Activity tagged "Coinbase"
It’s been two weeks since Coinbase disclosed its data breach, and so far we’re up to:
• 8 customer class actions against Coinbase
• 1 shareholder class action against Coinbase
• 1 customer class action against TaskUs, a contractor the plaintiffs allege was responsible for the breach.
Given the recent data breach and Coinbase’s user agreement that aims to force customers into arbitration rather than individual or class action lawsuits, it’s interesting to read the outcome of a recent arbitration case against Coinbase.
Customer lost $350,000 in September 2022 to a phishing attack from a scammer that the customer said had “confidential information that could have only been obtained with direct access to Coinbase’s database”.
Coinbase didn’t prevent the suspicious transfers, allegedly wiped customer’s transaction history, blamed the customer for the loss, then refused to reimburse. Arbitration concluded with $0 reimbursement.
Arbitrator found the complaint had been filed too late, and that the customer had admitted that a third party rather than a Coinbase insider had performed the theft. Doesn’t appear the arbitrator investigated the claims of a possible breach, or how the hardware MFA was bypassed.
A Coinbase data breach filing with the Maine Attorney General finally gives us some more detail than Coinbase’s vague “less than 1% of monthly transacting users”. 69,461 people were affected, and Coinbase says the data breach occurred on December 26, 2024.
It took them almost five months between the incident and the incident disclosure, although the company has since admitted it knew customer support agents were suspiciously accessing customer data as far back as January.
Security researchers who have spent months trying to call Coinbase’s attention to serious issues at the company are disputing Coinbase’s claims about the timing of the breach. “Threat actors had ongoing access via multiple insiders over a prolonged period of time.”
The SEC requires material cybersecurity incidents be disclosed within four business days; state laws often have a 30-day disclosure deadline. It’s not clear if customers outside the US were affected; if so, other disclosure laws may apply.
Issue 84 – Rogue overseas support agents
In April, Coinbase announced changes to its user agreement that added two clauses further limiting class action lawsuits and requiring lawsuits to be filed in New York. The changes apply to disputes initiated after May 15.
On May 14, Coinbase disclosed a data breach.
Five lawsuits have been filed against Coinbase in response to the breach since then: all class action, none before May 15, two outside of New York.
Coinbase announces it's joining the S&P 500 and then announces a serious data breach two days later.
oof.
The only data Coinbase has disclosed about the scale of the breach is that it affects "less than 1% of Coinbase monthly transacting users", which seems super cagey.
Coinbase Chief Legal Officer: the critics who think we’ve bought out the government are refusing to engage with the nuanced and complicated fact that Trump used to be anti-crypto before we started spending hundreds of millions of dollars on politics
Coinbase says that the SEC has agreed to drop the enforcement case against the company. It only cost them $75 million in political contributions.
(Don’t forget that $50 million of those contributions appeared to be blatantly illegal, although Trump is already hard at work making the Federal Elections Commission even less effective than it previously was.)