en
Back to the list

Coinbase Refuses $20 Million Ransom, Launches Equal-Size Bounty After Insider Breach

source-logo  beincrypto.com 15 May 2025 08:20, UTC
image

Coinbase says cybercriminals bribed a small cadre of overseas support contractors to pull customer data from internal tools, hitting “less than 1 %” of its monthly active users.

The exchange disclosed that no passwords, private keys, or funds were exposed, and Coinbase Prime accounts were untouched.

Coinbase Attackers Demanded $20 Million Ransom

The attackers demanded a $20 million payment to keep the incident quiet. However, Coinbase said that it refused and redirected the sum into a $20 million reward fund for information leading to their arrest and conviction.

“We will pursue the harshest penalties possible and will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible for this attack,” Coinbase said.

Stolen records include names, addresses, phone numbers, masked Social Security digits, partial bank details, and account snapshots. The company vowed to make victims “whole” if they were lured by follow-up social-engineering scams. New withdrawal friction, extra ID checks, and real-time scam prompts are already live on flagged accounts.

The scheme began in late April when insiders siphoned high-balance account lists and hackers posed as Coinbase staff in phishing emails. Within days, security teams spotted anomalous queries, revoked access, and opened a criminal probe. Infrastructure systems and wallets “were never in danger,” the firm added.

Preventive measures include a new US support hub, stronger insider-threat detection, and nonstop red-team simulations. Fired insiders have been referred to the US and international law enforcement agencies. Coinbase also works with blockchain analytics firms to tag the attackers’ addresses and freeze stolen funds on compliant platforms, mirroring past takedown efforts.

beincrypto.com