[HN Gopher] I have recordings proving Coinbase knew about breach...
___________________________________________________________________
I have recordings proving Coinbase knew about breach months before
disclosure
Author : jclarkcom
Score : 226 points
Date : 2025-11-16 20:18 UTC (2 hours ago)
(HTM) web link (jonathanclark.com)
(TXT) w3m dump (jonathanclark.com)
| jclarkcom wrote:
| In January 2025, I was targeted by scammers who knew my exact
| Bitcoin balance, SSN, DL, and other private Coinbase account
| details. I immediately reported this to Coinbase's Head of Trust
| & Safety with recordings and technical evidence. Despite repeated
| follow-ups asking how attackers had my data, Coinbase went silent
| for 4 months. They only disclosed the breach in May after
| attackers demanded $20M ransom. The breach involved overseas
| contractors at TaskUs being bribed for customer data. This
| article documents the timeline with emails, recordings, and
| evidence showing Coinbase was aware of the breach months before
| their official "discovery" date.
| scottiebarnes wrote:
| Are you going to be suing?
| jclarkcom wrote:
| I would consider it but I'm not sure what my options are on
| this.
| tyre wrote:
| You'd need to prove harm, which is somewhat nebulous here.*
|
| Matt Levine has a prescient and depressing quote about the
| only recourse for being being shareholder lawsuits:
|
| > I find all of this so weird because of how it elevates
| finance. [Various cases] imply that we are not entitled to
| be protected from pollution as _citizens_ , or as _humans_.
| [Another] implies that we are not entitled to be told the
| truth as _citizens_. (Which: is true!) Rather, in each
| case, we are only entitled to be protected from lies _as
| shareholders_. The great harm of pollution, or of political
| dishonesty, is that it might lower the share prices of the
| companies we own.
|
| * To be clear, I don't think it is nebulous, and you're
| right to feel harmed. But, legally, I don't know the harm
| in "they didn't respond to my emails" after there's no
| concrete damage.
| criddell wrote:
| Were you harmed?
|
| I've never looked at the Coinbase agreement that's
| presented when you open an account, but chances are you
| would have to go through arbitration first. That's not
| necessarily a bad thing.
| nightpool wrote:
| You mentioned that the DKIM headers "passed validation for
| coinbase.com". How could that have been possible, if the email
| was a phishing email? I'm not sure I understood that part,
| especially because you didn't provide any examples of the
| header data you received from the attacker.
| Cantinflas wrote:
| Yeah this is very confusing for me too, how could the
| attackers create a valid DKIM signature for coinbase.com?
| Either there is a huge misconfiguration or it's not possible.
| Am I missing something?
| jmclnx wrote:
| Isn't there a new law from the Biden era that forces a company
| disclose breaches to their customers and the SEC within a few
| weeks ?
|
| If so and if the US had a sane administration maybe, this would
| be acted upon, but these days, anything goes as long as you
| 'donate' to the ballroom.
| jclarkcom wrote:
| Yes, I did briefly touch on that in the article. "SEC rules
| require timely reporting of material cybersecurity incidents."
|
| Looking into this more now I see SEC Rule requiring disclosure
| within 4 business days of determining a cybersecurity incident
| is "material"
|
| There is a big list of SEC violations as a result: 1. Late
| Disclosure (Item 1.05) If materiality was determinable in
| January - 4-day rule violated Penalty: Fines, enforcement
| actions
|
| 2. Misleading Statements/Omissions (Rule 10b-5) Any public
| statements about security between Jan-May could be problematic
| Omitting known material risks = securities fraud
|
| 3. Inadequate Internal Controls (SOX) Failure to properly
| investigate and escalate user reports Inadequate breach
| detection systems
|
| 4. Failure to Maintain Adequate Disclosure Controls My report
| should have triggered disclosure review Going silent suggests
| broken escalation process
| divvvyy wrote:
| Wild tale, but very annoying that he wrote it with an AI. It's
| horribly jarring to read.
| Grimblewald wrote:
| How do you know?
|
| I'm not trying to be recalcitrant, rather I am genuinly
| curious. The reason I ask is that no one talks like a LLM, but
| LLMs do talk like someone. LLMs learned to mimic human speech
| patterns, and some unlucky soul(s) out there have had their
| voice stolen. Earlier versions of LLMs of LLMs that more
| closely followed the pattern and structure of a wikipedia entry
| were mimicking a style that that was based of someone elses
| style and given some wiki users had prolific levels of
| contributions, much of their naturally generated text would
| register as highly likely to be "AI" via those bullshit ai
| detector tools.
|
| So, given what we know of LLMs (transformers at least) at this
| stage it seems more likely to me that current speech patterns
| again are mimicry of someones style rather than an organically
| grown/developed thing that is personal to the LLM.
| gmzamz wrote:
| Looks like AI to me too. Em dashes (albeit nonstandard) and
| the 'it's not just x, it's y' ending phrases were everywhere.
| Harder to put into words but there's a sense of grandiosity
| in the article too.
|
| Not saying the article is bad, it seems pretty good. Just
| that there are indications
| lynndotpy wrote:
| It's also strange to suggest readers use ChatGPT or Claude
| to analyze email headers.
|
| Might as well say "You can tell by the way it is".
| drabbiticus wrote:
| Just chiming in here - any time I've written something online
| that considers things from multiple angles or presents more
| detailed analysis, the liklihood that someone will ask if I
| just used ChatGPT go way up. I worry that people have gotten
| really used to short, easily digestible replies, and conflate
| that with "human". Because of course it would be crazy for a
| human to expend "that much effort" on something /s.
|
| EDIT: having said that, many of the other articles on the
| blog do look like what would come from AI assistance. Stuff
| like pervasive emojis, overuse of bulleted lists, excessive
| use of very small sections with headers, art that certainly
| appears similar in style to AI generated assets that I've
| seen, etc. If anything, if AI was used in this article, it's
| way less intrusive than in the other articles on the blog.
| jclarkcom wrote:
| Author here - yes, this was written using guided AI. I
| consider this different than giving a vague prompt and
| telling it to write an article. My process was to provide
| all the information, for example I used AI to: 1.
| transcribe the phone call into text using whisper model 2.
| review all the email correspondence 3. research industry
| news about the breach 4. brainstorm different topics and
| blog structures to target based on the information, pick
| one 5. Review the style of my other blog articles 6. write
| the article and redact any personal info 7. review the
| article and suggest iterate on changes multiple times. To
| me this is more akin to having a writer on staff who can
| save you a lot of time. I can do all the above in less than
| 30mins, where it could take a full day to do it manually. I
| had a blog 20 years ago but since then I never had time to
| write content again (too time consuming and no ROI) - so
| the alternative would be nothing.
|
| There are some still some signs you can tell content is AI
| written based on verbosity, use of bold, specific HTML
| styling, etc. I see no issues with the approach. I noticed
| some people have an allergic reaction to any hint of AI,
| and when the content produced is "fluff" with no real
| content I get annoyed too - however that isn't the case for
| all content.
| shayway wrote:
| The issue is that the article is excessively verbose; the
| time you saved in writing end editing comes at the cost
| of wasting readers' time. There is nothing wrong with
| using AI to improve writing, but using it to insert fluff
| that came at no cost to you and no benefit to me feels
| like a violation of social contract.
|
| Please, at least put a disclaimer on top so I can ask an
| AI to summarize the article and complete the cycle of
| entropy.
| jclarkcom wrote:
| I have attempted to condense it based on your feedback,
| and added some more info about email headers.
| yuvadam wrote:
| This blog post isn't human speech, it's typical AI slop.
| (heh, sorry.)
|
| Way too verbose to get the point across, excessive usage of
| un/ordered bullets, em dashes, "what i reported / what
| coinbase got wrong", it all reeks of slop.
|
| Once you notice these micro-patterns, you can't unsee them.
|
| Would you like me to create a cheat sheet for you with these
| tell tale signs so you have it for future reference?
| glitchc wrote:
| Supporting evidence required.
| anonym29 wrote:
| Many people find whining about coherent, meaningful text based
| on the source identity to be far more annoying than reading
| coherent, meaningful text.
|
| But I guess you knew that already, which is why you just made a
| fresh burner account to whine on rather than whining from your
| real account.
| KomoD wrote:
| Coherent? It's really annoying to read.
|
| The post just repeats things over and over again, like the
| Brett Farmer thing, the "four months", telling us three times
| that they knew "my BTC balance and SSN" and repeatedly
| mentioning that it was a Google Voice number.
| anonym29 wrote:
| Almost sounds like the posts of people whining about LLMs.
|
| Of course, unlike those people, LLMs are capable of
| expressing novel ideas that add meaningful value to diverse
| conversations beyond loudly and incessantly ensuring
| everyone in the thread is aware of their objection to new
| technology they dislike.
| lxgr wrote:
| LLMs are definitely capable of helping with writing,
| connecting the dots, and sometimes now of genuine
| insight. They're also still very capable of producing
| time-wasting slop.
|
| It's the task of anybody presenting their output to third
| parties to read (at least without a disclaimer about a
| given text being unvetted LLM output) to make damn sure
| it's the former and not the latter.
| anonym29 wrote:
| Thankfully, the 8 millionth post whining about LLMs with
| zero additional value added to the conversation is far
| less time-wasting than a detailed blog post about a real-
| world security incident in a major corporation that isn't
| being widely covered by other outlets.
|
| The article isn't paywalled. Nobody was forced to read
| it. Nobody was prohibited from asking an LLM to summarize
| the article.
|
| Whining about LLM written text is whining about one's own
| deliberate choice to read an article. There is no implied
| contract or duty between the author and the people who
| freely choose to read or not read the author's (free)
| publication.
|
| It's like walking into a (free) soup kitchen, consuming
| an entire bowl of free soup, and then whining loudly to
| everyone else in the room about the soup being too salty.
| lxgr wrote:
| I think the feedback that LLMs were used not very
| successfully in the making of TFA is valid criticism and
| might even help other/future authors.
|
| We're probably reading LLM-assisted or even generated
| texts many times per day at this point, and as long as I
| don't notice that my time is being wasted by bad writing
| or hallucinated falsehoods, I'm perfectly fine with it.
| BobAliceInATree wrote:
| I don't know if he wrote it via AI, but he repeats himself over
| and over again. It could have been 1/3 the length and still
| conveyed the same amount of information.
| d1sxeyes wrote:
| 'I don't know if he wrote it via AI, but he repeats himself'.
| alwa wrote:
| I know I shouldn't pile on with respect to the AI Slop
| Signature Style, but in the hopes of helping people rein in the
| AI-trash-filter excesses and avoid reactions like these...
|
| The sentence-level stuff was somewhat improved compared to
| whatever "jaunty Linked-In Voice" prompt people have been
| using. You know, the one that calls for clipped repetitive
| phrases, needless rhetorical questions, dimestore mystery
| framing, faux-casual tone, and some out-of-proportion "moral of
| the story." All of that's better here.
|
| But there's a good ways left to go still. The endless bullet
| lists, the "red flags," the weirdly toothless faux drama ("The
| Call That Changed Everything", "Data Catastrophe: The 2025
| Cyber Fallout"), and the Frankensteined purposes ("You can
| still protect yourself from falling victim to the scams that
| follow," "The Timeline That Doesn't Make Sense," etc.)...
|
| The biggest thing that stands out to me here (besides the essay
| being five different-but-duplicative prompt/response sessions
| bolted together) are the assertions/conclusions that would mean
| something if real people drew them, but that don't follow from
| the specifics. Consider:
|
| _"The Timeline That Doesn 't Make Sense
|
| Here's where the story gets interesting--and troubling:
|
| [they made a report, heard back that it was being investigated,
| didn't get individual responses to their follow-ups in the
| immediate days after, the result of the larger investigation
| was announced 4 months later]"_
|
| Disappointing, sure. And definitely frustrating. But like...
| "doesn't make sense?" How not so? Is it really surprising or
| unreasonable that it takes a large organization time, for a
| major investigation into a foreign contractor, with law
| enforcement and regulatory implications, as well as 9-figure
| customer-facing damages? Doesn't it make sense (even if it's
| disappointing), when stuff that serious and complex happens,
| that they wait until they're sure before they say something to
| an individual customer?
|
| I'm not saying it's good customer service (they could at least
| drop a reply with "the investigation is ongoing and we can't
| comment til it's done"). There's lots of words we could use to
| capture the suckage besides "doesn't make sense." My issue is
| more that the AI presents it as "interesting--and troubling;
| doesn't make sense" when those things don't really follow
| directly from the bullet list of facts afterward.
|
| Each big categorical that the AI introduced this way just...
| doesn't quite match what it purports to describe. I'm not sure
| exactly how to pin it down, but it's as if it's making its
| judgments entirely without considering the broader context...
| which I guess is exactly what it's doing.
| AlexErrant wrote:
| Here's a Reuters report from June 2, which includes a link to a
| May 14 SEC filing:
|
| > Cryptocurrency exchange Coinbase knew as far back as January
| about a customer data leak at an outsourcing company connected to
| a larger breach estimated to cost up to $400 million, six people
| familiar with the matter told Reuters.
|
| https://www.reuters.com/sustainability/boards-policy-regulat...
|
| > On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase
| Global, Inc. ("Coinbase" or the "Company"), received an email
| communication from an unknown threat actor claiming to have
| obtained information about certain Coinbase customer accounts, as
| well as internal Coinbase documentation, including materials
| relating to customer-service and account-management systems.
|
| https://www.sec.gov/Archives/edgar/data/1679788/000167978825...
| jclarkcom wrote:
| Very interesting... January 7th is when I reported it to them
| so that lines up. I suspect I wasn't the very first person, the
| person I spoke with on the phone had the confidence I wouldn't
| expect on the first try.
| j-bos wrote:
| > an outsourcing company
|
| From what I've seen, this is going to be a common subheading to
| a lot of these stories.
| chaps wrote:
| Once did some programming/networking work for a company that did
| the networking of a office sharing building that Coinbase was
| running out of. Early in my work there I noticed that the company
| had its admin passwords written on a whiteboard -- visible from
| the hallway because they had glass for walls. So I sent them an
| email to ask that they remove it (I billed them for it).
|
| Their fix was to put a piece of paper over the passwords.
|
| What a time.
| Aurornis wrote:
| > So I sent them an email to ask that they remove it (I billed
| them for it)
|
| Sending unsolicited bills for unrequested services is a great
| way to make sure nobody takes your email seriously
| nightpool wrote:
| GP is saying that they were already one of Cloudflare's
| vendors (they did the networking/IT setup for Cloudflare's
| office). Whether you'd tolerate that kind of behavior from a
| vendor is one thing, but for an existing vendor relationship
| I think adding a few billable hours for "I found this issue
| in your network and documented and reported it for you" to an
| existing contract is not particularly unreasonable.
| aorloff wrote:
| More likely, this is a spectacular version of CYA. By
| billing the hours, there is a paper trail so that when the
| inevitable breach occurs, you can point to having done the
| appropriate thing.
| Vvector wrote:
| s/cloudflare/coinbase/
| bongodongobob wrote:
| They are lucky they just got a bill and not a terminated
| contract. Consulting companies I have worked for would have
| dropped them immediately because we don't want clients with
| that kind of risk. Massive red flag that signals management
| is non-existent, incompetent, or checked out. That is
| egregious negligence.
| hnthrowaway0315 wrote:
| Top notch start-up speed! Let's brrrrrrrrr...
| 650REDHAIR wrote:
| This doesn't surprise me at all.
|
| Bitcoin, and really fintech as a whole, are beyond reckless.
| monero-xmr wrote:
| Ah yes, I remember all the times they hacked bitcoin
| jamespo wrote:
| lol monero in username
| 8organicbits wrote:
| There's a great index of hacks here
| https://www.web3isgoinggreat.com/?theme=hack
|
| It's breathtaking how frequent these are.
| happyopossum wrote:
| That's like saying the $USD was hacked when a bank gets
| breached.
| braingravy wrote:
| Are banks breached at the same rate as bitcoin brokers? I
| think that was op's point.
| 8organicbits wrote:
| That's a silly assumption to make. I'm clearly talking
| about the poor security offered by cryptocurrency, in
| practice, as evidenced by the frequent hacks impacting
| cryptocurrency companies.
| arcanemachiner wrote:
| It's been a while, but it has happened:
|
| https://nvd.nist.gov/vuln/detail/CVE-2010-5139
| KetoManx64 wrote:
| Bitcoin is a crypto-currency/blockchain. Coinbase is a
| corporation that allows users to buy/trade crypto-currencies.
|
| With Bitcoin you do not get government bailouts like what
| happened with the beyond reckless banks in 2008.
| arcanemachiner wrote:
| > With Bitcoin you do not get government bailouts like what
| happened during the beyond reckless banks in 2008
|
| It is not beyond imagination that the most popular Bitcoin
| blockchain (and thus, the label of being the "real"
| Bitcoin) could change at some point in the future.
|
| "Bitcoin" is not immune from the implications of political
| fuckery.
| adastra22 wrote:
| By what mechanism? The whole point of bitcoin is that you
| can't force a consensus change. This is enforced by the
| algorithm and the laws of thermodynamics.
| arcanemachiner wrote:
| If, for whatever reason, all the mining power switches to
| the other chain, it will become the de facto "Bitcoin".
|
| I don't know what the specific mechanism would be, but I
| would bet that it relates to the billions of dollars
| backing the current ecosystem, and the interests of the
| people behind them. If the right event or crisis comes
| along, then people could be compelled to switch over to
| something else.
|
| I'm sure there's someone out there still mining blocks on
| that chain with the exploit from 2010, but that's not
| where the mining power is. If the right series of events
| occurs, the miners will switch.
| KetoManx64 wrote:
| Bitcoin has forked a few times it's creation:
| https://en.wikipedia.org/wiki/List_of_bitcoin_forks The
| determining factor for which fork is successfully is
| bases on the Bitcoin node runners and miners choosing
| which fork they devote their resources to.
|
| Governments around the world are 100% attempting
| different plans to destabilize or destroy Bitcoin because
| it harms their interests and ability to print money from
| thin air. But at the end of the day it's a distributed
| ledger, so even if they do find a way to manipulate or
| damage or takeover the network the Bitcoin users can just
| fork it from before they did their damage and continue
| from there. That is the ultimate power of a decentralized
| blockchain, nobody has ultimate power and everyone votes
| with their resources.
| nradov wrote:
| Power comes from the barrel of a gun.
| dahinds wrote:
| "With Bitcoin you do not get government bailouts" -- yeah
| maybe not yet? Is it beyond belief that a government with
| leadership deeply invested in crypto currencies might take
| action if something super disruptive happens?
| KetoManx64 wrote:
| Possible. But Bitcoin is hard capped at 21 million coins.
| The government can peint more paper money to bail a
| company out if it makes stupid decisions, but they cannot
| print more Bitcoin. This will devalue the paper currency
| even more and also increase the value of Bitcoin. Bitcoin
| is called a hedge against inflation for a reason.
| robocat wrote:
| At present BTC is usually denominated in USD. Until I
| start to see BTC used as the cross-rate I'm sceptical.
| Presuming it occurs, it would occur relatively quickly?
| kibwen wrote:
| _> But Bitcoin is hard capped at 21 million coins_
|
| Bitcoin is not an immutable law of nature. If the coin
| minting cap is reached, all that needs to happen is for
| miners to start running a fork with a higher cap. Tada,
| more coins conjured out of the ether, just like all the
| previous ones. If you want enforced scarcity, you need to
| be tied to something physically scarce.
| immibis wrote:
| There was a government* bailout in Ethereum, however.
| https://en.wikipedia.org/wiki/The_DAO
|
| The government of Ethereum is not the US government.
| KetoManx64 wrote:
| I don't see a reference to a government bailout in the
| article you listed. The chain was forked by the community
| to the state before the hack and most users switched over
| this supporting this fork and calling it Etherium going
| forward.
| danielhlockard wrote:
| You say that but I work in fintech (granted, one of the
| larger more corporate ones, after an acquisition) and we are
| heavily regulated, and audited.
| BrenBarn wrote:
| I'm shocked, shocked to find that a cryptocurrency company did
| something shady.
| anonym29 wrote:
| Your employer doesn't utilize low-cost overseas labor to pad
| margins?
| rs186 wrote:
| Not parent but mine doesn't let them handle client social
| security numbers.
| tchalla wrote:
| Founder mode.
| anonym29 wrote:
| Has anyone demonstrated that agentic AI systems can be bribed
| with money, or is that vulnerability still strictly relegated to
| unrealiable, untrustworthy biological intelligence?
| paulbjensen wrote:
| I got rung in the UK I think a month ago from someone claiming to
| be from Coinbase. I told them I only had about PS5 of Bitcoin
| cash in my account (which was true), and they immediately lost
| interest and said a forthcoming email would handle the matter.
|
| They also asked if I had cold storage. I told them I had a fridge
| (also true).
| KetoManx64 wrote:
| Hahaha, i'm using this next time I get a spam call
| jrm4 wrote:
| FWIW, this is why "not your keys, not your coins."
|
| Coinbase is good for on-ramping, bad for storage. You know, the
| entire point of cryptocurrency.
| wmf wrote:
| People doing self-custody also get hacked and phished all the
| time.
| jclarkcom wrote:
| True - but be very careful. Roughly 10-18% of all BTC are
| believed gone forever due to lost keys/wallets. That is more
| than all hacks and exchange blowups combined. If you take your
| wallet offline it can be hard not to lose your keys over a long
| period of time, including across death to your next of kin.
| mtlynch wrote:
| This is an extremely clickbaity headline.
|
| The "recordings" are of a phisher attempting to get information
| from the author. It proves nothing about what Coinbase knew.
|
| The author turned the information over to Coinbase, but that
| doesn't prove Coinbase knew about their breach. The customer
| could have leaked their account details in some other way.
| jclarkcom wrote:
| I sent the phone recording and emails to coinbase, and they
| acknowledged them saying "This report is super robust and gives
| us a lot to look into. We are investigating this scammer now."
| rs186 wrote:
| You apparently did not read the article. What you are looking
| for is right there.
| what-the-grump wrote:
| We use Coinbase as an org, we were targeted in early Feb 2025.
| Caught by person handling the accounts who is paranoid enough to
| reach out to the org contact on the other side.
| fragmede wrote:
| My Coinbase account got caught up in this and I'm so glad I used
| something like coinbase_jridi46@example.com as my email address
| with them because emails to that address can be treated as
| hostile in the wake of the breach. if I'd just used
| coinbase@example.com as my email address with them, I'd be
| fucked.
| immibis wrote:
| Why couldn't you treat coinbase@example.com as hostile?
| happyopossum wrote:
| Interesting timeline, but nothing here proves, or even strongly
| indicates, that Counbase "knew about the breach" from this one
| report.
|
| Screenscraping malware is fairly common, and it's not
| unreasonable for an analyst to look at a report like this and
| assume that the customer got popped instead of them.
|
| Customers get popped _all the time_ , and have a tendency to
| blame the proximate corporation...
| jclarkcom wrote:
| That's true, but in this case I got a response from the head of
| trust and safety after I sent the phone recording, email +
| email headers, saying "This report is super robust and gives us
| a lot to look into. We are investigating this scammer now."
| anxman wrote:
| Not sure if the op is reading, but I also detected the same
| Coinbase hack around the same timeline. From what I can tell,
| literally everything was compromised because even their Discord
| channel's api keys were compromised and were finally reset around
| April or May. This means their central secrets manager was likely
| compromised too.
| 8organicbits wrote:
| This doesn't seem like proof to me.
|
| The author got a phishing call and reported it. Coinbase likely
| has a deluge of phishing complaints, as criminals know their
| customers are vulnerable and target their customers regularly.
| The caller knowing account details is likely not unique in those
| complaints; customers accidentally leak those all the time. Some
| of the details the attacker knew could have been sourced from
| other data breaches. At the time of complaint, the company
| probably interpreted the report as yet another customer handling
| their own data poorly.
|
| Phishing is so pervasive that I wouldn't be surprised if the
| author was hit by a different attack.
| jclarkcom wrote:
| My first thought was someone they tied a blockchain transaction
| to my name and then traced it backwards. But they also knew my
| ETH and BTC balances, and date the account was opened. You
| might be able to figure out the open date by looking at the
| blockchain but I could never determine how they would know
| balances for two unrelated cryptos without some kind of
| coinbase compromise.
| coolThingsFirst wrote:
| The entire web3 scene is a clusterfuck filled with scammers.
| Recently i got hacked by web3 interview which is a common vector
| nowadays.
|
| They send github repo and as soon as you run it they send
| rejection after stealing tokens and installing keylogger. Pretty
| sophisticated and the frontend of the codebase looked polished as
| well.
___________________________________________________________________
(page generated 2025-11-16 23:00 UTC)