Coinbase warns of up to $400 million hit from cyberattack

Hackers had paid multiple contractors and employees working in support roles outside the US to collect information. (AP)
Short Url
Updated 16 May 2025
Follow

Coinbase warns of up to $400 million hit from cyberattack

  • Hackers bribed staff overseas
  • Company rejected $20 million ransom demand

Coinbase forecast a hit of $180 million to $400 million from a cyberattack that breached account data of a “small subset” of its customers, the crypto exchange said in a regulatory filing on Thursday.
The company received an email from an unknown threat actor on May 11, claiming to have information about certain customer accounts as well as internal documents.
While some data — including names, addresses and emails — was stolen, the hackers did not get access to login credentials or passwords, Coinbase said. It would, however, reimburse customers who were tricked into sending funds to the attackers.
Hackers had paid multiple contractors and employees working in support roles outside the US to collect information. The company had fired those involved, it said.
Separately, the US Securities and Exchange Commission had begun scrutinizing whether Coinbase had misstated its user figures, two sources familiar with the matter told Reuters.
The agency had also been interested in whether any inaccurate user data could indicate the company had inadequate know-your-customer compliance that is required of firms registered with the SEC, the sources said.
A Coinbase spokesperson denied the SEC was probing the company’s compliance with know-your-customer and Bank Secrecy Act rules.
Another source familiar with the matter said that the SEC did not directly ask questions about such compliance and that it would not be a relevant topic since the SEC
dropped a separate case
against Coinbase alleging the firm failed to register with the SEC.
The inquiry into Coinbase’s “verified user” metric had continued even after the SEC abandoned its other lawsuit, the source said. The New York Times first reported the investigation into user data from past disclosures.
Coinbase shares extended losses after the report and were last down 6.5 percent.
“This is a hold-over investigation from the prior administration about a metric we stopped reporting two and a half years ago, which was fully disclosed to the public,” Coinbase’s chief legal officer, Paul Grewal, said.
“While we strongly believe this investigation should not continue, we remain committed to working with the SEC to bring this matter to a close.”
The SEC declined to comment.

Cracks in crypto
The latest developments come days before the company is set to join the benchmark S&P 500 index, casting a shadow over what was expected to be a landmark moment for the crypto industry.
Security remains a challenge for the crypto industry despite its growing mainstream acceptance. In February, Bybit disclosed a hack in which around $1.5 billion of digital tokens were stolen — widely dubbed the biggest crypto heist of all time.
“The cyberattack may push the industry to adopt stricter employee vetting and introduce some reputational risks,” said Bo Pei, analyst at US Tiger Securities.
Funds stolen by hacking crypto platforms totaled $2.2 billion in 2024, according to a report from Chainalysis.
“As our nascent industry grows rapidly, it draws the eye of bad actors, who are becoming increasingly sophisticated in the scope of their attacks,” said Nick Jones, founder of crypto firm Zumo.
The firm now also faces a lawsuit, filed in the Southern District of New York, alleging the world’s largest crypto exchange failed to secure and safeguard personally identifiable information of millions of former and current customers, the filing showed.
Coinbase has refused to pay a ransom demand of $20 million from the attackers and is working with law enforcement agencies. It has instead established a $20 million reward for information on the hackers.
The company is also opening a new support hub in the US and taking other measures to prevent such cyberattacks, it said.


Death toll in Karachi shopping plaza fire rises to 10 as search continues for dozens missing

Updated 2 sec ago
Follow

Death toll in Karachi shopping plaza fire rises to 10 as search continues for dozens missing

  • Mayor Murtaza Wahab said on Monday that four more bodies were recovered overnight, raising the death toll to at least 10
  • The fire broke out late Saturday. According to Sindh Chief Minister Murad Ali Shah, families reported about 60 people missing
KARACHI: The death toll from a massive fire at a shopping plaza in Pakistan’s largest city, Karachi, rose to at least 10 after rescuers recovered four more bodies from the badly damaged building during an overnight search for dozens of people reported missing, officials said Monday.
Firefighters extinguished the blaze at the multistory Gul Plaza late Sunday nearly 24 hours after it erupted, allowing rescue teams to enter the building to rescue those trapped there. Mayor Murtaza Wahab said four more bodies were recovered overnight, raising the death toll to at least 10.
Local media reported that at least 14 people died in the blaze.
The fire broke out late Saturday and spread quickly through shops storing cosmetics, garments and plastic goods, said Dr. Abid Jalal Sheikh, the city’s chief rescue officer.
On Sunday night, Sindh Chief Minister Murad Ali Shah said families had reported about 60 people missing, prompting authorities to launch the search operation. Relatives of the missing gathered outside the heavily damaged building Monday, many in tears, witnesses said.
The cause of the fire was not immediately known. Police said an investigation was underway.
Karachi, the capital of Sindh province, has a history of deadly fires, often blamed on poor safety standards and illegal construction. In November 2023, a fire at a shopping mall in the city killed 10 people and injured 22 others.
A massive fire at a garments factory in Karachi in 2012 killed 260 people.