masked bank account numbers, government ID images, and account balance and transaction snapshots. Passwords, seed phrases, 2FA codes and private keys were never exposed, so the data alone could not move funds; its value was in making the second stage convincing. Armed with a customer's real balance and transaction history, callers impersonating Coinbase support could establish credibility instantly and talk victims into sending crypto to attacker wallets. Coinbase began seeing unusual support-representative activity in January 2025 and fired the implicated insiders.
AI involvement · No AI reported
No AI involvement was reported in Coinbase's disclosure.
The control that would have caught it· our reading, not a claim from the sources
Support tooling should mask or withhold balance and transaction data by default, with per-record access justification and volume alerting, so a bribed agent cannot assemble the dossier that makes downstream impersonation work.
Sources (3)
- Protecting Our Customers - Standing Up to ExtortionistsCoinbase·coinbase.comOpen ↗
- Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt FailsThe Hacker News·thehackernews.comOpen ↗
- Coinbase confirms insiders handed over data of 70K usersThe Register·theregister.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.