Coinbase Promises to Deposit Stolen Funds to At Least 6,000 Hacked Accounts

2021-10-4 18:08

Cryptocurrency exchange Coinbase, which has about 68 million users globally, disclosed this week that hackers stole from at least 6,000 of its customers.

According to a breach notification letter sent by the exchange to affected customers, hackers used a vulnerability to bypass Coinbase’s SMS multi-factor authentication security feature.

The attack took place between late April and early May this year, as per the copy of the letter posted on the website of California’s Attorney General. By exploiting a flaw in the company's SMS account recovery process, unauthorized third parties gained access to the accounts and then transferred the funds to outside crypto wallets.

“We immediately fixed the flaw and have worked with these customers to regain control of their accounts and reimburse them for the funds they lost,” a Coinbase spokesperson said on Friday.

The company said to successfully attack, hackers needed to have email addresses, passwords, and phone numbers associated with the affected accounts along with having access to the victim’s email account. But said there was no evidence to suggest the information was obtained from the company.

While it is not yet known just how the attackers gained access to all the information, Coinbase believes it was through phishing campaigns that attackers stole customers’ account credentials.

But even if a hacker has access to customers’ email accounts and credentials, they would still be prevented from logging into an account if multi-factor authentication has been enabled.

Here, Coinbase noted that due to a vulnerability that existed in their SMS account recovery process, it allowed the hackers to gain the SMS two-factor authentication needed to access a secured account.

Due to the fact that it was a bug in Coinbase’s SMS Account Recovery process allowing threat actors access to accounts, the exchange is depositing funds in affected accounts equal to the stolen amount.

“We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed — we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today.”

The post Coinbase Promises to Deposit Stolen Funds to At Least 6,000 Hacked Accounts first appeared on BitcoinExchangeGuide.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Safe Exchange Coin (SAFEX) на Currencies.ru

$ 0.0054306 (-0.25%)
Объем 24H $1.742k
Изменеия 24h: 1.41 %, 7d: -8.63 %
Cегодня L: $0.0053635 - H: $0.0055227
Капитализация $6.099m Rank 99999
Доступно / Всего 1.123b SAFEX

coinbase customers least hackers exchange breach notification

coinbase customers → Результатов: 126


Coinbase Opens Wire Transfers, OTC Trading and Custody Services for Select Customers in Asia and Europe

The American based cryptocurrency exchange of Coinbase has opened cross-border wire transfers for high volume traders in the two continents of Asia and Europe. Making the announcement earlier today, the exchange explained that the service will be available to customers with high-volume trading on Coinbase Pro and Prime.

2019-1-22 17:22


The Daily: Akon introduces A

Additional stories include an ICO mogul who bought land worth $19 million with bitcoin, a massive trove of Coinbase customers’ complaints and more. Also Read: Control of Highly Demanded Crypto Classes May Spark Turf War at Universities Akon Launches Akoin Akon, the Senegalese-American singer, is launching his own cryptocurrency token called Akoin. ICO Mogul Buys

2018-6-21 16:45