A security researcher says Coinbase knew about a December 2024 security breach during which miscreants bribed its support staff into handing over almost 70,000 customers' details at least four months before it disclosed the data theft. The researcher, Jonathan Clark, says he knows this for a fact because he reported the attack to Coinbase on January 7 after the criminals tried to scam him. According to Clark, Coinbase's Head of Trust and Safety Brett Farmer responded to his "comprehensive security report" the same day he emailed it to the company's security@ address. In a blog about the incident, Clark says Farmer replied: "This report is super robust and gives us a lot to look into. We are investigating this scammer now." And then, he says, he never heard another word from Coinbase, despite four follow-up emails sent in January. As a refresher: In May, Coinbase disclosed the breach to the US Securities and Exchange Commission. At the time, the company said the data thieves stole 69,461 people's private and financial information, including their name, date of birth, the last four digits of their Social Security number, address, phone number, email address, driver's license number, passport number, national identity card number, transaction history, balance, transfer, and the date customers opened their accounts. Coinbase said the breach took place on December 26, 2024, but wasn't discovered until May 11. The crooks also tried extorting the company for $20 million. Clark dispu...
Security researcher calls BS on Coinbase breach disclosure timeline
The Register
·Jessica Lyons
·Published Nov 17, 2025
·Updated
Affected Software
1 affected component
Coinbase Coinbase
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security breach at Coinbase where customer details were compromised after bribery of support staff.
2
What security implications are discussed?
The implications include potential identity theft and unauthorized access to customer accounts due to the leaked personal information.
3
What products or software are affected?
The affected product is Coinbase, a cryptocurrency exchange platform.
4
When did the breach reportedly occur?
The breach reportedly took place in December 2024.
5
How long did Coinbase wait to disclose the breach?
Coinbase allegedly waited at least four months to disclose the breach after becoming aware of it.