Coinbase Sets Out How It Foiled a 'Sophisticated' Hacking Attack
Cryptocurrency exchange Coinbase has detailed how it was targeted by, and foiled, "a sophisticated, highly targeted, thought out attack."

Cryptocurrency exchange Coinbase has described how it was targeted by, and foiled, "a sophisticated, highly targeted, thought out attack" aimed to access its systems and presumably to make off with some of the billions of dollars'-worth of cryptocurrency it holds.
In an Aug. 8 blog post that sets out in technical detail how the plot unfolded and how the exchange countered the attempted theft, Coinbase said the hackers used a combination of means to try and hoodwink staff and access vital systems – methods that included spear phishing, social engineering and browser zero-day exploits.
The attack had started on May 30, with a dozen staff being sent emails that purported to be from Gregory Harris, a Research Grants Administrator at the University of Cambridge. Far from random, these cited the employees' past histories and requested help with judging projects competing for an award.
Coinbase said:
"This email came from the legitimate Cambridge domain, contained no malicious elements, passed spam detection, and referenced the backgrounds of the recipients. Over the next couple weeks, similar emails were received. Nothing seemed amiss."
The attackers developed email conversations with several staffers, holding back from sending any malicious code until June 17, when "Harris" sent another email, containing a URL that, when opened in Firefox, would install malware capable of taking over someone’s machine.
Coinbase said that, "within a matter of hours, Coinbase Security detected and blocked the attack."
The first stage of the attack, the post indicates, first identified the OS and browser on the intended victims' machines, displaying a "convincing error" to macOS users who were not using the Firefox browser, and prompting them to install the latest version of the app.
Once the emailed URL was visited with Firefox, the exploit code was delivered from a different domain, that had been registered on May 28. It was at this point that the attack was identified, "based on both a report from an employee and automated alerts," Coinbase said.
Its analysis found that stage two would have seen another malicious payload delivered in the form of a variant of the Mac-targeting backdoor malware called Mokes.
Coinbase explained that there had been two separate Firefox zero-day exploits utilized in the attack: "one that allowed an attacker to escalate privileges from JavaScript on a page to the browser (CVE-2019–11707) and one that allowed the attacker to escape the browser sandbox and execute code on the host computer (CVE-2019–11708)."
Notably, the former was discovered by Samuel Groß of Google’s Project Zero at the same time as the attacker, though Coinbase played down the likelihood that the hacking team had gained the information on the vulnerability via that source. Groß addresses that in a Twitter thread.
In another sign of the sophistication of the hacking team – labeled by Coinbase as CRYPTO-3 or HYDSEVEN – it took over or created two email accounts and created a landing page at the University of Cambridge.
Coinbase said:
"We don’t know when the attackers first gained access to the Cambridge accounts, or whether the accounts were taken over or created. As others have noted, the identities associated with the email accounts have almost no online presence and the LinkedIn profiles are almost certainly fake."
After discovering the single affected computer at the company, Coinbase said it revoked all credentials on the machine, and locked all the staffer's accounts.
"Once we were comfortable that we had achieved containment in our environment, we reached out to the Mozilla security team and shared the exploit code used in this attack," the exchange said. "The Mozilla security team was highly responsive and was able to have a patch out for CVE-2019–11707 by the next day and CVE-2019–11708 in the same week."
Coinbase also contacted Cambridge University to report and help fix the issue, as well as to gain more information on the attacker’s methods.
Coinbase concluded:
"The cryptocurrency industry has to expect attacks of this sophistication to continue, and by building infrastructure with excellent defensive posture, and working with each other to share information about the attacks we’re seeing, we’ll be able to defend ourselves and our customers, support the cryptoeconomy, and build the open financial system of the future."
Coinbase CEO Brian Armstrong via CoinDesk archives
More For You
KuCoin Hits Record Market Share as 2025 Volumes Outpace Crypto Market

KuCoin captured a record share of centralised exchange volume in 2025, with more than $1.25tn traded as its volumes grew faster than the wider crypto market.
What to know:
- KuCoin recorded over $1.25 trillion in total trading volume in 2025, equivalent to an average of roughly $114 billion per month, marking its strongest year on record.
- This performance translated into an all-time high share of centralised exchange volume, as KuCoin’s activity expanded faster than aggregate CEX volumes, which slowed during periods of lower market volatility.
- Spot and derivatives volumes were evenly split, each exceeding $500 billion for the year, signalling broad-based usage rather than reliance on a single product line.
- Altcoins accounted for the majority of trading activity, reinforcing KuCoin’s role as a primary liquidity venue beyond BTC and ETH at a time when majors saw more muted turnover.
- Even as overall crypto volumes softened mid-year, KuCoin maintained elevated baseline activity, indicating structurally higher user engagement rather than short-lived volume spikes.
More For You
Crypto ETFs with staking can supercharge returns but they may not be for everyone

From yield potential to custody risks, here’s how direct ETH and staking funds compare for different investor goals.
What to know:
- Investors can now choose between owning ether directly or buying shares in a staking ETF that earns rewards on their behalf.
- While staking ETFs offers yield, they come with risks and less control than holding ETH in an exchange or wallet.
- Grayscale’s Ethereum staking ETF recently paid $0.083178 per share, yielding $3.16 in rewards on a $1,000 investment.











