8-KOther EventsExhibits & Filings

Coinbase Global, Inc. 8-K Report, Cybersecurity Incident (May 15, 2025)

Filed May 15, 2025For Securities:COIN

Summary

Coinbase Global, Inc. (COIN) has disclosed a material cybersecurity incident via an 8-K filing on May 14, 2025, detailing a campaign initiated by an external threat actor. The incident involved contractors or employees outside the U.S. gaining unauthorized access to internal systems to extract customer data and internal documentation. While passwords and private keys were not compromised, and customer funds remained secure, the breach exposed customer names, addresses, phone numbers, emails, masked Social Security numbers, masked bank account information, government ID images, and account data. Coinbase has terminated the involved personnel, enhanced fraud monitoring, and is notifying affected customers. The company intends to reimburse eligible retail customers who may have lost funds directly due to the incident. A preliminary estimated range for remediation costs and voluntary customer reimbursements is between $180 million and $400 million, excluding potential further losses or recoveries. The company is also relocating support functions to the U.S. to bolster defenses.

Key Highlights

  • 1Material cybersecurity incident involving unauthorized access to customer and internal data by contractors/employees.
  • 2Customer funds and private keys were not compromised.
  • 3Exposed data includes PII (name, address, email, phone), masked SSN and bank details, government ID images, and account information.
  • 4Coinbase to reimburse eligible customers who lost funds directly as a result of the incident.
  • 5Preliminary estimated costs for remediation and reimbursements range from $180 million to $400 million.
  • 6Coinbase is cooperating with law enforcement and taking steps to enhance security, including establishing a U.S.-based support hub.
  • 7The full financial impact is still under assessment and could exceed the preliminary estimate.

Frequently Asked Questions

No, the filing explicitly states that customer funds and private keys were not compromised. The incident involved unauthorized access to customer information and internal documentation, not direct access to customer assets.

The accessed information includes customer names, addresses, phone numbers, and emails. It also includes masked Social Security numbers (last 4 digits only), masked bank account numbers and some identifiers, images of government IDs (like driver's licenses and passports), and account data such as balance snapshots and transaction history. Limited corporate data was also obtained.

Coinbase has provided a preliminary estimated range of $180 million to $400 million for remediation costs and voluntary customer reimbursements. However, the company notes that this estimate excludes potential further losses, indemnification claims, and recoveries, meaning the ultimate financial impact could be higher or lower.

Coinbase has terminated the personnel involved, implemented heightened fraud monitoring, is notifying affected customers, and intends to reimburse eligible customers for direct losses. They are also establishing a new support hub in the United States to strengthen defenses and are cooperating with law enforcement in the investigation.