Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

11–20 of 287 posts

Re: Coinbase Breach Notification

#11

> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > ac…

Not necessarily. You can collect information such as username, passwords, phone numbers from leaked databases and then attempt to login via Coinbase. Some might have 2FA, so they might even go as far as to sim swap them given that they know their phone number.

So it doesn’t necessarily mean they got it from Coinbase.

Re: Coinbase Breach Notification

#12
post #10
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

In the linked PDF, Coinbase does not claim to have knowledge of a vulnerability in their system (edit: though it does note "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process," I interpreted that as "we supported SMS account recovery at all" which is inherently broken [0]). The requisite two-factor bypass is detailed in the linked pdf:

> Even with the information described above, additional authentication is required in order to access your Coinbase account. However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.

My guess is, because funds were stolen from users' accounts, the CA breach notification laws apply and this needed to be disclosed as such. However, that doesn't necessarily mean that Coinbase was technically "breached," only that customer accounts were compromised.

If the attacker controls your personal email associated with Coinbase, accompanying passwords, and phone number, and you use SMS 2FA, then your funds were stolen. Otherwise, they were safe. That's my reading of the article.

[0]: https://krebsonsecurity.com/2019/08/who-owns-your-wireless-s...

Re: Coinbase Breach Notification

#13
From what I understand, the SMS verification was bypassed but not the password validation.

I am probably not understanding this correctly, but if the attacker had to have knowledge of your password then why did they reimburse affected users. They could've called it a day and claimed it was the user's fault.

Re: Coinbase Breach Notification

#14

> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > ac…

I don't see the conflict with those statement. They're saying "we don't know where the information came from and we haven't found any evidence that it came from Coinbase itself".

It's difficult to prove a negative here until you find where the stolen credentials originated from. They're just saying that they have no evidence that it came from themselves thus far.

Re: Coinbase Breach Notification

#15
post #5

What can be said that has not already? It's like people saying, "I don't like the bank with their ridiculous paperwork so I will use a loan shark instead, he doesn't need paperwork" Then the loan shark disappears/beats you up/asks for loads of interest etc. and you still want to complain to the police. Most people hate regulators but they are there for a reason. What certifications does coinbase have to hold your mil…

[deleted]

Re: Coinbase Breach Notification

#16
post #8

In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the informatio…

Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process.

At least they will be reimbursed, and everyone should walk happy.

Re: Coinbase Breach Notification

#17
post #12
post #10

Earlier quoted context omitted.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

In the linked PDF, Coinbase does not claim to have knowledge of a vulnerability in their system (edit: though it does note "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process," I interpreted that as "we supported SMS account recovery at all" which is inherently broken [0]). The requisite two-factor bypass is detailed in the linked pdf: > Even with the information described above, addi…

[deleted]

Re: Coinbase Breach Notification

#18
>"We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today."

I sympathize with the "Not your keys, not your coins" crowd, but you have to admit that you are far more likely to be compensated in the event of an attack if you are using a large exchange. Not guaranteed, of course, but Coinbase has an image to maintain.

I also believe, personally, that a large exchange has much better security than anything I could muster with a hot wallet. Yes, I know I can airgap a cold wallet but I like the ability to quickly sell some amount of crypto at market rates without having to transfer from a paper wallet. I also worry about physical security since my home has been burglarized before. Therefore, I keep my coins on exchanges and follow good practices with 2FA across my accounts (no SMS for any) and have withdrawal delays / whitelisting active.

Re: Coinbase Breach Notification

#19

> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > ac…

How? Those statements seem entirely consistent and reasonable to me. They have no evidence or reason to believe that the information was stolen from Coinbase, but beyond that they don't know how attackers got it.

Your car was stolen. I haven't been able to determine conclusively who did steal it or how, but I know it wasn't me.

Re: Coinbase Breach Notification

#20
post #5

What can be said that has not already? It's like people saying, "I don't like the bank with their ridiculous paperwork so I will use a loan shark instead, he doesn't need paperwork" Then the loan shark disappears/beats you up/asks for loads of interest etc. and you still want to complain to the police. Most people hate regulators but they are there for a reason. What certifications does coinbase have to hold your mil…

Coinbase is not an unregulated free-for-all. They are licensed in all 50 states, and is registered as an MSB with FinCEN.

https://www.coinbase.com/legal/licenses

Post reply on HN