BTC $83,418.56 +0.31%
ETH $2,687.10 +0.70%
BNB $767.23 +0.78%
XRP $1.49 -0.23%
SOL $118.03 -1.27%
TRX $0.3373 +0.69%
DOGE $0.0950 +1.65%
ADA $0.2486 +2.12%
BCH $306.47 +0.06%
LINK $14.43 +0.22%
HYPE $89.34 +3.76%
AAVE $164.13 +2.55%
SUI $1.17 +1.67%
XLM $0.2274 +3.08%
ZEC $1,414.81 +0.19%
AAPL $334.38 +1.37%
AMZN $251.13 +1.71%
GOOGL $352.80 +3.46%
MSFT $515.12 +1.05%
META $730.33 -1.12%
NVDA $230.23 +1.03%
TSLA $356.99 +0.88%
SNDK $1,757.19 +2.18%
INTC $122.29 +5.50%
SPCX $151.49 +1.56%
MU $1,065.58 -0.44%
AMD $618.41 +1.87%
BTC $83,418.56 +0.31%
ETH $2,687.10 +0.70%
BNB $767.23 +0.78%
XRP $1.49 -0.23%
SOL $118.03 -1.27%
TRX $0.3373 +0.69%
DOGE $0.0950 +1.65%
ADA $0.2486 +2.12%
BCH $306.47 +0.06%
LINK $14.43 +0.22%
HYPE $89.34 +3.76%
AAVE $164.13 +2.55%
SUI $1.17 +1.67%
XLM $0.2274 +3.08%
ZEC $1,414.81 +0.19%
AAPL $334.38 +1.37%
AMZN $251.13 +1.71%
GOOGL $352.80 +3.46%
MSFT $515.12 +1.05%
META $730.33 -1.12%
NVDA $230.23 +1.03%
TSLA $356.99 +0.88%
SNDK $1,757.19 +2.18%
INTC $122.29 +5.50%
SPCX $151.49 +1.56%
MU $1,065.58 -0.44%
AMD $618.41 +1.87%

The turmoil over the security of cryptocurrency funds has resurfaced, with Coinbase accused of "covering up a $1 billion hacker attack."

Core Viewpoint
Summary: With hardware wallets and exchanges being continuously hacked, where should users place their funds when every choice comes with a cost?
Zhou
2026-09-30 10:50:23
With hardware wallets and exchanges being continuously hacked, where should users place their funds when every choice comes with a cost?

Author: Zhou, ChainCatcher

The aftermath of the nearly $390 million theft from Bitget has not yet subsided, and a controversy surrounding Coinbase has once again brought exchange security back into the public spotlight.

On September 26, X user kuno posted that Coinbase had locked his account a year ago, claiming he still owed $1.2 million, and demanded that Coinbase resolve the issue within 24 hours, or he would publicly disclose meeting recordings and resort to legal action.

Cobie, head of the Coinbase Base App, responded that no accounts matching the description were found and suspected this was an attempt to gain attention. He stated that there had been no response from the user to communications from Coinbase over the past six months, and that the incident was being used to promote a scam coin, appearing to be a completely false scam report aimed at boosting interactions.

The turmoil over the security of cryptocurrency funds has resurfaced, with Coinbase accused of

Subsequently, Ari Paul, founder of crypto asset management firm BlockTower Capital, commented that Coinbase caused his company to lose $25 million a few years ago, later discovering that Coinbase had actually been covering up large-scale and repeated hacking incidents, with the related funds still not returned.

He stated that the team had tracked at least a dozen affected institutions, involving amounts exceeding $1 billion, but due to multiple ongoing legal proceedings, they could only disclose this information for now.

The turmoil over the security of cryptocurrency funds has resurfaced, with Coinbase accused of

As of the time of publication, Ari Paul had not publicly disclosed verifiable evidence, and Coinbase had not made a public response. However, this accusation quickly spread within the community, with many users claiming they had also experienced financial losses on Coinbase. This is related to several security incidents Coinbase has faced over the past few years.

From SMS Vulnerabilities to Insider Threats: Coinbase's Old Issues

In early October 2021, Coinbase sent a data breach notification letter to some customers. According to the notice submitted to the California Attorney General's website, between March and May 20 of that year, at least 6,000 customer accounts were compromised.

The notice indicated that attackers needed to have prior knowledge of the victim's email, password, and phone number, and could log into their personal email to exploit a flaw in the Coinbase SMS account recovery process to obtain a dual verification code, allowing them to access the account and transfer funds.

A Coinbase spokesperson stated that the company had immediately fixed the vulnerability and assisted customers in recovering their accounts and compensating for losses. However, according to CNBC, prior to the notification being sent, users had already complained about their accounts being emptied for months, and Coinbase faced criticism for its slow response.

Four years later, a similar time lag occurred again. On May 11, 2025, Coinbase received a ransom email, in which the sender displayed internal information they had obtained, demanding $20 million for confidentiality.

Coinbase subsequently disclosed in an official blog that criminals had bribed and recruited a group of overseas customer service personnel to steal customer data for social engineering attacks. According to its report submitted to the Maine Attorney General, approximately 69,500 customers were affected, with the leak beginning around December 26, 2024. Coinbase stated that passwords, private keys, funds, and Coinbase Prime accounts were not affected.

Coinbase refused to pay the ransom and instead set up a $20 million reward. According to documents submitted to the U.S. Securities and Exchange Commission, the estimated cost of this incident is between $180 million and $400 million.

CEO Brian Armstrong stated that the involved personnel had been fired at the time, but it was only now that these incidents were connected as part of the same attack. According to Reuters, citing informed sources, Coinbase had learned as early as January 2025 that an employee of the contractor TaskUs in India had used a personal phone to take pictures of customer data on their work computer.

However, lawyer Ariel Givner pointed out on X that the ransom email was sent as early as May 11, and Coinbase only notified users after deciding to refuse to pay the ransom.

Scams impersonating Coinbase did not stop there. According to the Brooklyn District Attorney's Office in New York, a local man, Ronald Spektor, impersonated Coinbase customer service, claiming that user accounts had been hacked and assets were at risk, luring about 100 users to transfer their crypto assets into wallets he controlled, defrauding them of approximately $15.94 million. He pleaded guilty on September 2 and was sentenced to 4 to 12 years in prison on September 23.

Whether the defrauded users can get their money back depends on Coinbase's determination. For users who were scammed in the 2025 incident, Coinbase promised compensation, but each case needs to be reviewed to confirm that the losses are directly related to this leak.

If users have disputes with Coinbase, suing is not so easy. One user sued Coinbase, claiming it failed to conduct a timely and good-faith investigation into fraudulent transfers in their account, but Coinbase invoked the user agreement to demand mandatory arbitration. The U.S. Ninth Circuit Court of Appeals overturned the lower court's dismissal of the arbitration request in a December 2023 ruling, determining that the relevant terms in the agreement were enforceable.

Looking back at these incidents, Coinbase's own processes indeed had exploitable vulnerabilities. Although they ultimately disclosed the incidents and promised compensation, the disclosure process was indeed slow.

It remains unclear whether Ari Paul's mention of covering up hacking incidents refers to Coinbase's custody system being breached without disclosure or to Coinbase refusing to compensate after accounts were hacked.

Hardware Wallets and Exchanges Being Hacked: How to Compensate?

In the second half of this year, security incidents in the crypto industry have noticeably increased. According to statistics from blockchain security company PeckShield, there were 50 major hacking incidents in August, a 67% increase from 30 in July, marking the highest number of incidents in a single month this year.

However, the losses in August did not follow suit. The total loss for the month was approximately $136.3 million, a 49.5% decrease from about $270 million in July, with the average loss per incident dropping from about $9 million in July to about $2.7 million.

Entering September, the scale of individual incidents increased again, especially with the incidents involving Bitget and Liquid Network.

According to an incident announcement released by Blockstream, the technology provider for Liquid, a self-proclaimed white hat attacker withdrew approximately 4,000 bitcoins from the federated wallet of the Bitcoin sidechain Liquid Network on September 6, which was worth about $320 million at the time, accounting for about 95% of the reserves.

The incident report from Liquid showed that no private keys were leaked. The attacker exploited a vulnerability in the underlying open-source software Elements of Liquid to generate approximately 4,000 L-BTC without reserve backing, and then exchanged them for real bitcoins through the normal withdrawal process.

After Blockstream confirmed the vulnerability was fixed, the attacker returned 3,400 bitcoins on September 7, with approximately 598.5 bitcoins still not returned, and demanded 10% of the bounty from Blockstream. Blockstream rejected this request, and CEO Adam Back publicly stated on September 10, when Liquid resumed block production, that the 1:1 peg of L-BTC to Bitcoin would be guaranteed, with the shortfall covered by Blockstream.

However, the promise of a backstop does not mean users have already recovered their funds. Liquid officially stated on September 17 that the withdrawal function remained suspended, and no further progress has been announced since.

More than two weeks later, Bitget also encountered issues. On the evening of September 24, Bitget's wallet began transferring assets to an unfamiliar address. On-chain tracking indicated a loss of approximately $387.5 million, making it the largest cryptocurrency theft incident of the year, and September the month with the highest amount stolen this year.

The attacker exploited a vulnerability in a third-party security product they were using to gain elevated access to the internal network, and the fraudulent transactions were automatically released after passing through the normal approval process. Bitget CEO Gracy Chen stated that the attacker did not steal private keys, and Bitget suspects the attack originated from North Korean hackers.

Bitget officially stated that the losses would be fully covered by a protection fund held by users with 5,500 bitcoins, and that withdrawals would be gradually restored starting September 28, with a plan for full restoration by October 2.

Beyond exchanges and sidechains, self-custody has not been spared either. At the end of July this year, hardware wallet Coldcard was reported to have firmware flaws, allowing some recovery phrases generated since 2021 to be deduced, resulting in users losing approximately 1,800 bitcoins, including those stored in bank safes and devices that had never been connected to the internet. According to Forbes, the manufacturer Coinkite is assisting victims in reporting to the police and applying for insurance claims, but has not offered compensation, and some victims are preparing for a class-action lawsuit.

The Issue of Fund Security Resurfaces

Looking back at these incidents, where funds are stored leads to very different outcomes when issues arise.

When stored in centralized exchanges, whether the platform can compensate after being hacked depends on whether the exchange was prepared in advance. Those with protection funds can fully cover losses, but if the fund is valued in crypto assets, its value will also fluctuate with the market. Compensation for defrauded users often requires case-by-case review, and if disputes arise, they may be pushed toward arbitration.

Even if the operator promises to cover losses, users may not be able to quickly retrieve their funds. Before the promise is fulfilled, assets may remain frozen for an extended period.

Choosing a hardware wallet for self-custody allows users to break free from reliance on platforms but also takes on the risks associated with the device and supply chain. Even with correct operations, if the manufacturer's firmware has defects, losses often have to be borne by the users themselves or pursued through litigation.

Attacks such as impersonating customer service and bribing insiders target people, and regardless of where assets are stored, they cannot be avoided.

Regarding how assets should be stored, there has been a long-standing debate in the industry. In August of this year, Ari Paul commented on the theft of Coldcard, stating that whether self-custody or third-party custody, crypto assets cannot be secured. In most developed countries, the legal system's protection of assets is far more reliable than cryptography.

ShapeShift founder Erik Voorhees countered that no asset is absolutely safe, and each storage method has its trade-offs. The key is that users can choose independently and take responsibility for their choices.

Solana Labs co-founder toly believes that crypto assets have various uses. If they are for investment, they should be entrusted to a custodian; if they are to guard against extreme situations, then they are a cost rather than an investment, and one should focus on researching cold storage. The two should not be confused.

Now, Ari Paul has turned his attention to Coinbase. Whether this accusation holds water will depend on evidence and legal proceedings. However, this controversy always presents a question to every holder: when every choice has a cost, where should you put your money?

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.