Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

South Africa’s Aggressive New Capital Flow Rules

April 25, 2026

Humanity Protocol up 80% from April lows: Can bulls keep H rising?

April 25, 2026

Bitcoin might be at risk from a new quantum math trick that breaks digital ownership

April 25, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Coinbase Attackers Bypassed Account Authentication
Coinbase Attackers Bypassed Account Authentication
Security and Privacy

Coinbase Attackers Bypassed Account Authentication

July 7, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

US cryptocurrency exchange Coinbase is facing a backlash from its users after notifying them that at least 6,000 customers had their funds stolen by hackers.

The “third-party campaign” took place between March and May 20, 2021.

“In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox,” the firm explained in a breach notification letter.

“While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks or other social engineering techniques to trick a victim into unknowingly disclosing login credentials to a bad actor. We have not found any evidence that these third parties obtained this information from Coinbase itself.”

However, while Coinbase does not appear to have been responsible for the initial data leak, which enabled the first stage of the attack, a crucial flaw in its authentication process was to blame for the unauthorized account access.

“Even with the information described above, additional authentication is required in order to access your Coinbase account,” it continued.

“However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.”

Coinbase, the world’s second-largest cryptocurrency exchange with tens of millions of global users, said it would reimburse customers the full value of their losses. The firm has also updated its SMS Account Recovery protocols to ensure authentication can’t be bypassed in a similar way in the future.

See also  Coinbase Made an Arbitration Case to the U.S. Supreme Court – Again

However, it warned that, while inside hacked accounts, unauthorized third parties would have access and potentially changed details. These details include full name, email and home address, date of birth, IP address for account activity, transaction history, account holdings and balance.

This isn’t the first time Coinbase has been in the news following a security breach. In 2019 it was forced to halt trading of Ethereum Classic (ETC) after spotting “double spend” attacks totalling more than $1m.

Hacked Coinbase accounts are said to be worth as much as $610 apiece on the cybercrime underground.

Source link

Account Attackers Authentication Bypassed Coinbase
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

April 24, 2026

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026

New York Attorney General Sues Coinbase, Gemini Over Unlicensed Prediction Markets

April 23, 2026

New York sues Coinbase, Gemini over prediction market offerings

April 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Crypto Exec Pushing for Industry Support of Kamala Harris for U.S. President

August 1, 2024

Slovenia Sell $32.5M Digital Bond Through Digital Ledger Technology (DLT) and Tokenization

July 29, 2024

Tether And USDC To Face The Heat After Hong Kong’s Strict Stablecoin Regulation

January 1, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

South Africa’s Aggressive New Capital Flow Rules

April 25, 2026

Humanity Protocol up 80% from April lows: Can bulls keep H rising?

April 25, 2026

Bitcoin might be at risk from a new quantum math trick that breaks digital ownership

April 25, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,563.00-0.64%
  • ethereumEthereum(ETH)$2,313.99-0.26%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.43-0.27%
  • binancecoinBNB(BNB)$634.13-0.49%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$86.370.24%
  • tronTRON(TRX)$0.323058-1.46%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.48%
  • dogecoinDogecoin(DOGE)$0.0978990.02%