Share this article

Coinbase Multi-Factor Authentication Hack Affects at Least 6,000 Customers

A flaw allowed hackers to get customers’ SMS two-factor authentication code and break into their accounts.

Updated May 11, 2023, 7:07 p.m. Published Oct 1, 2021, 9:22 p.m.
(Shutterstock)

A vulnerability that allowed hackers to bypass Coinbase’s multi-factor authentication SMS option has affected at least 6,000 of the exchange’s customers, according to a notification letter sent to affected customers that the company has filed with the California state attorney general offices.

  • Between March and May 20, the hacker or hackers used a flaw in Coinbase’s account recovery process to get the SMS two-factor authentication token to break into customers’ accounts and transfer funds out of them.
  • The bad actor or actors also had access to the email address, password and phone number associated with each Coinbase account. Coinbase believes that the hacker stole those credentials through a phishing scheme and noted in its letter to the California AG that it has not found evidence of the hacker getting this information from Coinbase itself.
  • “We took immediate action to mitigate the impact of the campaign by working with external partners to remove phishing sites as they were identified, as well as notifying the email providers impacted,” a Coinbase spokesperson said via email. “Unfortunately we believe, although cannot conclusively determine, that some Coinbase customers may have fallen victim to the phishing campaign and turned over their Coinbase credentials and the phone numbers verified in their accounts to attackers.”
  • Coinbase said it is compensating customers for the stolen funds, but it’s unclear whether those payments are being made in fiat or crypto.
  • The exchange recommended that users switch to a more secure version of multi-factor authentication such as a hardware security key or authentication app.
  • This appears to be one of the largest breaches to have affected Coinbase. Other notable breaches included a password glitch in August 2019 that stored 3,500 customer passwords in plain text on an internal server log, although outside parties didn’t take advantage of the vulnerability. In the same month, Coinbase revealed the details of a sophisticated attack that was blocked by Coinbase but that resembled what would normally happen in a nation state-sponsored attack.
jwp-player-placeholder
STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Tether debuts federally regulated USAT stablecoin via Anchorage Digital

Tether CEO Paolo Ardoino at White House

The new token is issued by Anchorage Digital Bank and designed to comply with the GENIUS Act, targeting institutional demand for a U.S.-regulated digital dollar.

What to know:

  • USAT is purpose-built for the U.S. market, operating under the federal oversight of the Office of the Comptroller of the Currency (OCC) via issuer Anchorage Digital Bank.
  • Cantor Fitzgerald will serve as the reserve custodian, while the token launches with support from exchanges including Kraken, OKX, and Crypto.com.
  • Managed by CEO Bo Hines, USAT will coexist with Tether’s global USDT, marking the firm's formal entry into the U.S. domestic regulatory regime.