Coinbase said a former customer support agent was arrested in India as investigators probe a breach tied to insider bribery and customer data theft. Chief ExecutiveCoinbase said a former customer support agent was arrested in India as investigators probe a breach tied to insider bribery and customer data theft. Chief Executive

Coinbase claims arrest in the $355 million insider extortion scheme that targeted nearly 70,000 customers

2025/12/29 02:45
5 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Coinbase said a former customer support agent was arrested in India as investigators probe a breach tied to insider bribery and customer data theft.

Chief Executive Officer Brian Armstrong said on Dec. 27 that the arrest involved a former support agent and thanked Hyderabad Police for assistance in the ongoing investigation.

The update puts attention on the operational side of exchange security, including who can access support tooling, how exceptions are handled, and how outsourced teams are supervised.

Brian Armstrong CEO & Co-Founder Coinbase
View Profile

Those areas can shape regulatory expectations and risk pricing in 2026

Coinbase has described the incident to regulators as an extortion attempt built on insider access.

In a May 14 filing, the company said it received an email demanding payment and claiming the sender had obtained customer information and internal documents, according to the SEC.

Coinbase said the information was taken from systems used for customer support and account management.

The company added that the stolen data was used to conduct social engineering attempts against customers.

Public filings provide a timeline and a specific headcount.

A state notification filed in Maine listed the breach date as Dec. 26, 2024, with insider wrongdoing discovered May 11, 2025, and reported 69,461 affected people, according to the Maine Attorney General’s office.

Reuters has also reported that the U.S. Department of Justice opened an investigation into the incident earlier in 2025, adding federal scrutiny to the company’s response and controls.

The company has tied the event to remediation work and reimbursements for customers who lost funds after being targeted.

Coverage of Coinbase’s disclosure referenced a company estimate of $180 million to $400 million in costs tied to remediation and voluntary reimbursements.

Coinbase’s Q3 2025 shareholder letter recorded $48 million in “data theft incident” costs in Q3 after $307 million in Q2, for $355 million recognized across the two quarters.

The $355 million total equals about 89% of the $400 million top end of that range, a datapoint investors have used to gauge how much of the guided amount has already flowed through earnings.

Timeline and cost checkpointsDetail
Breach dateDec. 26, 2024
Insider wrongdoing discoveredMay 11, 2025
SEC material incident filingMay 14, 2025
Affected people69,461
Company cost estimate$180 million–$400 million
Costs recognized in earnings$307 million (Q2 2025) + $48 million (Q3 2025) = $355 million

The mechanism described in the SEC filing shifts attention from custody technology toward identity, access, and human workflows.

Coinbase said support personnel were bribed or recruited to access internal tooling and pull customer information, creating conditions for impersonation attempts and account takeovers.

Even when private keys and on-chain infrastructure are not directly compromised, a compromised support channel can function as a distribution point for fraud.

Victims may treat inbound calls, emails, or chat messages as authentic when they appear to come from an exchange.

Breach research outside crypto is converging on the same exposure: third parties

Verizon’s 2025 Data Breach Investigations Report said third-party involvement in breaches doubled to 30% globally.

For exchanges that rely on contractors and outsourced teams, the operational answer is measurable controls around access scope and oversight.

That includes least-privilege design, session monitoring, privileged access reviews, and stronger out-of-band verification for high-risk account changes.

The incident also fits into a 2025 crime mix where theft and scams scale through social engineering.

Chainalysis reported more than $2.17 billion stolen in the first half of 2025 and said the pace could reach as much as $4 billion for the year.

In the Coinbase case, the SEC filing lays out a repeatable sequence: data taken from internal systems, a plausible impersonation surface, then targeted outreach to users.

U.S. prosecutors have described how that sequence plays out at the victim level.

The Brooklyn District Attorney’s Office said a 23-year-old was indicted in a phishing and social engineering scheme that stole nearly $16 million from about 100 Coinbase users.

Prosecutors described impersonation of Coinbase representatives and laundering through swaps, mixers, and gambling services.

Coinbase separately wrote that it worked with the Brooklyn DA in that matter as part of supporting victims and assisting prosecutors, according to Coinbase.

Regulatory frameworks in Europe and the U.K.

EU rules under the Digital Operational Resilience Act emphasize ICT risk controls and oversight of contracted providers, including dependency management for critical services, according to Baker McKenzie.

In the U.K., the Financial Conduct Authority’s consultation work on how handbook requirements apply to regulated cryptoasset activities discusses operational and technology risks and resilience expectations, according to Regulation Tomorrow.

For market participants holding liquid tokens rather than exchange equity, the immediate transmission channel is behavior around custody and access to fiat rails.

Incidents rooted in impersonation and account access can push users to split balances across venues and move more assets into self-custody.

That can thin order books at the margin for less liquid assets and shift where retail volume routes.

Coinbase’s Q3 2025 shareholder letter said operating expenses increased in part due to customer service and global compliance efforts, positioning fraud prevention and support operations as recurring cost centers rather than episodic work.

Armstrong said Coinbase is continuing to work with law enforcement, including Brooklyn District Attorney’s Office.

The post Coinbase claims arrest in the $355 million insider extortion scheme that targeted nearly 70,000 customers appeared first on CryptoSlate.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
Ripple Concludes 700 Million XRP Escrow Lock for March

Ripple Concludes 700 Million XRP Escrow Lock for March

The post Ripple Concludes 700 Million XRP Escrow Lock for March appeared on BitcoinEthereumNews.com. XRP reacts with mild price surge  Ripple to relock 700 million
Share
BitcoinEthereumNews2026/03/04 05:34