Coinbase Said No: The $20 Million Demand That Became a $20 Million Manhunt
Unknown actors bribed overseas Coinbase support workers to copy customer data, then demanded $20 million. Coinbase refused, disclosed the incident to the SEC with a preliminary $180–$400 million cost estimate, and posted a $20 million reward for the attacker's arrest and conviction.

3-Minute Fast Briefing
- The ParadoxOn May 11, 2025, an unknown threat actor emailed Coinbase demanding $20 million, claiming to hold customer account data and internal company documents copied by bribed overseas support personnel.
- The Turning PointCoinbase refused to pay, told the SEC that passwords, private keys, two-factor codes, and customer funds were never exposed, and preliminarily estimated $180–$400 million in remediation and reimbursement costs.
- The LegacyThe exchange converted the ransom figure into a $20 million reward for information leading to the attacker's arrest and conviction, answering data extortion with a public manhunt.
Chronological Timeline
Per a Maine Attorney General filing reported by The Hacker News, the insider wrongdoing originally occurred on December 26, 2024, with Bloomberg-reported statements dating unusual agent activity to January.
According to Coinbase's Form 8-K, its security monitoring independently detected support personnel accessing data without business need in the previous months, and the company says it immediately fired them and warned affected customers.
An unknown threat actor emails Coinbase claiming customer account data and internal documents, demanding money not to publish; Coinbase assesses the message as credible and press reports the demand as $20 million.
Coinbase Global files a Form 8-K material cybersecurity incident report: no payment made, law enforcement cooperation, the exposed-data list, and a preliminary $180–$400 million remediation estimate.
In a public blog post and customer letters, Coinbase says “We said no” and creates a $20 million reward fund for information leading to the attacker's arrest and conviction.
An Email Arrives: Pay $20 Million or We Publish
On May 11, 2025, Coinbase received an email from an unknown threat actor claiming to hold information about certain customer accounts and internal company documentation. According to the Form 8-K that Coinbase Global filed with the Securities and Exchange Commission, the message demanded money in exchange for not publicly disclosing the material, and Coinbase assessed it as credible.[1]
The data left the building through people with legitimate keys, not a cracked vault. The threat actor, Coinbase told the SEC, appears to have paid multiple contractors and employees in support roles outside the United States to copy information from internal systems they could already access for work. Coinbase's monitoring independently caught the improper accesses in the previous months, and the company says it immediately fired those involved and warned potentially affected customers.[1]
Criminals targeted our customer support agents overseas. They used cash offers to convince a small group of insiders to copy data in our customer support tools for less than 1% of Coinbase monthly transacting users.[3][4]— Coinbase, blog post quoted by The Record
Coinbase concluded the earlier accesses were one campaign that succeeded in taking data. Reporting filled the calendar: a Maine Attorney General notice reported by The Hacker News dated the incident to December 26, 2024 with 69,461 affected individuals, and Bloomberg-reported statements had Coinbase observing unusual agent activity as far back as January.[1][4]
What Was Copied — and What Coinbase Says Was Never Touched
The theft was intimate rather than cataclysmic. While still investigating, Coinbase listed what the copied data included: names, addresses, phone numbers and emails; masked Social Security numbers showing only the last four digits; masked bank-account numbers and some bank identifiers; images of government IDs such as driver's licenses and passports; balance snapshots and transaction history; and limited corporate material available to support agents.[1][2]
No passwords, private keys, or funds were exposed and Coinbase Prime accounts are untouched.[4]— Coinbase, quoted by The Hacker News
Coinbase repeated the negative side of that ledger everywhere it explained the incident. Its notification letter filed with the California Attorney General told customers the data did not include their password, seed phrase, private keys, or anything else allowing direct access to an account or funds, and that Coinbase Prime was untouched. Per company statements reported by The Record, the scheme also did not capture login credentials, two-factor codes, the ability to move or access customer funds, or access to cryptocurrency wallets.[2][3]
Why steal data that cannot move funds? Because, as the letter explained, attackers want it for social-engineering attacks — appearing credible enough to convince victims to move their own money. The filing drew the boundary: at no time, Coinbase stated, were the targeted contractors or employees able to access customer funds. Losses would come through deception, not a breached wallet.[2][1]
The footprint stayed narrow by the company's account: under 1% of monthly transacting users. The Record, citing The Block's figure of about 9.7 million such users in the first quarter of 2025, calculated that fewer than 100,000 people were likely affected. Separately, The Hacker News reported that a Maine filing listed 69,461 affected individuals. A Coinbase executive told Fortune the compromised agents worked in India and had all been fired.[3][4]
“We Said No”: Refusal Becomes a Manhunt
The email posed the extortion dilemma: pay quietly, or absorb the damage publicly and hunt. Coinbase's letter described the moment — after the insiders were fired and security tightened, a third party claimed access to customer data and attempted to extort a $20 million payment. The 8-K recorded the first half of the answer; the bounty completed it.[1][2]
The Company has not paid the threat actor’s demand and is cooperating with law enforcement in the investigation of this Incident.[1]— Coinbase Global, Inc., Form 8-K (May 14, 2025)
Then came the inversion. Instead of paying the $20 million ransom, Coinbase said it was creating a fund of the same size — a $20 million reward for information leading to the attacker's arrest and conviction, with tips directed to [email protected]. The demand and the bounty share one number and point in opposite directions.[2][3]
What these attackers were doing was finding Coinbase employees and contractors based in India who were associated with our business process outsourcing or support operations, that kind of thing, and bribing them in order to obtain customer data.[4]— Philip Martin, Coinbase Chief Security Officer, quoted by The Hacker News
The manhunt ran on several fronts. Coinbase said the insiders were fired on the spot, the case was referred to U.S. and international agencies, and it is pressing for criminal charges; with industry partners it tagged the attackers' addresses so authorities could track and attempt recovery. It also disputed, per Bloomberg-reported statements, the threat actor's claim that bribery bought “effectively on-demand access” to customer data over five months.[4][2]
The Cleanup Bill: $180 Million to $400 Million
Refusal had a price, and Coinbase labeled it preliminary. In the same filing, the company estimated expenses of roughly $180 million to $400 million for remediation and voluntary customer reimbursements — a figure it said could move meaningfully either way after further review, and one whose remedies it plans to pursue aggressively.[1]
Part of the bill is making customers whole. Coinbase said it intends to reimburse eligible retail customers who sent funds to the threat actor as a direct result of the incident, after confirming the facts. Flagged accounts, the letter added, now face additional ID checks on large withdrawals and mandatory scam-awareness prompts.[1][2]
The structural fixes aim at the root: outsourced support. Coinbase is opening a new support hub in the United States and says it has increased investment in insider-threat detection, automated response, and simulated attacks meant to find failure points in any internal system. Affected customers were offered a free year of IDX credit monitoring, including a $1,000,000 insurance reimbursement policy.[1][2]
The $40 Million Signal
The refusal landed at the moment Coinbase had never looked more established: its stock joined the S&P 500 that same week, and The Record noted a market capitalization of about $67 billion. One of the world's largest crypto exchanges chose to fight rather than pay at maximum visibility.[3]
Coinbase framed the stakes as trust, not money. “Crypto adoption depends on trust,” its letter told customers, before apologizing for the worry and inconvenience caused and warning that imposters — related to this breach or not — may pose as Coinbase employees and pressure people into moving their funds.[2][3]
The lasting lesson lives in the distinction the company kept repeating: data was exposed, while funds, by Coinbase's account, were not — the danger was deception, not drained wallets. The incident made insider access to support tooling a first-class security boundary, and it left a simple test: no legitimate Coinbase call asks for your password, your 2FA codes, or a transfer to a new address, account, vault or wallet.[1][3][2]
Key Takeaways for Investors & Builders
The perimeter moved inside
No system was cracked. Legitimate support access, copied by bribed humans, did the damage — so insider-threat detection, least-privilege tooling, and simulated insider attacks are now baseline exchange controls, exactly where Coinbase said it is investing.
Data breaches carry explicit price tags
Even a “no funds exposed” incident produced a preliminary $180–$400 million estimate for remediation and customer reimbursements in an SEC filing. For investors, data risk is quantifiable even when wallets are safe.
Refusal as strategy
Paying a ransom funds the next attack. Coinbase converted the $20 million demand into a $20 million bounty, treating trust — not secrecy — as the asset worth defending.
Connected Stories in this Universe
Explore the chain reaction of historical breakthroughs, blunders, and legends.

The 10,000 BTC Pizza: $700 Million at $70,000 per Bitcoin
How two pizzas turned 10,000 BTC into Bitcoin's most enduring real-world transaction story.
Read story →
The 100,000-Byte Blank Check: Bitcoin Core v30, OP_RETURN, and the Knots Rebellion
Core's 100,000-byte OP_RETURN default met Knots' 42-byte filter: a relay-policy war over spam and node choice that never touched consensus.
Read story →
One Prompt, $47,000: How p0pular.eth Out-Persuaded the Freysa AI Agent
How a public adversarial AI game on Base ended when one prompt tricked the Freysa agent into approving the transfer of its 13.19 ETH prize pool.
Read story →Sources & References
- [1]Source 1: Coinbase Global, Inc. Form 8-K — Material Cybersecurity Incident (Item 1.05), SEC EDGARU.S. Securities and Exchange Commission · 2025-05-14Accessed 2026-08-23
- [2]Source 2: Coinbase template individual notification letter — Notice of Data BreachCalifornia Attorney General data breach archive (Coinbase letter)Accessed 2026-08-23
- [3]Source 3: Coinbase offers $20 million bounty after extortion attempt with stolen dataThe Record from Recorded Future News (Joe Warminsky) · 2025-05-15Accessed 2026-08-23
- [4]Source 4: Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt FailsThe Hacker News (Ravie Lakshmanan) · 2025-05-15Accessed 2026-08-23