Editorial draft v2 · Evidence reader R1 · Evidence cutoff: May 7, 2026

Disclosures covered: The May 15, 2025 incident disclosure in an issuer-distributed filing representation, and Coinbase's May 7, 2026 first-quarter results release.

Coinbase said a data-theft campaign used access held by overseas support personnel and led to an extortion demand in May 2025. Its initial account paired a description of affected customer information with a preliminary $180 million–$400 million remediation and reimbursement estimate. A later financial release reported period-specific net losses and recoveries for the same incident. Those later accounting measures are distinct from the initial estimate and from money demanded by an attacker. Incident disclosure · Later financial release

How Coinbase connected the activity

On May 11, 2025, Coinbase Inc., the parent's subsidiary, received an email from an unknown actor claiming to hold customer-account information and internal customer-service and account-management documentation. The actor demanded payment to prevent public disclosure. Coinbase assessed the email as credible and connected earlier improper access to one campaign that had succeeded in taking internal data. The filing's report header is May 14 and its signature is May 15; neither changes the stated May 11 email date. Incident disclosure

According to Coinbase, the actor appeared to have paid multiple contractors or employees in support roles outside the United States to collect information available through their legitimate job access. Security monitoring had independently detected instances of access without a business need during the preceding months. Coinbase said it terminated those personnel, heightened fraud monitoring, and warned potentially affected customers. It had not paid the actor's demand and was cooperating with law enforcement. The payment-to-personnel explanation remains the company's assessment; the selected source does not independently prove it or identify a named actor. Incident disclosure

Information taken and response measures

The affected information included names and contact details; Social Security numbers masked to the last four digits; masked bank-account numbers and some bank identifiers; government-ID images; balance snapshots and transaction histories; and limited corporate material accessible to support agents. Coinbase said passwords and private keys were not compromised and that the targeted personnel could not access customer funds. The investigation was ongoing, and the disclosure did not supply an exact affected-customer count. Incident disclosure

Coinbase was strengthening anti-fraud protections against social engineering using the compromised information. It intended to reimburse eligible retail customers who had sent funds to the actor as a direct result of the incident, after reviewing the facts. That conditional reimbursement policy describes a different circumstance from support personnel directly accessing customer funds. The company also said it was opening a United States support hub and taking further defensive measures. Incident disclosure

The preliminary estimate and subsequent quarter measures

As of the initial disclosure, Coinbase reported no material operational impact, while the financial assessment remained incomplete. It preliminarily estimated approximately $180 million–$400 million in remediation costs and voluntary customer reimbursements. Potential losses, indemnification claims, and recoveries could meaningfully increase or decrease that estimate. It was not a final expense amount, an annual loss range, or a disclosed ransom payment. Incident disclosure

The May 7, 2026 release's Adjusted EBITDA reconciliation separately presented Data Theft Incident losses (recoveries), net, in millions of dollars, for the quarters below. Its footnote expressly connected the row to the incident disclosed May 15, 2025. Later financial release

PeriodNet losses (recoveries), USD millions
Q1 2025—
Q2 2025306.7
Q3 202548.0
Q4 2025(9.5)
Q1 20268.6

The Q4 2025 (9.5) entry represents USD 9.5 million of net recoveries, displayed negatively in the losses/(recoveries) line. The footnote says the row includes voluntary reimbursements, direct legal costs, and reward payments, if any, associated with an actor's arrest and conviction. That conditional wording does not establish that a reward was paid or that an arrest and conviction occurred. The net row also does not identify insurance or cash recoveries. This article does not add the quarters into a new total or treat them as proof of a final lifetime incident cost. Later financial release

Editorial interpretation: the sequence distinguishes a forecast made during an open investigation from later reported financial measures. It also keeps data access, social-engineering risk, and direct access to customer funds separate. The sources do not settle the full customer population, independently verify the actor's identity, or provide a final resolution of all incident consequences. Incident disclosure · Later financial release

Sources

  • Incident disclosure — May 15, 2025; email May 11; report header May 14.

  • Financial release — May 7, 2026; first-quarter results for the period ended March 31, 2026, with earlier-quarter comparisons.

Disclosure history

Article draft version 2 · Evidence reader revision 1 · Evidence cutoff May 7, 2026, 12:00 AM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • Coinbase Publisher posted May 15, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 9:36 PM UTC · Retained Oct 7, 2026, 9:36 PM UTC
    • Issuer-published hosted/converted HTML filing representation, not native SEC acquisition or established EDGAR byte equivalence.
    • May15 is issuer-listed posting/filing date; report/event dateMay14 must be retained distinctly.
    • Current representation cannot establish historical exact bytes.
  • Coinbase Publisher posted May 7, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:49 PM UTC · Retained Oct 7, 2026, 7:49 PM UTC
    • Current issuer-published representation; historical exact bytes are unknown.
    • Independent publisher HTTPS origin; not native SEC acquisition, no EDGAR byte-equivalence established.
    • Frozen issuer CIK is subject association only; SEC filing/accession fields remain unavailable on this public-source record.