Overview
- The breach targeted less than 1% of Coinbase's customer base, exposing personal data including names, addresses, government IDs, and partial Social Security numbers, but no passwords or private keys were compromised.
- Hackers bribed rogue overseas support agents to access internal systems and facilitate social engineering scams aimed at stealing user funds.
- Coinbase declined the $20 million ransom demand and instead established a $20 million reward fund for information leading to the attackers' arrest.
- The company estimates costs between $180 million and $400 million for remediation, customer reimbursements, and security improvements.
- The SEC is investigating Coinbase's historical user metrics, adding regulatory pressure as the company prepares to join the S&P 500 index next week.