Coinbase

Coinbase Data Breach Class Action Lawsuit

Coinbase's 2025 data incident, MDL 3153, exposed information, pending allegations, arbitration issues, and practical steps for affected customers.

DeFi Farmer Research Desk

Sep 3, 2026 · 14 min read

In brief. Lawsuits arising from Coinbase's 2025 customer-data incident were centralized for pretrial proceedings in MDL 3153 in the Southern District of New York. Coinbase confirmed improper access to identity and account data while saying passwords, private keys, and customer funds were not compromised through that access. The consolidated claims remain allegations, and no classwide settlement fund should be assumed without a filed order and official administrator site.

On this page13 sections

A fractured customer data layer surrounding a sealed cryptographic key chamber and case documents

coinbase data breach class action lawsuit pages often jump from Coinbase's confirmed incident to a promised payout, even though the federal proceeding is a coordinated multidistrict litigation and the public record needs to be checked before anyone assumes class certification or settlement. Coinbase confirmed that support personnel improperly accessed customer information. Plaintiffs then alleged legal violations and losses. Those are distinct facts.

Treat identity data as durable risk. Lock down email and mobile access, save the official notice, and document every suspicious contact.

Secure the account and preserve evidence

Confirmed incident facts and disputed claims

PointSource statusWhat can be said carefully
Improper access by support personnelCoinbase SEC filingCoinbase said contractors or employees outside the US were paid to collect information from systems they could access for work
Data categoriesCoinbase SEC filing and state noticeContact, partial identity, government-ID, banking, balance, transaction, and internal support information were involved
Passwords and private keysCoinbase SEC filingCoinbase said the incident did not compromise them
Direct fund accessCoinbase SEC filingCoinbase said targeted support personnel could not access customer funds
Legal faultDisputed litigation issuePlaintiffs allege Coinbase failed to safeguard data and assert several legal claims; defendants can contest liability and class treatment
Settlement paymentNo assumption warrantedUse a filed settlement agreement, approval order, and official administrator before believing a payout claim

The difference between an exchange statement and a complaint is simple to miss. A public-company filing can confirm operational facts while preserving uncertainty about scope and impact. A complaint states plaintiffs' allegations. A judge later decides motions under specific legal standards.

  1. 01

    Incident

    Support-role access is allegedly abused and customer information leaves internal systems.

  2. 02

    Disclosure

    Coinbase files with the SEC, sends notices, investigates, and announces reimbursement criteria.

  3. 03

    Litigation

    Customers file complaints in several courts and the JPML centralizes common pretrial questions.

  4. 04

    Resolution

    Motions, discovery, arbitration, class certification, settlement, or trial may resolve different claims at different times.

A data incident can create operational remediation, individual fraud claims, and coordinated litigation on separate tracks.

What Coinbase disclosed

The May 2025 Form 8-K is the cleanest starting point. Coinbase said an unknown threat actor claimed to possess customer-account information and internal documents, then demanded money to avoid disclosure.

According to the filing, the actor appears to have paid multiple contractors or employees in support roles outside the United States. Those people allegedly gathered information from systems they were authorized to use for their jobs, while accessing records without a business need. Coinbase said its monitoring independently detected incidents in prior months and personnel were terminated.

The filing listed these data categories.

  • Names, postal addresses, phone numbers, and email addresses.
  • Last four digits of Social Security numbers for some people.
  • Government identification. Images such as driver's licenses or passports were included.
  • Masked bank-account numbers and some identifiers.
  • Balance snapshots and transaction history.
  • Limited internal documents, training material, and communications visible to support agents.

That collection has unusual social-engineering value. A caller who knows a home address, recent transaction, balance range, and identity-document details can sound convincing without possessing a password.

Coinbase also drew boundaries. It said passwords and private keys were not compromised and that the involved personnel never had access to customer funds. Those statements mean the reported access path did not directly reveal those secrets. They do not make phishing harmless. A victim can still be persuaded to reveal a code or transfer assets voluntarily.

The company's preliminary expense estimate was $180 million to $400 million for remediation and voluntary reimbursements, subject to change. That corporate estimate is separate from damages sought in litigation and separate again from any hypothetical settlement fund.

How many people were affected

The Maine attorney general breach entry reported 69,461 affected people, including about 217 Maine residents. It listed December 26, 2024 as the occurrence date, May 11, 2025 as discovery, and May 30, 2025 as the consumer-notification date.

The filing described insider wrongdoing and one year of IDX credit monitoring and identity-protection services for impacted individuals. It also referenced identity restoration, dark-web monitoring, and an insurance component under the provider's terms.

That count should be tied to the filing date. Investigations can refine totals, and a litigation class can be defined differently from the people in a breach-notification report. A national class proposal may add people who allege downstream loss, while a court can narrow it based on standing, contracts, causation, or state law.

What MDL 3153 means

Customers filed actions in several federal districts after disclosure. The Judicial Panel on Multidistrict Litigation entered an August 7, 2025 transfer order centralizing common pretrial proceedings before Judge Edgardo Ramos in the Southern District of New York.

The panel identified shared factual questions such as when the incident occurred, the adequacy of security practices, notification timing, and alleged damages. Later tag-along cases could be transferred into the MDL when they shared that factual core.

An MDL reduces duplicate discovery and inconsistent pretrial rulings. Individual actions retain their identity unless resolved or otherwise ordered. Cases can eventually return to their original courts for trial, though many MDLs resolve through dispositive rulings or negotiated agreements.

Several labels remain premature unless a court order supports them.

  • Putative class. Plaintiffs ask to represent a group. Certification requires a later decision or a settlement-specific order.
  • Class allegations can survive while some individual claims go to arbitration.
  • A consolidated complaint organizes claims. It is still a pleading.
  • A transfer order addresses case administration. It does not find negligence.

The public MDL docket should be checked for filings after this article's August 24, 2026 document audit. Public mirrors can lag PACER.

Allegations in the consolidated litigation

Public filings describe claims involving negligence, implied contract, unjust enrichment, breach-notification statutes, state consumer-protection laws, and related theories. Plaintiffs seek damages and other relief while alleging inadequate safeguarding and harm from the exposed information.

Some plaintiffs also allege cryptocurrency loss after targeted social engineering. Causation will matter. A court or arbitrator may examine the stolen data, message timing, account controls, transaction authorization, recovery attempts, and intervening events.

The defense can challenge standing, causation, contract terms, arbitration, the legal sufficiency of each claim, and classwide treatment. Coinbase's SEC filing does not concede those elements.

TaskUs appeared in early allegations and related proceedings concerning support personnel. Its 2025 annual report said a January 2026 consolidated class complaint removed TaskUs as a defendant from the Coinbase MDL. A separate Estrada action against TaskUs had its own procedural path. Readers should avoid merging the dockets.

Field noteWhat the docket audit established

I matched Coinbase's Form 8-K, the Maine breach notice, the JPML transfer order, and the MDL docket. I did not inspect a reader's notice, support history, arbitration agreement, or PACER-only sealed material. The article therefore separates company disclosures, plaintiffs' allegations, and entered orders.

Arbitration can change the route

Coinbase user agreements have included arbitration provisions. Their enforceability and scope depend on the version accepted, amendment history, notice, claims, and governing law.

An order compelling one person's claims to arbitration does not automatically decide every MDL plaintiff's position. For example, a New Jersey federal court in Davis v. Coinbase granted a motion to compel arbitration in June 2026 and stayed that individual matter. The agreement and procedural record there matter.

Arbitration may affect forum, procedure, discovery, aggregation, and appeal rights. It does not itself prove or disprove the underlying incident allegations.

Anyone considering an opt-out notice, demand, or lawsuit should have counsel review the actual account agreement and timeline. Screenshots of current terms may differ from the version accepted years ago.

Reimbursement and a lawsuit claim are separate

Coinbase said it intended to reimburse eligible retail customers who sent funds to the threat actor as a direct result of the incident, after verifying facts. That is a voluntary program described by the company.

A litigation claim can assert a different injury, such as identity exposure, mitigation cost, fraud loss, loss of time, or statutory harm. Whether a remedy is legally available varies by jurisdiction and facts.

Keep the company's final written decision. A reimbursement may include conditions or a release. Read before accepting. Never assume that receiving credit monitoring waives a claim, and never assume it preserves every claim either. The operative terms control.

If funds moved onchain, record transaction hashes and destination addresses. Build a timeline with UTC timestamps because email, phone, exchange, and blockchain records may use different time zones. The crypto due diligence guide gives a source hierarchy for preserving evidence.

Security steps for an affected customer

Start with the email account tied to Coinbase. Change its password from a trusted device, sign out unknown sessions, secure recovery channels, and enable phishing-resistant multifactor authentication where available.

Then review the exchange account through a typed bookmark or the official app. Do not enter through an email advertisement. Inspect sessions, devices, API keys, withdrawal addresses, linked bank accounts, and profile changes.

Move mobile service to a carrier PIN and port-out lock. A phone number plus partial identity data can support SIM-swap attempts. SMS remains useful for alerts while stronger authentication should protect account access.

Consider a credit freeze at Equifax, Experian, and TransUnion if US identity information was involved. A freeze restricts new-credit access and can be lifted when needed. A fraud alert is a different control. Use the bureaus' official domains and retain confirmation codes.

Government-ID images create long-lived exposure. Ask the issuing authority what replacement or monitoring options apply. Procedures vary by state and document type.

Keep funds in a self-custody wallet only when you can secure its seed phrase and transaction approvals. Moving assets in panic can introduce new risk. Review what a seed phrase protects before changing custody.

Coinbase breach checklist

  1. Verify the notice

    Compare the sender, date, affected data, and support path with Coinbase's official app and state-filed notice.

  2. Secure email and mobile service

    Replace reused passwords, revoke unknown sessions, protect recovery accounts, and enable a carrier port lock.

  3. Audit Coinbase access

    Review devices, API keys, withdrawal addresses, linked accounts, identity details, and support tickets.

  4. Freeze credit when appropriate

    Use each official bureau, store the PINs securely, and monitor statements and identity records.

  5. Preserve a UTC timeline

    Save notices, full email headers, call logs, chat transcripts, transaction hashes, bank records, and screenshots.

  6. Report unauthorized activity

    Contact Coinbase and relevant financial institutions through verified channels. File reports with law enforcement or regulators when appropriate.

  7. Check the court record

    Use MDL number 3153 and the Southern District of New York docket. Distrust ads promising an unannounced settlement payment.

Phishing scripts to expect

One script claims an account is under attack and instructs the user to move assets to a “safe” wallet. The attacker controls that address.

Another asks the customer to “verify” a seed phrase or one-time code because the breach exposed credentials. Coinbase said the incident did not expose passwords or private keys. No support agent needs those secrets.

A third imitates a law firm or claims administrator, promising a settlement payment after a wallet connection or processing fee. There is no reason to sign a token approval to receive a conventional class-action payment.

Calls become persuasive when the caller cites a real balance or transaction. Hang up. Open a known channel separately. This small pause is worth more than arguing with the caller.

Report malicious token approvals quickly and use the token approval checker guide to understand revocation. Revoking an approval cannot reverse an already completed transfer.

When to consult counsel

Speak with a lawyer if substantial assets were transferred after a targeted contact, Coinbase denied reimbursement, an arbitration deadline is approaching, or identity theft produced measurable loss.

Counsel may also help when a business account, trust, minor, deceased owner, or non-US resident is involved. Class definitions and contract rights can treat those situations differently.

Do not publish evidence in a public thread. Account balances, transaction timing, phone numbers, ticket IDs, and partial documents can help another attacker refine the story.

Three things to do

  • Freeze the attacker's easiest recovery routes, beginning with email and mobile service.
  • Preserve the official notice and a timestamped loss record.
  • Track MDL 3153 through court sources before believing settlement advertising.

Coinbase data breach class action lawsuit FAQ

Is there a Coinbase data breach settlement?

Do not assume one. The 2025 cases were centralized in MDL 3153 for pretrial proceedings. Verify any later settlement through a filed agreement, court approval order, and administrator site linked from the docket.

Were Coinbase private keys stolen?

Coinbase's May 2025 Form 8-K said passwords and private keys were not compromised through the incident and the involved support personnel could not directly access customer funds.

What customer information was exposed?

Coinbase listed names, addresses, phone numbers, emails, partial Social Security numbers, masked banking information, government-ID images, account balance snapshots, and transaction history among the involved data.

How many customers were affected?

A filing published by the Maine attorney general reported 69,461 affected people. Treat that as a dated breach-notification figure rather than a final litigation-class count.

Does joining a class action replace a Coinbase reimbursement request?

They are separate processes. A voluntary reimbursement decision, individual arbitration, and putative class claims can have different standards and releases. A lawyer should review significant losses and any proposed waiver.

Sources

Exposed identity and account details can make a false support call feel credible. Verify every contact through a separate channel.

Recognize targeted wallet scams
DeFi Farmer

DeFi Farmer Research Desk

Source-first research for safer onchain decisions.

Keep reading

All articles

Get the next field guide

New protocol research, risk checks, and practical DeFi tools.

Join the newsletter