U.S. cryptocurrency exchange Coinbase was made aware of a customer data leak at its outsourcing company Taskus some four months before a major breach that is expected to cost the company $400 million, according to a Reuters report citing six sources. The delayed disclosure has sparked fierce criticism over user data protection and third-party risk management.
Employee Caught Photographing Work Computer
An employee of Taskus in Indore, India, was caught taking photos of her work computer and passing customer information to hackers in exchange for bribes. According to five anonymous former employees, the unnamed female employee and an accomplice were involved in the illegal data transfer. A report was made to Coinbase at the time, but the exchange only publicly acknowledged the breach in May 2025 — after hackers attempted to extort $20 million from the firm.
Following the initial discovery, Taskus abruptly terminated 200 employees, prompting allegations of unfair dismissal. The affected workers said they were let go without proper investigation or compensation.
Public Acknowledgment After Extortion Attempt
Coinbase’s May 15 statement claimed that attackers had targeted internal customer support systems and accessed personal information of less than 1% of monthly transacting users. However, the company did not disclose that it had been aware of the leak since January. In its response, Coinbase said it “cut ties with the TaskUs personnel involved and other overseas agents, and tightened controls.” Taskus separately stated that two employees were terminated in January.
The incident comes amid a rising wave of armed robberies and kidnappings targeting wealthy crypto holders. In several recent cases, criminals appeared to have detailed information about victims’ holdings. Observers believe the true cost of this breach extends far beyond the $400 million estimate, as user trust erodes and regulatory scrutiny intensifies.
Broader Implications for Crypto Exchanges
The Coinbase breach underscores the risks of outsourcing customer support and other sensitive functions. Industry experts argue that exchanges must implement stricter oversight of third-party vendors and establish mandatory disclosure timelines when user data is compromised. Failure to do so not only exposes customers to financial and physical threats but also leaves the platform vulnerable to massive liabilities and reputational damage.

