Customer lost $350,000 in September 2022 to a phishing attack from a scammer that the customer said had “confidential information that could have only been obtained with direct access to Coinbase’s database”.
Coinbase didn’t prevent the suspicious transfers, allegedly wiped customer’s transaction history, blamed the customer for the loss, then refused to reimburse. Arbitration concluded with $0 reimbursement.
Arbitrator found the complaint had been filed too late, and that the customer had admitted that a third party rather than a Coinbase insider had performed the theft. Doesn’t appear the arbitrator investigated the claims of a possible breach, or how the hardware MFA was bypassed.