Disclosures and evidence

Revision 1 of 1 · Evidence cutoff May 7, 2026, 12:00 AM UTC

0 prior statements preserved · 24 statements added. Attributed source statements retain the source’s qualifications.

What the company disclosed

  1. Coinbase stated: “On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase Global, Inc. (“Coinbase” or the “Company”), received an email communication from an unknown threat actor claiming to have obtained information about certain Coinbase customer accounts, as well as internal Coinbase documentation, including materials relating to customer-service and account-management systems. The communication demanded money in exchange for not publicly disclosing the information. The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities. These instances of such personnel accessing data without business need were independently detected by the Company’s security monitoring in the previous months. Upon discovery, the Company had immediately terminated the personnel involved and also implemented heightened fraud-monitoring protections and warned customers whose information was potentially accessed in order to prevent misuse of any compromised information. Since receipt of the email, the Company has assessed the email to be credible, and has concluded that these prior instances of improper data access were part of a single campaign (the “Incident”) that succeeded in taking data from internal systems. The Company has not paid the threat actor’s demand and is cooperating with law enforcement in the investigation of this Incident.”

Affected organizations and relationships

  1. Coinbase stated: “On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase Global, Inc. (“Coinbase” or the “Company”), received an email communication from an unknown threat actor claiming to have obtained information about certain Coinbase customer accounts, as well as internal Coinbase documentation, including materials relating to customer-service and account-management systems. The communication demanded money in exchange for not publicly disclosing the information. The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities. These instances of such personnel accessing data without business need were independently detected by the Company’s security monitoring in the previous months. Upon discovery, the Company had immediately terminated the personnel involved and also implemented heightened fraud-monitoring protections and warned customers whose information was potentially accessed in order to prevent misuse of any compromised information. Since receipt of the email, the Company has assessed the email to be credible, and has concluded that these prior instances of improper data access were part of a single campaign (the “Incident”) that succeeded in taking data from internal systems. The Company has not paid the threat actor’s demand and is cooperating with law enforcement in the investigation of this Incident.”

Operational impact

  1. Coinbase stated: “While Coinbase has not experienced material operational impacts from these events as of the date hereof, the full financial impact of the Incident on the Company is still in the process of being assessed. Based on the information available to the Company on the date hereof and based on facts that continue to evolve, the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs and voluntary customer reimbursements relating to this Incident, prior to further review of potential losses, indemnification claims, and potential recoveries, which could meaningfully increase or decrease this estimate. The Company plans to aggressively pursue all remedies. As the Company’s investigation is ongoing, the full impact of these events are not yet known.”

Reported data impact

  1. Coinbase stated: “The Incident did not involve the compromise of passwords or private keys, and at no time were any of the targeted contractors or employees able to access customer funds. While the Company is still investigating the affected data, it included:”

  2. Coinbase stated: “• Name, address, phone, and email;”

  3. Coinbase stated: “• Masked Social Security (last 4 digits only);”

  4. Coinbase stated: “• Masked bank-account numbers and some bank account identifiers;”

  5. Coinbase stated: “• Government‑ID images (e.g., driver’s license, passport);”

  6. Coinbase stated: “• Account data (balance snapshots and transaction history); and”

  7. Coinbase stated: “• Limited corporate data (including documents, training material, and communications available to support agents).”

Financial impact, scope and period

  1. Coinbase stated: “While Coinbase has not experienced material operational impacts from these events as of the date hereof, the full financial impact of the Incident on the Company is still in the process of being assessed. Based on the information available to the Company on the date hereof and based on facts that continue to evolve, the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs and voluntary customer reimbursements relating to this Incident, prior to further review of potential losses, indemnification claims, and potential recoveries, which could meaningfully increase or decrease this estimate. The Company plans to aggressively pursue all remedies. As the Company’s investigation is ongoing, the full impact of these events are not yet known.”

  2. Coinbase stated: “| Data Theft Incident losses (recoveries), net 1 | – | 306.7 | 48.0 | (9.5) | 8.6” Unit declaration: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table context: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table note: “[1] Losses, net of recoveries, directly related to the data theft incident announced on the Current Report on Form 8-K we filed with the SEC on May 15, 2025 (the “Data Theft Incident”), including voluntary customer reimbursements, direct legal costs, and reward payments, if any, in connection with the threat actor’s arrest and conviction.” Selected table cell: “Q2’25” / “306.7” (USD millions).

  3. Coinbase stated: “| Data Theft Incident losses (recoveries), net 1 | – | 306.7 | 48.0 | (9.5) | 8.6” Unit declaration: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table context: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table note: “[1] Losses, net of recoveries, directly related to the data theft incident announced on the Current Report on Form 8-K we filed with the SEC on May 15, 2025 (the “Data Theft Incident”), including voluntary customer reimbursements, direct legal costs, and reward payments, if any, in connection with the threat actor’s arrest and conviction.” Selected table cell: “Q3’25” / “48.0” (USD millions).

  4. Coinbase stated: “| Data Theft Incident losses (recoveries), net 1 | – | 306.7 | 48.0 | (9.5) | 8.6” Unit declaration: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table context: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table note: “[1] Losses, net of recoveries, directly related to the data theft incident announced on the Current Report on Form 8-K we filed with the SEC on May 15, 2025 (the “Data Theft Incident”), including voluntary customer reimbursements, direct legal costs, and reward payments, if any, in connection with the threat actor’s arrest and conviction.” Selected table cell: “Q4’25” / “(9.5)” (USD millions; accounting parentheses retained).

  5. Coinbase stated: “| Data Theft Incident losses (recoveries), net 1 | – | 306.7 | 48.0 | (9.5) | 8.6” Unit declaration: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table context: “| ($ in millions) | Q1’25 | Q2’25 | Q3’25 | Q4’25 | Q1’26” Table note: “[1] Losses, net of recoveries, directly related to the data theft incident announced on the Current Report on Form 8-K we filed with the SEC on May 15, 2025 (the “Data Theft Incident”), including voluntary customer reimbursements, direct legal costs, and reward payments, if any, in connection with the threat actor’s arrest and conviction.” Selected table cell: “Q1’26” / “8.6” (USD millions).

Response

  1. Coinbase stated: “The Company is continuing to review and bolster its anti-fraud protections to mitigate the risk that the compromised information could be used in social-engineering attempts. To the extent any eligible retail customers previously sent funds to the threat actor as a direct result of this Incident, the Company intends to voluntarily reimburse them after it completes its review to confirm the facts. The Company is also in the process of opening a new support hub in the United States and taking other measures to harden its defenses to prevent this type of incident.”

  2. Coinbase stated: “On May 11, 2025, Coinbase, Inc., a subsidiary of Coinbase Global, Inc. (“Coinbase” or the “Company”), received an email communication from an unknown threat actor claiming to have obtained information about certain Coinbase customer accounts, as well as internal Coinbase documentation, including materials relating to customer-service and account-management systems. The communication demanded money in exchange for not publicly disclosing the information. The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information from internal Coinbase systems to which they had access in order to perform their job responsibilities. These instances of such personnel accessing data without business need were independently detected by the Company’s security monitoring in the previous months. Upon discovery, the Company had immediately terminated the personnel involved and also implemented heightened fraud-monitoring protections and warned customers whose information was potentially accessed in order to prevent misuse of any compromised information. Since receipt of the email, the Company has assessed the email to be credible, and has concluded that these prior instances of improper data access were part of a single campaign (the “Incident”) that succeeded in taking data from internal systems. The Company has not paid the threat actor’s demand and is cooperating with law enforcement in the investigation of this Incident.”

Dates and disclosures

  1. Coinbase stated: “Date of Report (Date of earliest event reported): May 14, 2025”

  2. Coinbase stated: “| Dated: May 15, 2025 | By: | /s/ Alesia J. Haas”

  3. Coinbase stated: “May 7, 2026”

  4. Coinbase stated: “Materials containing Coinbase’s financial results for the first quarter ending March 31, 2026 have been posted on its Investor Relations website at investor.coinbase.com. The Company will hold a webcast to discuss these financial results at 2:30 p.m. PT today. The live webcast of the call can be accessed here . Following the call, a replay of the call, as well as a transcript, will be available on the Investor Relations website at investor.coinbase.com.”

Disclosure evolution

  1. Coinbase stated: “[1] Losses, net of recoveries, directly related to the data theft incident announced on the Current Report on Form 8-K we filed with the SEC on May 15, 2025 (the “Data Theft Incident”), including voluntary customer reimbursements, direct legal costs, and reward payments, if any, in connection with the threat actor’s arrest and conviction.”

Qualifications and uncertainty

  1. Coinbase stated: “While Coinbase has not experienced material operational impacts from these events as of the date hereof, the full financial impact of the Incident on the Company is still in the process of being assessed. Based on the information available to the Company on the date hereof and based on facts that continue to evolve, the Company has preliminarily estimated expenses to be within the range of approximately $180 million to $400 million relating to remediation costs and voluntary customer reimbursements relating to this Incident, prior to further review of potential losses, indemnification claims, and potential recoveries, which could meaningfully increase or decrease this estimate. The Company plans to aggressively pursue all remedies. As the Company’s investigation is ongoing, the full impact of these events are not yet known.”

  2. Coinbase stated: “[1] Losses, net of recoveries, directly related to the data theft incident announced on the Current Report on Form 8-K we filed with the SEC on May 15, 2025 (the “Data Theft Incident”), including voluntary customer reimbursements, direct legal costs, and reward payments, if any, in connection with the threat actor’s arrest and conviction.”

Disclosure sources and provenance

  • Coinbase Publisher posted May 15, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 9:36 PM UTC · Retained Oct 7, 2026, 9:36 PM UTC
    • Issuer-published hosted/converted HTML filing representation, not native SEC acquisition or established EDGAR byte equivalence.
    • May15 is issuer-listed posting/filing date; report/event dateMay14 must be retained distinctly.
    • Current representation cannot establish historical exact bytes.
  • Coinbase Publisher posted May 7, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:49 PM UTC · Retained Oct 7, 2026, 7:49 PM UTC
    • Current issuer-published representation; historical exact bytes are unknown.
    • Independent publisher HTTPS origin; not native SEC acquisition, no EDGAR byte-equivalence established.
    • Frozen issuer CIK is subject association only; SEC filing/accession fields remain unavailable on this public-source record.

Evidence limitations

  • Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
  • Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.