Coinbase was reportedly informed about a customer data leak involving outsourcing firm TaskUs roughly four months before the crypto exchange publicly acknowledged a breach now expected to cost it as much as $400 million. The report, published by Reuters and based on six sources, has intensified scrutiny over how major crypto platforms manage third-party contractors, internal controls, and the protection of sensitive user information.
Early Warning Allegedly Came From an Incident at TaskUs
According to the report, one of the warning signs came from an incident in Indore, India, where a TaskUs employee was allegedly caught taking photos of her work computer screen. The incident was reportedly escalated to Coinbase, indicating that the exchange had reason to know about a potential leak of customer information months before the breach became public.
Reuters cited five anonymous former employees who said the unnamed worker and an alleged accomplice were believed to have supplied customer data to hackers in exchange for bribes. An investigation was launched after the incident. Soon afterward, around 200 TaskUs employees were abruptly dismissed, a move that later prompted accusations of unfair termination from affected workers.
Public Disclosure Came Only After an Extortion Attempt
Despite those earlier signs, Coinbase did not publicly confirm the breach until May 15, after attackers in possession of sensitive user information attempted to extort $20 million from the company. At the time, Coinbase said the attackers had targeted internal customer support systems and obtained personal data belonging to fewer than 1% of monthly transacting users.
The gap between when the company was allegedly alerted and when it disclosed the incident is likely to become a central point of debate. Based on the Reuters account, Coinbase had been aware in prior months that contractors had improperly accessed user data. Even so, the company appears to have taken broader public action only after the extortion demand brought the matter into sharper focus.
Coinbase and TaskUs Responses
Coinbase has said it severed ties with the TaskUs personnel involved, as well as with other overseas agents connected to the matter, and that it tightened internal controls afterward. That response suggests the company recognized a meaningful breakdown in oversight around outsourced support operations.
TaskUs, for its part, said the two employees at the center of the incident were dismissed in January. The outsourcing firm’s statement addresses personnel action but does not resolve broader concerns about how customer information was handled, what monitoring systems were in place, and whether warning signs were adequately escalated across the vendor relationship.
Why the Fallout May Extend Beyond Financial Losses
While the projected $400 million cost is already substantial, some observers believe the real impact could be even greater. The breach surfaced at a time when wealthy crypto holders have increasingly become targets of violent crime, including kidnappings and armed robberies. In several such cases, criminals appeared to possess unusually detailed knowledge about victims, including information related to their digital asset holdings.
That broader context makes user-data exposure especially serious for crypto platforms. Even if the number of directly affected accounts was limited to less than 1% of monthly transacting users, the nature of the information involved may raise concerns well beyond identity theft or phishing. The possibility that sensitive customer data could be used to identify high-value targets adds a physical-security dimension that is particularly acute in the digital asset industry.
Vendor Risk and Timing Now Under the Spotlight
The Coinbase case underscores a wider issue facing large crypto companies: operational dependence on external support providers can create security vulnerabilities that are harder to detect and govern. Outsourcing may improve scale and efficiency, but it also expands the circle of individuals who can access sensitive systems or customer data. When controls fail, the consequences can include regulatory scrutiny, legal exposure, reputational damage, and a loss of user trust.
In this case, the most contentious question may not be only whether a leak occurred, but whether Coinbase responded quickly and forcefully enough once it became aware of the problem. The timeline outlined in the Reuters report is likely to draw attention from users, policymakers, and security professionals alike, especially as the crypto sector continues to face pressure to improve governance standards.
For now, the incident stands as another reminder that in crypto, cybersecurity is not limited to code, wallets, or on-chain threats. Human access points, outsourced workflows, and customer support infrastructure can also become critical attack surfaces. As more details emerge, market participants will be watching how Coinbase handles remediation, customer protection, and future oversight of third-party service providers.

