BTC
$103,049.99
-
1.82%
ETH
$2,577.52
-
1.83%
USDT
$1.0002
+
0.02%
XRP
$2.1683
-
1.99%
BNB
$650.77
-
2.51%
SOL
$149.55
-
3.82%
USDC
$0.9999
+
0.05%
DOGE
$0.1792
-
5.49%
TRX
$0.2732
-
0.02%
ADA
$0.6615
-
1.93%
HYPE
$34.21
-
5.00%
SUI
$3.0722
-
4.42%
LINK
$13.57
-
2.74%
AVAX
$19.73
-
5.22%
XLM
$0.2624
-
2.20%
LEO
$8.6639
-
2.60%
BCH
$400.42
-
1.79%
TON
$3.2036
+
1.11%
SHIB
$0.0₄1262
-
2.76%
HBAR
$0.1653
-
1.98%
Logo
  • News
  • Prices
  • Data
  • Indices
  • Research
  • Events
  • Sponsored
  • Sign In
  • Sign Up
Markets
Share this article
X iconX (Twitter)LinkedInFacebookEmail

Coinbase Denies Reports of Data Breach, Addresses Security Concerns

Coinbase has responded to allegations that its service has a flaw that leaves users open to fraud and spam.

By Pete Rizzo
Updated Sep 11, 2021, 10:36 a.m. Published Apr 1, 2014, 7:27 p.m.
coinbase

San Francisco-based bitcoin wallet provider Coinbase formally responded to community concerns relating to a design function of its 'Request Money' service on 1st April, amid reports that suggested this service could be misused by phishers and fraudsters.

The response was issued after a Pastebin entry surfaced suggesting that roughly 2,000 Coinbase customer names and emails were compromised as part of a "data breach" of the site, rumours that caused widespread speculation on reddit and social media.

Story continues
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
By signing up, you will receive emails about CoinDesk products and you agree to our terms of use and privacy policy.

Speaking to CoinDesk, the company clarified that, although certain user personal information was posted online, the event was not a data breach, but rather an exploitation of a feature common to popular tech services. Malicious users, it noted, can use an email address to determine if someone has an account on other payment services such as PayPal, Square Cash and Venmo – a process called email enumeration.

Wrote the company in its official response:

"Though we believe this type of spam and user enumeration activity doesn’t represent a significant risk to Coinbase customers, we absolutely recognize that it can be an inconvenience and cause confusion."

Coinbase's Request Money feature allows users to request funds by entering an email address. If the recipient is a Coinbase user, the website generates a return email complete with the individual's first and last name, provided they used their real name to register with the service.

Coinbase does not require its users to provide real names, and indicates in its privacy policy that it makes such information available.

However, at least one security official has expressed concern that such information could be used by malicious parties to commit larger fraud.

Origin of the dispute

This functionality was brought to light to the bitcoin community by Australia-based security researcher Shubham Shah, who posted his frustrations on his blog. That post detailed a step-by-step process of how to conduct email enumeration using Coinbase, and lashed out against the company for not taking measures to address his concerns.

Coinbase reviewed the "design flaw" as submitted by Shah, but informed him that it would not be looking to implement a fix or issuing a reward for the finding. As such, he decided to publish the claim on his blog.

According to a timeline posted by Shah, the developer first contacted Coinbase on 28th February. The communication was part of a series of correspondences that ended on 31st March, when Shah indicates Coinbase confirmed it had closed his bug report.

Speaking to CoinDesk, Shah indicated that as a security researcher, he felt the responsibility to bring the issue to the community so that it could be addressed. Further, he claimed no affiliation with the subsequent PasteBin posting of customer names and email addresses.

Coinbase's response

Coinbase's blog post explained that despite claims circulating online, the design feature was intentional, and meant to increase the usability of its service. Further, it stated that not implementing a limit on the number of emails that can be generated via its service serves a specific use case.

Said Coinbase:

"Allowing lists to be invoiced is core functionality of our service, and this functionality is intentionally built into our API."

In a message dated 31st March, a Coinbase representative offered the company's internal assessment to Shah via HackerOne, an online organisation of security experts that coordinates rewards for hackers who contribute to a safer Internet.

"We are not considering account existence bugs to be high enough severity for our scope. This behaviour is mostly informational to an attacker and does not directly increase risk in any significant way. We may consider updating this behaviour in the future but do not feel it warrants a reward."

The representative elaborated that allowing lists to be invoiced was a key aspect of its service, and that it "would not be any more effective than more traditional phishing methods, which we spend a considerable amount of time preventing".

Unlikely attacks

In its blog post, Coinbase indicated that only a very small amount of users – less than 0.5% – were named in the user data post today. In addition, it went on to describe why it believes such attacks are incredibly unlikely.

Said Coinbase: "This list of emails was likely sourced from other sites – probably bitcoin-related ones."

The company said that malicious users would need to first acquire email addresses, which aren't publicly available online, then send money to recipients who, in turn, would have to choose to send money to unknown users.

Shah indicated that the design flaw is important due to the nature of bitcoin's design.

"You're not dealing with a normal account. You're dealing with an account that holds digital currency, which is irreversible. It's a little more serious."

Coinbase acknowledged this concern, though it said it believes it represents a low fraud risk, and is more threatening to users as a spam issue.

Coinbase indicated in its blog post that it is taking the issue of spamming seriously, noting that it employs rate limits on sensitive actions such as requesting money so that they aren't widely abused.

CoinbaseSecurityExchangesstartupsTechnologyNewsCompaniesTechnology News
Pete Rizzo

Pete Rizzo was CoinDesk's editor-in-chief until September 2019. Prior to joining CoinDesk in 2013, he was an editor at payments news source PYMNTS.com.

Picture of CoinDesk author Pete Rizzo
Latest Crypto News
Article image

Bitcoin Whales Seem to Be Calling a Top as BTC Price Consolidates

May 29, 2025

Bitcoin (BTC) price on May 19 (CoinDesk)

Bitcoin Climbs to $105K; Crypto ETF Issuer Sees 35% Upside

May 29, 2025

Breaking News

Breaking New test

May 29, 2025

FastNews (CoinDesk)

Fast News test

May 29, 2025

Article image

Ethereum Surges 4% on Massive Volume as Institutional Interest Grows.

May 27, 2025

Article image

test research article

May 22, 2025

Top Stories
Gold (Credit: Shutterstock)

Gold Continues Correcting and That Might Be Good for Bitcoin

May 1, 2025

President Donald Trump (TheDigitalArtist/Pixabay)

Bitcoin Poised to Top Record as Trump Inauguration Nears, Major Coins Due for 10% Swings: Traders

Jan 16, 2025

Crypto veteran Hunter Merghart has been hired by hedge fund giant Millennium Management. (Pixabay)

Crypto Exchange Luno's Co-Founder Departed in December

Jan 19, 2023

Tokyo, Japan (Jaison Lin/Unsplash)

Metaplanet Buys Another 1,004 Bitcoin, Lifts Holdings to Over $800M Worth of BTC

May 19, 2025

Article image

Bitcoin Whales Seem to Be Calling a Top as BTC Price Consolidates

May 29, 2025

(CJ/Unsplash)

XRP Futures Start Trading on CME

May 19, 2025

Only 2 articles remaining this month.

Sign up for free

About

  • About Us
  • Masthead
  • Careers
  • CoinDesk News
  • Crypto API Documentation

Contact

  • Contact Us
  • Accessibility
  • Advertise
  • Sitemap
  • System Status
DISCLOSURE & POLICES
CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.
EthicsPrivacyTerms of UseCookie SettingsDo Not Sell My Info

© 2025 CoinDesk, Inc.
X icon
Sign Up
  • News
    Back to menu
    News
    • Markets
    • Finance
    • Tech
    • Policy
    • Focus
  • Prices
    Back to menu
    Prices
    • Data
      Back to menu
      Data
      • Trade Data
      • Derivatives
      • Order Book Data
      • On-Chain Data
      • API
      • Research & Insights
      • Data Catalogue
      • AI & Machine Learning
    • Indices
      Back to menu
      Indices
      • Multi-Asset Indices
      • Reference Rates
      • Strategies and Services
      • API
      • Insights & Announcements
      • Documentation & Governance
    • Research
      Back to menu
      Research
      • Events
        Back to menu
        Events
        • Consensus Hong Kong
        • Consensus 2026
        • CoinDesk: Policy & Regulation
      • Sponsored
        Back to menu
        Sponsored
        • Thought Leadership
        • Press Releases
        • CoinW
        • MEXC
        • Phemex
        • Advertise
      • Videos
        Back to menu
        Videos
        • CoinDesk Daily
        • Shorts
        • Editor's Picks
      • Podcasts
        Back to menu
        Podcasts
        • CoinDesk Podcast Network
        • Markets Daily
        • Gen C
        • Unchained with Laura Shin
        • The Mining Pod
      • Newsletters
        Back to menu
        Newsletters
        • The Node
        • Crypto Daybook Americas
        • State of Crypto
        • Crypto Long & Short
        • Crypto for Advisors
      • Webinars & Events
        Back to menu
        Webinars & Events
        • Consensus 2025
        • Policy & Regulation Conference
      Select Language
      English enEspañol esFilipino filFrançais frItaliano itPortuguês pt-brРусский ruУкраїнська uk