Coinbase support-contractor data breach and downstream thefts hack — December 2024
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | May 15, 2025 |
| Target type | Centralised exchange |
| Loss | $307,000,000Published estimates range $180,000,000 to $400,000,000Price at time of incident |
| Method | Insider actionCriminals paid overseas outsourced customer-support agents to copy customer records out of Coinbase's internal support tools. The stolen identity and balance data was then used to place convincing impersonation calls that talked customers into sending crypto to attacker-controlled wallets. Coinbase's own systems, wallets and keys were not breached. |
| Chains | Multiple chains |
| Attributed to | Unidentified extortionist(s) who paid overseas Coinbase support contractors for customer recordsAlleged |
| Outcome | Users reimbursed |
What happened
Criminals paid overseas customer-support contractors working for Coinbase to copy customer records out of internal systems. In a Form 8-K filed on 15 May 2025 Coinbase said the threat actor obtained the data by paying multiple contractors or employees in support roles outside the United States. The data included names, addresses, phone numbers, email addresses, the last four digits of Social Security numbers, masked bank account details, government ID images, account balances and transaction history. Passwords, private keys and customer funds were not directly accessed, and Coinbase said its hot and cold wallets were untouched.
Coinbase received an extortion email on 11 May 2025 demanding $20 million, refused to pay, referred the matter to the Justice Department and offered a $20 million reward instead. Its notification to the Maine Attorney General put the number of affected customers at 69,461 and dated the start of the unauthorised access to 26 December 2024. A class-action filing reported by Fortune places the first thefts by a contractor at an Indore, India service centre several months earlier and says participants were paid about $200 per screenshot.
The money was taken downstream: callers armed with the stolen data impersonated Coinbase staff convincingly enough to talk customers into sending crypto to attacker wallets. No independently verified total of customer crypto losses has been published. The dollar figure recorded here is Coinbase's own cost accounting, not a measured sum of stolen coins. The 8-K estimated $180 million to $400 million in remediation and voluntary customer reimbursement; Coinbase's second-quarter 2025 results recorded $307 million.
Law enforcement
Coinbase refused the $20 million extortion demand, referred the matter to the US Department of Justice and offered a $20 million reward for information leading to arrests and convictions. Indian police arrested a former outsourced support agent in connection with the insider data theft. Coinbase ended its relationship with the outsourcing provider and said it was building a US-based support hub with additional insider-threat monitoring.
Sources
- US Securities and Exchange Commission (Coinbase Global Form 8-K)Primary · retrieved 2026-08-01
- FortuneSecondary · retrieved 2026-08-01
- SecurityWeekSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://www.sec.gov/Archives/edgar/data/1679788/000167978825000094/coin-20250514.htm
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Coinbase support-contractor data breach and downstream thefts hack — December 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/coinbase-support-contractor-data-breachhttps://itokenly.com/hacks/coinbase-support-contractor-data-breachPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.