Hackers exploit MFA flaw to steal from 6,000 Coinbase customers — report

Hackers exploit MFA flaw to steal from 6,000 Coinbase customers — report

Cryptocurrency exchange Coinbase has reportedly suffered another security breach after attackers were able to bypass the company’s multi-factor authentication, or MFA, feature in a coordinated campaign earlier this year. 

The attackers stole cryptocurrency from 6,000 accounts, though the monetary value of the theft wasn’t disclosed, according to a report from Bleeping Computer. Earlier this week, Coinbase reportedly notified affected customers that the theft occurred between March and May of this year.

Our top trading bots

To gain access to the accounts, the attackers must have known the affected users’ email address, password and phone number. It’s not clear how the attackers obtained this information, though phishing scams targeting exchange users are not uncommon. However, Coinbase did identify a vulnerability in the account recovery process that the attackers exploited to gain access to the accounts:

“ [...] in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.”

Coinbase, which operates one of the largest crypto exchanges in the world, has received scathing criticism for its poor customer service. As Cointelegraph reported, customers whose accounts were reportedly hacked and drained of funds were unable to access support staff, leading to thousands of complaints against the company.

Related: SEC was the only regulator unwilling to meet with Coinbase: Brian Armstrong

Coinbase’s IPO debuted at $86 billion in April, but the company has been unable to scale its customer service department adequately. In August, the company announced a new support line for customers who believe their account has been compromised.

Continue reading with Cointelegraph
Ex-Goldman Sachs banker launches crypto app after $33M raise
The former Head of Product for “Marcus by Goldman Sachs” has launched a crypto investing app, “Domain Ventures,” raising $33 million from investors on Jan...
Analysis-Amid Bukele's bitcoin hype, not all Salvadorans 'Feel the Bit'
By Sarah Kinosian and Rodrigo CamposSAN SALVADOR (Reuters) - El Salvador's President Nayib Bukele took the stage last weekend at the end of "Bitcoin Week"...
THORSwap hammers home the point: Aligned incentives are a crypto superpower
THORChain hasn’t had an easy year. After three exploits in the space of a month during the summer the protocol’s native token (RUNE) took a beating, plummeting...
‘Free coin to everyone’ project aims to make 1B crypto owners in 2 years
Funded by crypto heavyweights, new crypto unicorn Worldcoin revealed its plan to let everyone claim free coins to accelerate global crypto adoption.Providing...
Bitcoin could hit $37K but trader says BTC price top will be 'number you can't comprehend'
Bitcoin (BTC) sealed another $40,000 retest on Sunday, Sept. 26, as the battle for the weekly close raged on.BTC/USD 1-hour candle chart (Bitstamp). Source:...
Blockchain will transform government services, and that’s just the beginning
Governments are tasked with bringing fair and efficient services to the public. Unfortunately, providing transparency and accountability often results in...
OpenSea bug appears to have destroyed nearly $100K in NFTs
Reports have emerged that a bug on OpenSea's marketplace has deleted user-owned NFTs worth 28.44 Ether (ETH), nearly $100,000 at the time of writing.The...
Bitcoin dominance on the rise once again as crypto market rallies
Bitcoin’s price has been rallying in tandem with altcoins, sending mentions of the markets flipping back to a bullish supercycle for Bitcoin (BTC). The...
Bitcoin traders express mixed emotions about what’s next for BTC price
The rumor that Amazon would accept cryptocurrency payments sparked a wave of bullish enthusiasm across the crypto market earlier in the week but now this...
Bitcoin rally puts $40,000 in view as Amazon steps up crypto push
By Samuel IndykInvesting.com – The price of Bitcoin was approaching $40,000 early on Monday morning after a weekend rally saw the world’s largest cryptocurrency...
Polygon committing $10M to reach 1M users using 0x API
The network onboarding a large number of decentralized applications aims to hit one million users through 0x’s decentralized exchange liquidity aggregator...
Top 5 cryptocurrencies to watch this week: BTC, BNB, ADA, LTC, LINK
Over the past week, several traders bought Dogecoin (DOGE) leading up to Elon Musk’s Saturday Night Live appearance as they expected a pump. However, the...
What are Bitcoin mixers, and why do exchanges ban them?
One of the original allures of cryptocurrency is the narrative that using them provides the sender or recipient anonymously, but this is a common misconception...
NYDIG raises $100 million and launches 'Bitcoin-powered' insurance initiative
New York Digital Investment Group announced the completion of a growth capital funding round as well as the launch of a business initiative relating to...
Polish Central Bank Admits Campaigning Against Cryptos Via YouTube
Bitcoin and its brethren must have tough times as some governments do not only try to tackle them but also run anti-cyber-money campaigns online, to drive...