Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

21–30 of 287 posts

Re: Coinbase Breach Notification

#21
post #10
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

It doesn't matter who techinically is at fault Coinbase wants to stay ahead of the potential bad press and people pulling all their funds from the platform. Probably just figured this was cheaper.

Re: Coinbase Breach Notification

#22

From what I understand, the SMS verification was bypassed but not the password validation. I am probably not understanding this correctly, but if the attacker had to have knowledge of your password then why did they reimburse affected users. They could've called it a day and claimed it was the user's fault.

[deleted]

Re: Coinbase Breach Notification

#23
post #12
post #10

Earlier quoted context omitted.

> had to perform a "SIM swap" type attack on the users. source? I kind of doubt that's something coinbase would call a flaw in their system?

In the linked PDF, Coinbase does not claim to have knowledge of a vulnerability in their system (edit: though it does note "the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process," I interpreted that as "we supported SMS account recovery at all" which is inherently broken [0]). The requisite two-factor bypass is detailed in the linked pdf: > Even with the information described above, addi…

They also say "we updated our SMS Account Recovery protocols to prevent any further bypassing of that authentication process". What did they update if it wasn't due to a weakness on their side?

EDIT: on reading some of their docs, recovery is supposed to be followed by the user submitting ID documents etc before they get full access back - maybe that's the part they didn't do before or that could somehow be circumvented? (which is a flaw, but still requires intercepting the SMS to use?)

Re: Coinbase Breach Notification

#24
I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well.

I'll guess the users had the same usernames and passwords that they've used for a hundred other sites, and one of those got breached at some point. Don't do that!

Re: Coinbase Breach Notification

#25

From what I understand, the SMS verification was bypassed but not the password validation. I am probably not understanding this correctly, but if the attacker had to have knowledge of your password then why did they reimburse affected users. They could've called it a day and claimed it was the user's fault.

Goodwill generated + money saved by avoiding lawsuits > reimbursement costs

Re: Coinbase Breach Notification

#26

I think this reflects very favorably on Coinbase. They're making everyone whole, and gosh - the attackers had the user's usernames, passwords and phone numbers. Hard not to be sympathetic to Coinbase in that scenario. How are they supposed to know those aren't the real users? Consider that if they are going to identify those cases as fraudulent actors, then they could easily lock-out legitimate users as well. I'll gu…

[deleted]

Re: Coinbase Breach Notification

#27

From what I understand, the SMS verification was bypassed but not the password validation. I am probably not understanding this correctly, but if the attacker had to have knowledge of your password then why did they reimburse affected users. They could've called it a day and claimed it was the user's fault.

If trad banks did that, people would riot.

Re: Coinbase Breach Notification

#28
post #16
post #8

In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox. While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks ... Even with the informatio…

Well, it's not like Coinbase should be blamed for all of it. It's a combination of their customer's poor hygiene + a flaw in Coinbase’s SMS Account Recovery process. At least they will be reimbursed, and everyone should walk happy.

Anyone care to speculate what the flaw in their SMS recovery flow actually was? It's hard for me to think there's even a safe way to implement SMS based account recovery. They would be smarter to just turn it off.

Re: Coinbase Breach Notification

#29

> Unfortunately, between March and May 20, 2021, you were a victim of a third-party campaign to gain > unauthorized access to the accounts of Coinbase customers and move customer funds off the Coinbase > platform. At least 6,000 Coinbase customers had funds removed from their accounts, including you. I see 2 conflicting claims here: > While we are not able to determine conclusively how these third parties gained > ac…

Phishing or malware would be obvious avenues for someone to gain this information not from Coinbase itself.

If people reused passwords, they also could potentially have cobbled together 6000 valid username/password/phone combinations from previous hacks of other services.

Re: Coinbase Breach Notification

#30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.
Post reply on HN