The turmoil over the security of cryptocurrency funds has resurfaced, with Coinbase accused of "covering up a $1 billion hacker attack."
Author: Zhou, ChainCatcher
The aftermath of the nearly $390 million theft from Bitget has not yet subsided, and a controversy surrounding Coinbase has once again brought exchange security back into the public spotlight.
On September 26, X user kuno posted that Coinbase locked his account a year ago, claiming he still owed $1.2 million, and demanded that Coinbase resolve the issue within 24 hours, or he would publicly disclose meeting recordings and resort to legal action.
Cobie, head of the Coinbase Base App, responded that no accounts matching the description were found and suspected this was an attempt to gain attention. He stated that there had been no response from the user to communications from Coinbase over the past six months, and that the incident was being used to promote a scam coin, appearing to be a completely false fraud report aimed at boosting interactions.

Subsequently, Ari Paul, founder of the crypto asset management firm BlockTower Capital, commented that Coinbase caused his company a loss of $25 million several years ago, later discovering that Coinbase had actually been covering up large-scale and repeated hacking incidents, with the related funds still not returned.
He stated that the team had tracked at least a dozen affected institutions, involving amounts exceeding $1 billion, but due to multiple ongoing legal proceedings, they could only disclose this information for now.

As of the time of publication, Ari Paul had not publicly disclosed verifiable evidence, and Coinbase had not made a public response. However, this accusation quickly spread within the community, with many users claiming they had also experienced financial losses on Coinbase. This is not unrelated to several security incidents Coinbase has faced over the past few years.
From SMS Vulnerabilities to Insider Threats: Coinbase's Old Issues
In early October 2021, Coinbase sent a data breach notification letter to some customers. According to the notice submitted to the California Attorney General's office, between March and May 20 of that year, at least 6,000 customer accounts were hacked.
The notice indicated that attackers needed to have prior knowledge of the victim's email, password, and phone number, and could log into their personal email to exploit a flaw in the Coinbase SMS account recovery process to obtain a two-factor verification code, allowing them to access the account and transfer funds.
A Coinbase spokesperson stated that the company had immediately fixed the vulnerability and assisted customers in recovering their accounts and compensating for losses. However, according to CNBC, before the notice was sent out, users had already complained about their accounts being emptied for months, and Coinbase faced criticism for its slow response.
Four years later, a similar time lag occurred again. On May 11, 2025, Coinbase received a ransom email, with the sender displaying internal information they had obtained, demanding $20 million for confidentiality.
Coinbase later disclosed in an official blog that criminals had bribed and recruited a group of overseas customer service personnel to steal customer data for social engineering attacks. According to their report submitted to the Maine Attorney General, approximately 69,500 customers were affected, with the leak beginning around December 26, 2024. Coinbase stated that passwords, private keys, funds, and Coinbase Prime accounts were not affected.
Coinbase refused to pay the ransom and instead set up a $20 million reward. According to documents submitted to the U.S. Securities and Exchange Commission, the estimated cost of this incident is between $180 million and $400 million.
CEO Brian Armstrong stated that the involved personnel had been fired at the time, but it was only now that these incidents were linked as part of the same attack. According to reports from Reuters citing insiders, Coinbase had known as early as January 2025 that an employee of the contractor TaskUs in India had taken photos of customer data on their work computer using a personal phone.
However, lawyer Ariel Givner pointed out on X that the ransom email was sent out on May 11, while Coinbase only notified users after deciding to refuse to pay the ransom.
Scams impersonating Coinbase did not stop there. According to the Brooklyn District Attorney's Office in New York, a local man named Ronald Spektor impersonated Coinbase customer service, claiming that user accounts had been hacked and assets were at risk, luring about 100 users to transfer their crypto assets into wallets he controlled, defrauding them of approximately $15.94 million. He pleaded guilty on September 2 and was sentenced to 4 to 12 years in prison on September 23.
Whether the scammed users can get their money back depends on Coinbase's determination. For users who were scammed in the 2025 incident, Coinbase promised compensation, but it requires case-by-case review to confirm that the losses are directly related to this leak.
If there are disputes between users and Coinbase, litigation is not so easy. One user sued Coinbase, claiming it did not conduct a timely and good-faith investigation into fraudulent transfers in the account, while Coinbase invoked the user agreement to demand mandatory arbitration. The U.S. Ninth Circuit Court of Appeals overturned the lower court's dismissal of the arbitration request in a December 2023 ruling, determining that the relevant clauses in the agreement were enforceable.
Looking back at these incidents, Coinbase's own processes indeed had vulnerabilities that were exploited. Although the incidents were ultimately disclosed and compensation promised, the disclosure process was indeed slow.
It remains unclear whether what Ari Paul referred to as covering up hacking attacks means that Coinbase's custody system was breached but not disclosed, or that Coinbase refused to compensate after accounts were hacked.
Hardware Wallets and Exchanges Continuously Hacked: How to Compensate?
In the second half of this year, security incidents in the crypto industry have noticeably increased. According to statistics from blockchain security company PeckShield, there were 50 major hacking incidents in August, a 67% increase from 30 in July, making it the month with the highest number of incidents this year.
However, the losses in August did not follow suit. The total losses for the month were approximately $136.3 million, a 49.5% decrease from about $270 million in July, with the average loss per incident dropping from about $9 million in July to about $2.7 million.
Entering September, the scale of individual incidents increased again, especially with the incidents involving Bitget and Liquid Network.
According to an incident report released by Blockstream, the technology provider for Liquid, a self-proclaimed white hat attacker withdrew about 4,000 bitcoins from the Liquid Network's federated wallet on September 6, which was worth approximately $320 million at the time, accounting for about 95% of the reserves.
The incident report from Liquid indicated that no private keys were leaked. The attacker exploited a vulnerability in Liquid's underlying open-source software, Elements, to generate about 4,000 L-BTC without reserve backing, and then exchanged them for real bitcoins through the normal withdrawal process.
After Blockstream confirmed the vulnerability was fixed, the attacker returned 3,400 bitcoins on September 7, with approximately 598.5 bitcoins still not returned, and demanded 10% of the bounty from Blockstream. Blockstream rejected this request, and CEO Adam Back publicly stated on September 10, when Liquid resumed block production, that the 1:1 peg of L-BTC to bitcoin would be guaranteed, with the shortfall covered by Blockstream.
However, a promise to cover losses does not mean that users have already recovered their funds. Liquid officially stated on September 17 that the withdrawal function remained suspended, and no further progress was announced thereafter.
More than two weeks later, Bitget also encountered issues. On the evening of September 24, Bitget's wallet began transferring assets to an unfamiliar address. On-chain tracking indicated a loss of approximately $387.5 million, making it the largest cryptocurrency theft incident of the year, and causing September to become the month with the highest amount stolen this year.
The attacker exploited a vulnerability in a third-party security product they were using to gain elevated access to the internal network, and the forged transactions were automatically released after passing through the normal approval process. Bitget CEO Gracy Chen stated that the attacker did not steal private keys, and Bitget suspects the attack originated from North Korean hackers.
Bitget officially stated that the losses would be fully covered by a protection fund held by users with 5,500 bitcoins, with withdrawals set to gradually resume from September 28, aiming for full recovery by October 2.
Beyond exchanges and sidechains, self-custody has not been spared either. At the end of July this year, hardware wallet Coldcard was reported to have firmware flaws, allowing some recovery phrases generated since 2021 to be calculated, resulting in users losing approximately 1,800 bitcoins, including those stored in bank safes and devices that had never been connected to the internet. According to Forbes, the manufacturer Coinkite is assisting victims in reporting to the police and applying for insurance claims, but has not offered compensation, and some victims are preparing for a class action lawsuit.
The Issue of Fund Security Resurfaces
Looking back at these incidents, where the money is stored leads to very different outcomes when problems arise.
Funds stored in centralized exchanges depend on whether the platform is prepared for compensation after a breach. Those with protection funds can fully cover losses, but if the fund is valued in crypto assets, its value will also fluctuate with the market. Compensation for scammed users often requires case-by-case review, and if disputes arise, they may be pushed toward arbitration.
Even if the operators promise to cover losses, users may not be able to quickly retrieve their funds. Before the promise is fulfilled, assets may remain frozen for a long time.
Choosing a hardware wallet for self-custody allows users to break free from reliance on platforms, but also takes on the risks associated with the devices and supply chains. Even with correct operations, if the manufacturer's firmware has defects, losses often have to be borne by the user or pursued through litigation.
Attacks such as impersonating customer service and bribing insiders target people, and cannot be avoided regardless of where the assets are stored.
Regarding how assets should be stored, there has been a long-standing debate in the industry. In August of this year, Ari Paul commented on the theft of Coldcard, stating that whether self-custody or third-party custody, cryptocurrency assets cannot be secured. In most developed countries, the legal system's protection of assets is far more reliable than cryptography.
ShapeShift founder Erik Voorhees countered that no asset is absolutely safe, and every storage method has its trade-offs. The key is that users can choose independently and take responsibility for their choices.
Solana Labs co-founder toly believes that cryptocurrency assets have various uses. If they are for investment, they should be entrusted to a custody institution; if they are to guard against extreme situations, then they are a cost rather than an investment, and one should consider researching cold storage. The two should not be confused.
Now, Ari Paul has turned his attention to Coinbase. Whether this accusation holds water will depend on evidence and legal proceedings. However, this controversy consistently presents a question to every holder: when every choice has a cost, where should your money be placed?













