Coinbase is back at the center of a security debate after BlockTower Capital founder Ari Paul accused the exchange of concealing large-scale hacking incidents that he said affected at least a dozen institutions and involved more than $1 billion in losses.
The latest dispute began on Sept. 26, when X user kuno said Coinbase had locked the user’s account a year earlier and claimed another $1.2 million was still owed. The user demanded a resolution within 24 hours and said otherwise meeting recordings would be released and legal action would follow.
Cobie, who leads Coinbase Base App, replied that he could not find an account matching the description and said he suspected the post was an attempt to attract attention. He added that Coinbase had tried to contact the user for more than six months and that his own direct messages had gone unanswered. Cobie also said the episode was being used to promote a “shitcoin” and looked like a fake scam report designed to farm engagement.
Ari Paul then entered the discussion and said Coinbase had caused BlockTower Capital to lose $25 million several years ago. Afterward, he said, his team concluded that Coinbase had been covering up large-scale and repeated hacks, and that the funds had still not been returned.
Paul said his team had traced the issue to at least a dozen affected institutions, with total losses exceeding $1 billion. Because multiple legal proceedings are still underway, he said that was all he could disclose for now.
As of publication, Paul had not released verifiable evidence to support the allegation, and Coinbase had not made a public response. Even so, the claim spread quickly across the crypto community, with some users saying they had also suffered losses on Coinbase. The reaction drew renewed attention to several security incidents tied to the exchange over the past few years.
Old Coinbase incidents are back in focus
In early October 2021, Coinbase sent a data breach notice to some customers. According to the notice filed with the California Attorney General’s website, at least 6,000 customer accounts were compromised between March and May 20 of that year.
The notice said attackers first needed a victim’s email address, password and phone number, and also needed access to the victim’s email inbox. They then exploited a flaw in Coinbase’s SMS account recovery process to obtain two-factor authentication codes, enter the account and move funds out.
A Coinbase spokesperson said at the time that the company had fixed the flaw immediately and helped customers restore account access and recover losses. CNBC reported, however, that some users had complained for months that their accounts had been drained before the notice was sent, and Coinbase was criticized for responding too slowly.
A similar delay appeared again four years later. On May 11, 2025, Coinbase received an extortion email in which the sender displayed internal information that had already been obtained and demanded $20 million in exchange for silence.
Coinbase later said in an official blog post that criminals had bribed and recruited a group of overseas customer support workers to steal customer data for social engineering attacks. In a filing with the Maine Attorney General, the company said about 69,500 customers were affected and that the exposure began around Dec. 26, 2024. Coinbase said passwords, private keys, funds and Coinbase Prime accounts were not affected.
The company refused to pay the ransom and instead offered a $20 million reward. In a filing with the U.S. Securities and Exchange Commission, Coinbase said the incident was expected to cost between $180 million and $400 million.
Chief Executive Officer Brian Armstrong said the employees involved had been fired at the time, but the company only connected the incidents as part of a single attack during the later investigation. Reuters, citing people familiar with the matter, reported that Coinbase had learned as early as January 2025 that an employee of outsourcing contractor TaskUs in India had used a personal phone to photograph customer data displayed on a work computer.
Lawyer Ariel Givner said on X that the extortion email had been sent on May 11, but Coinbase did not notify users until after deciding not to pay.
Scams impersonating Coinbase support also continued. The Brooklyn District Attorney’s Office in New York said local resident Ronald Spektor posed as Coinbase customer support, told users their accounts had been hacked and their assets were at risk, and persuaded about 100 victims to transfer crypto to wallets he controlled. The office said he stole about $15.94 million in total. Spektor pleaded guilty on Sept. 2 and was sentenced on Sept. 23 to four to 12 years in prison.
Whether victims get their money back depends on Coinbase’s determination. For users tricked into transferring funds in the 2025 incident, Coinbase said it would reimburse losses, but only after case-by-case review to confirm a direct link to the data exposure.
If users disagree with Coinbase, litigation may not be straightforward. One user sued the exchange, alleging it failed to investigate fraudulent transfers in the account in a timely and good-faith manner. Coinbase invoked mandatory arbitration under its user agreement. In December 2023, the U.S. Court of Appeals for the Ninth Circuit reversed a lower court ruling that had rejected Coinbase’s arbitration request and held that the relevant contract terms were enforceable.
Looking across these cases, Coinbase’s own processes were at times exploited through identifiable weaknesses. The company did disclose the incidents and promise reimbursement, but the disclosures came late.
What Ari Paul meant by a “cover-up” remains unclear. It is not known whether he was referring to an undisclosed breach of Coinbase’s custody systems or to disputes over reimbursement after customer accounts were drained.
Bitget, Liquid Network and Coldcard show how outcomes differ
Security incidents have become more frequent across crypto in the second half of this year. Blockchain security firm PeckShield said August saw 50 major hacking incidents, up 67% from 30 in July and the highest monthly count so far this year.
Total losses in August did not rise with the incident count. PeckShield put the month’s losses at about $136.3 million, down 49.5% from roughly $270 million in July. Average losses per incident fell from about $9 million in July to about $2.7 million in August.
In September, the size of individual incidents expanded again, especially in the cases involving Bitget and Liquid Network.
According to an incident notice from Blockstream, the technology provider behind Liquid, a self-described white hat attacker withdrew about 4,000 BTC from the federation wallet of the Bitcoin sidechain Liquid Network on Sept. 6. At the time, the amount was worth about $320 million and represented roughly 95% of reserves.
Liquid’s incident report said no private keys were exposed. Instead, the attacker exploited a vulnerability in Elements, the open-source software underlying Liquid, to create about 4,000 unbacked L-BTC and then redeem them through the normal withdrawal process for real bitcoin.
After Blockstream confirmed the flaw had been fixed, the attacker returned 3,400 BTC on Sept. 7. About 598.5 BTC remained outstanding, and the attacker asked Blockstream for a 10% bounty. Blockstream rejected the request. On Sept. 10, when Liquid resumed block production, Chief Executive Officer Adam Back said the 1:1 peg between L-BTC and bitcoin would be maintained and that Blockstream would absorb the shortfall.
That promise did not mean users had already regained access to funds. On Sept. 17, Liquid said withdrawals were still suspended, and no further update was cited in the source material.
More than two weeks later, Bitget was hit as well. On the night of Sept. 24, assets began moving from Bitget wallets to an unfamiliar address. On-chain tracking put the loss at about $387.5 million. The report described it as the largest crypto theft of the year and said it made September the worst month of the year by stolen value.
The attacker exploited a vulnerability in a third-party security product used by Bitget, gained high-level access to the internal network, and had forged transactions pass through the normal approval process automatically. Bitget CEO Gracy Chen said no private keys were stolen and that the exchange suspected North Korean hackers were behind the attack.
Bitget said the loss would be fully covered by its user protection fund, which holds 5,500 BTC. The exchange said withdrawals would resume in phases starting Sept. 28 and were scheduled to be fully restored before Oct. 2.
Self-custody was not spared either. In late July, hardware wallet maker Coldcard was reported to have a firmware flaw that made some seed phrases generated since 2021 predictable. Users were said to have lost about 1,800 BTC in total, including devices stored in bank vaults and never connected to the internet. Forbes reported that manufacturer Coinkite was helping victims file police reports and insurance claims, but had not offered compensation, and some victims were preparing a class action lawsuit.
Where assets are held can shape what happens next
Viewed together, these cases point to a simple divide: where funds are stored often determines what happens after a breach.
On centralized exchanges, reimbursement after a platform compromise depends in part on what protections the exchange prepared in advance. A protection fund can cover losses in full, but if that fund is denominated in crypto, its value can move with the market. Users tricked into sending funds also often face case-by-case review, and disputes can end up in arbitration.
Even when an operator says it will make users whole, that does not mean access returns quickly. Assets can remain frozen for a long time before any promise is carried out.
With hardware wallets and self-custody, users reduce dependence on a platform but take on device and supply-chain risk themselves. Even if the user makes no operational mistake, a firmware defect at the manufacturer level can leave losses to be borne personally or pursued through litigation.
Attacks that rely on fake support staff or bribed insiders target people rather than wallets. In that sense, no storage model fully avoids them.
The industry has argued about custody for years. In August, Ari Paul said while discussing the Coldcard thefts that crypto assets cannot be made safe under either self-custody or third-party custody, and that in most developed countries legal systems protect assets more reliably than cryptography does.
ShapeShift founder Erik Voorhees pushed back, saying no asset is absolutely safe and every custody model involves trade-offs. What matters, he said, is that users can choose for themselves and bear responsibility for that choice.
Solana Labs co-founder toly took a different line. If crypto is being held as an investment, he said, it should be placed with a custodian. If it is meant as protection against extreme scenarios, then it is a cost rather than an investment, and cold storage may justify the extra effort. The two use cases should not be mixed together.
Now Ari Paul has turned his criticism toward Coinbase. Whether his allegation holds up will depend on evidence and legal proceedings. The dispute, though, leaves the same question in front of every token holder: when every option carries a cost, where should the money sit?


