At this point I would not trust Coinbase, their engineering department shows that they have very little clue when it comes to building a secure infrastructure. Not only they are not rate limiting and leaking names, their implementations are simply laughable. With a proper design, customer should have been allowed to either enable/disable that end-point when somebody is searching for their email, or there should have…
Almost any site that has a password reset can be used to verify whether an email account exists in that system - depending if the system tells you "no user with that username exists" or not. Coinbase is in no way unique with the amount of info they expose, which is the point they were trying to make on their "official" response.
I would have liked to see them announce that the API does have some sort of throttle and maybe they are going to think of ways to enable an option for this behavior or something - basically anything except to just dismiss it. Because even though I personally agree with them as far as the level of vulnerability - a lot of people don't and Coinbase doesn't seem to understand this perception problem.