Coinbase disclosed a material cybersecurity incident on May 15, 2025, saying an unknown threat actor had obtained customer-account information and internal support documents through paid insiders. The company’s SEC filing connected the stolen information to a campaign involving multiple contractors or employees in support roles outside the United States.
The incident mattered because it exposed a risk distinct from a blockchain or private-key compromise. Coinbase said the attackers did not gain passwords, private keys or direct access to customer funds. Instead, they obtained identity and account information that could make impersonation attempts more convincing, creating a bridge between a centralized company’s internal systems and irreversible cryptocurrency transfers initiated by deceived customers.
What Coinbase reported
Coinbase said it received an email from the threat actor on May 11 demanding money in exchange for withholding the information. During the preceding months, the company’s security monitoring had separately detected support personnel accessing data without a business need. Coinbase said it terminated those workers, increased fraud monitoring and warned customers whose information might have been accessed.
After receiving the May 11 message, Coinbase assessed it as credible and concluded that the earlier instances formed one campaign. The SEC filing listed exposed information including names, addresses, telephone numbers, email addresses, the last four digits of Social Security numbers, masked bank-account information, government-identification images, account-balance snapshots, transaction histories and limited internal corporate material.
The filing said no passwords or private keys were compromised and that the targeted workers could not access customer funds. Coinbase’s separate May 15 incident report added that login credentials, two-factor-authentication codes, Coinbase Prime accounts and customer hot or cold wallets were not accessed.
Coinbase described the affected population as less than 1% of its monthly transacting users. That was a company-reported proportion, not an independently audited count. The May 15 records did not disclose an absolute number of affected customers, and “monthly transacting users” was a narrower denominator than all registered accounts.
A ransom refusal and reimbursement commitment
Coinbase’s incident report placed the extortion demand at $20 million. The company said it would not pay and instead announced a $20 million reward fund for information leading to the attackers’ arrest and conviction. Its SEC filing confirmed that the demand had not been paid and that Coinbase was cooperating with law enforcement, without specifying the demanded amount.
The company also promised voluntary reimbursement for eligible retail customers who had sent assets to the attackers as a direct result of the campaign. Reimbursement remained subject to Coinbase reviewing each case and confirming the facts. The commitment therefore was not a verified measurement of losses or an unconditional payment to every affected account holder.
Coinbase said notifications to customers known to be affected were sent at 7:20 a.m. Eastern on May 15. It also described additional identity checks for some large withdrawals, stronger insider-threat monitoring and plans for a new support hub in the United States. Those were announced responses; the event-day record could not establish their eventual effectiveness.
The financial estimate was preliminary
Coinbase estimated approximately $180 million to $400 million of expenses related to remediation and voluntary customer reimbursements. The SEC filing explicitly characterized that range as preliminary and said it could change meaningfully after further review of losses, indemnification claims and potential recoveries.
As of May 15, Coinbase said it had not experienced a material operational impact, while also acknowledging that the full financial impact remained unknown. That distinction is important: the expense range did not represent a completed loss calculation, confirmed customer theft total or regulatory penalty.
What remained unresolved
The contemporaneous records did not establish the campaign’s starting date, the precise number of insiders or customers involved, total assets lost through impersonation, the attackers’ identities, or whether additional information had been extracted. They also could not determine whether Coinbase’s controls had contained every related misuse.
The defensible May 15 conclusion was therefore narrow but significant: insiders had extracted sensitive customer data from a major cryptocurrency intermediary, attackers had used that information to support social-engineering scams, and Coinbase faced a potentially substantial reimbursement and remediation bill. The ultimate losses, legal consequences and effectiveness of the response remained open questions.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

