Blockchain AcademicsBlockchain Academics
Coinbase Breach Tied to Outsourcing Firm Months Before Disclosure, Raising Security Red Flags

Coinbase Breach Tied to Outsourcing Firm Months Before Disclosure, Raising Security Red Flags

A Coinbase data breach traced to TaskUs months before public notice impacts 70,000 users and fuels legal scrutiny.

Blockchain Academics NewsroomJune 3, 20252 min read
Share

A major data breach at Coinbase has been traced back to a January security lapse involving a U.S. outsourcing firm months before the company publicly disclosed the incident. The breach, now the subject of legal action and industry scrutiny, exposed the sensitive personal data of nearly 70,000 Coinbase customers and highlights the growing risks associated with third-party customer support providers.

The incident originated when a TaskUs employee was allegedly caught photographing confidential customer data from her work terminal using her smartphone. According to multiple former employees cited by Reuters, the woman, along with a suspected accomplice, is believed to have sold the stolen data to hackers for financial gain. The leaked information would later be used in a $20 million ransom attempt.

Coinbase, one of the world’s largest cryptocurrency exchanges, was reportedly notified immediately. Yet, the company waited until mid-May to formally disclose the breach in a regulatory filing, drawing criticism for its delayed transparency. By that point, portions of the compromised data had already been leaked after Coinbase refused to meet the ransom demands.

The delayed disclosure comes as Coinbase faces mounting legal and reputational consequences. A class-action lawsuit filed in Manhattan on May 27 names TaskUs as a co-defendant, accusing the company of failing to enforce adequate data protection protocols. This isn’t the first time TaskUs has come under fire—previous lawsuits have tied the firm to another major breach in 2022 involving crypto wallet provider Ledger and e-commerce platform Shopify.

TaskUs, which had been managing Coinbase's customer support services from India, carried out a mass layoff in January, terminating over 200 employees. Although only two individuals were directly involved in the Coinbase incident, the broader operational failures have reignited debates around the security of outsourced crypto infrastructure.

In its public response, Coinbase stated it has severed ties with the implicated TaskUs personnel and has enhanced internal controls to prevent similar incidents. These measures include limiting access for third-party agents and enforcing stricter data monitoring protocols.

The fallout from the breach has extended beyond Coinbase. Victims of prior data leaks—such as the Ledger hack—continue to suffer from ongoing phishing campaigns and scams, years after their information was exposed. These persistent threats illustrate the long-term consequences of data mishandling in the crypto sector.

The Coinbase breach underscores the vulnerabilities inherent in outsourcing customer support in high-risk industries like cryptocurrency. As legal proceedings unfold, the industry is once again reminded that the weakest link in security is often human—and increasingly, that link lies far outside company headquarters.

Discussion

Loading comments...