Coinbase security incident

The retained public source describes the Coinbase incident as Insider threat: bribed overseas contracted customer-support agents exported customer data. Other material details remain unresolved.

Last modified

Summary

  • Environment: Cryptocurrency exchange
  • Operational impact: The reviewed source does not establish a precise operational or data impact
  • Financial impact: Est. $180-400M remediation/reimbursement cost
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In May 2025, Coinbase experienced an incident in its cryptocurrency exchange environment. The retained source describes the attack path as follows: Insider threat: bribed overseas contracted customer-support agents exported customer data. [1]

Impact

  • The reviewed source does not establish a precise affected-person count, data scope, or operational consequence.
  • Documented financial consequence: Est. $180-400M remediation/reimbursement cost. [1]

Threat Group & Attack Vector

The retained source describes the attack path as follows: Insider threat: bribed overseas contracted customer-support agents exported customer data. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The retained source reports coordination with law enforcement as part of the incident response. [1]

This account is bounded to Coinbase Form 8-K. Details absent from that evidence are left unresolved rather than inferred. [1]