• News/
  • https://www.bleepingcomputer.com/news/security/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/

Coinbase fixes 2FA log error making people think they were hacked

BleepingComputer
·
Lawrence Abrams
·
Published Apr 27, 2025
·
Updated

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised. As BleepingComputer first reported earlier this month, Coinbase had mistakenly labeled failed login attempts with incorrect passwords as two-factor authentication failures in the Account Activity logs. When a threat actor attempted to access someone's account and used the wrong password, error messages stating "second_factor_failure" or "2-step verification failed" would be shown instead. These entries imply that a valid username and password were entered, but the login was blocked by 2-factor authentication, such as entering the wrong one-time passcode from an authenticator app. Numerous Coinbase users contacted BleepingComputer with concerns that Coinbase had been breached, as their passwords were unique to the site, there was no sign of malware, and no other accounts were affected. However, Coinbase confirmed to BleepingComputer that its logging system was incorrectly attributing login attempts with incorrect passwords as "2FA failures," even though the attackers had not successfully reached the 2FA stage. Coinbase has now pushed an update to fix this incorrect labeling so that "Password attempt failed" logs are shown in Account Activity instead. Bugs like this are essential to fix as they cause unnecessary panic, with users telling BleepingComputer that they had reset all their passwords and spent hours trying to determine if their devices were c...

Read full article

Affected Software

2 affected components
Coinbase Account Activity Logging System
Coinbase Account Activity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main issue discussed in the article?

The article discusses a bug in Coinbase's account activity logs that misled users into thinking their accounts had been hacked.

2

How did this bug affect Coinbase users?

The bug incorrectly labeled failed login attempts, causing confusion and concern among users regarding the security of their accounts.

3

What has Coinbase done to address this issue?

Coinbase has implemented a fix to resolve the misleading log entries that generated incorrect security alerts.

4

Are there any security implications mentioned in the article?

The article highlights the importance of accurate logging in account security and the potential for user panic due to log inaccuracies.

5

Which product was specifically affected by this logging error?

The issue specifically affected the Coinbase Account Activity Logging System.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Coinbase fixes 2FA log error making people think they were hacked - SecAlerts