On February 16, 2019, public reporting carried Coinmama’s disclosure that a perpetrator had obtained approximately 450,000 user email addresses and hashed passwords. The cryptocurrency brokerage said it had learned of the exposure on February 15 and that the affected credentials belonged to customers who registered in August 2017 or earlier.

The disclosure was consequential because it separated custody risk from account-security risk. Coinmama said it did not hold customer funds or store credit-card information, but its service still depended on user accounts and identity checks. Compromised credentials could therefore expose customers to account takeover, credential-stuffing attempts elsewhere or targeted impersonation even without a reported loss of cryptocurrency from the brokerage.

What Coinmama said was exposed

Coinmama’s event-day account described email addresses and hashed passwords, not readable payment-card records. A password hash is not the same as a plaintext password, but its resistance to recovery depends on the hashing method, password strength and computing resources available to an attacker. Coinmama did not provide enough technical detail on February 15 or February 16 to independently evaluate that resistance.

The company said on February 15 that it had found no evidence that the exposed information had been used by the perpetrators. That statement described what Coinmama knew during an active investigation; it was not proof that misuse had not occurred or would not occur later. The identity of the person or group responsible also remained unknown.

Coinmama established an incident-response team, began notifying affected customers and started expiring potentially affected passwords on February 15. It also said it was monitoring its systems for suspicious activity and unauthorized access. Those were company-reported containment measures rather than independently audited findings.

Why the incident mattered to crypto infrastructure

The breach illustrated a recurring weakness in centralized access points to cryptocurrency markets. A brokerage can avoid custody of customer coins and still maintain account records that attackers may value. Email addresses and reused passwords can connect activity across services, while an established relationship with a crypto company can make a customer a more plausible target for phishing or impersonation.

The distinction also mattered institutionally. Crypto businesses that collect personal information for customer verification inherit data-protection obligations alongside the technical risks associated with digital assets. The incident was therefore not evidence that the Bitcoin or Ethereum networks had failed. It concerned the security of a company-operated customer system at the boundary between conventional identity records and cryptocurrency transactions.

Market context on February 16

Kraken’s daily report for February 16 recorded $30.8 million of trading across its listed markets. It reported bitcoin at $3,597, up 0.76%, on $14 million of venue volume, and ether at $122.60, up 1.95%, on $9.06 million. These were Kraken-specific observations for its dated reporting window, not consolidated global prices or official market closes. The surviving report does not specify its precise timezone boundary, and the figures do not establish that Coinmama’s disclosure caused any market movement.

Later clarification

Information released after February 16 materially expanded the known scope. Coinmama said that on February 17 it learned an unauthorized party had acquired data associated with 1.4 million accounts, including additional personal information. A later breach notice filed with the California attorney general identified December 9, 2018 as the known breach date. Those later records clarify the incident but were not available for the February 16 event-day assessment; the approximately 450,000-account figure remains the documented scope known in the contemporaneous disclosure.

Primary sourceCoinmama — Account Security FAQ

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.