Coinbase, a leading platform for trading cryptocurrency, recently dealt with a data breach. Some customer information was stolen by unauthorized people. Good news: your passwords and funds are still safe. Here’s what happened and what it means for you.
On May 15, 2025, Coinbase, one of the top cryptocurrency exchanges, reported a security issue. Criminals bribed customer service agents working overseas to access user data. This affected less than 1% of its monthly active users. With around 9 million users trading each month in 2025, that’s roughly 90,000 people.
What Got Stolen?
The attackers took personal details like names, addresses, phone numbers, and email addresses. They also grabbed account details, including balance snapshots and transaction records. Masked Social Security numbers (just the last four digits), masked bank-account numbers, and government ID photos were accessed too.
But here’s what they didn’t get: passwords, two-factor authentication codes, or private keys for crypto wallets. This means they can’t sign into your account or move your money. Your funds are secure.
How Did This Happen?
This wasn’t a high-tech hack. The criminals used social engineering. They tricked or paid off customer service agents to misuse their access. These agents, based outside the U.S., handed over the data. Attacks like this are growing fast. Coinbase says social engineering incidents targeting financial companies have jumped 10 times in the last year.
Coinbase Fights Back
Coinbase acted quickly. They rejected the criminals’ demand for $20 million to stay quiet. Instead, they’re offering a $20 million reward for tips that lead to arrests. The company fired the agents involved and reported them to the police. They’re working with law enforcement in the U.S. and abroad to catch the culprits.
To stop this from happening again, Coinbase is stepping up security. They’re adding ID checks for big withdrawals on affected accounts. They’re also building a new U.S.-based support center for better control. Plus, they’re investing in tools to spot insider risks and running more security tests. Users who sent money to scammers before May 15, 2025, because of this breach can get refunds after a review.
Why This Matters
Social engineering is a big problem now. Criminals use tricks to get information or access, often starting with data from other breaches or public sources. A Coinbase blog post from February 2025 warned about this trend.
Recently, some Coinbase users noticed more scam texts and calls. Coinbase says these scams aren’t tied to the breach or the separate TeleMessage incident. Still, it’s a reminder to stay cautious.
How to Stay Safe
Coinbase suggests a few easy steps:
- Turn on withdrawal allow-listing. This limits transfers to addresses you approve.
- Lock your account if something feels off .
- Watch out for scam calls or texts. Don’t share personal details over the phone. Check Coinbase’s scam tips for more advice.
These habits work for any online account, not just Coinbase.
Coinbase’s Past Troubles
This isn’t new for Coinbase. In July 2024, a third-party breach may have exposed user data. Back in 2021, a flaw let hackers steal funds from 6,000 accounts . The 2025 breach stands out because it involved insiders, showing even employees can be a weak link.
What’s Next?
The May 15, 2025, breach hit a small group of users but spared their funds. Coinbase’s refusal to pay and its $20 million bounty send a clear message to criminals. Yet, this incident shows how social engineering threatens crypto platforms. Stay smart about your security to keep your money safe.





















