the coinbase compromise was way worse than they made it seem apparently offsite customer service reps had full database access to transaction history, including bitcoin addresses, home addresses, phone numbers, emails, and bank info image

Replies (57)

Bilthon's avatar
Bilthon 1 year ago
Good old KYC (Kill Your Customer)
I don't doubt that. Moreso it'd be cool for them to push some educational materials to customers that'd help in the event of this type of breach. No one is "unhackable" but I'm guessing the answer is just offsite multisig.
Citizen's avatar
Citizen 1 year ago
#KYC is one, if not THEbiggestt, security risks...
will consider, it is difficult because there is no “one size fits all” advice highly recommend multisig for large holders, anchorwatch is a solid option for less technical users, they hold your hand through the process and insurance covers theft onchain privacy is an important piece as well and home security in general, cameras, guns, etc - don’t be a soft target
If only someone in their support department had warned them this was stupid and risky when they were first set this up years ago, maybe they would have listened… Oh yeah, it’s Coinbase. They care as much for their support reps as they do their customers, so that’s a big fat nope.
Odell could've posted this to X and played the game of centralised algorithms, probably would've got a bigger audience but has made a conscious choice to be the change he wants to see in the world.
But why were they on Coinbase :-) .. wasn't they the "self custody" supremo ? May be I am wrong .. Lesson - don't listen to the GURUs 😭😭😭 .. oh may be it is a free promo .
My family rents mainly because we feel morally conflicted in increasing M2 money supply to purchase a home, and I’m not selling 🌽 to buy a house. But beyond that, companies make you put in your address for everything nowadays, and things are shipped to you all the time. Until personal data is taken seriously and secured uncompromisingly, staying on the move through renting is just another layer of opsec. View quoted note →
For God's sake, why does Brian (naked mole rat) Armstrong even have a job still?
Default avatar
Roboto 1 year ago
Horrendous. Fuck centralization!
It is a breach of Least Privilege, which is a fundamental cybersecurity principle. An egregious error on Coinbase's part. Anyone with even just a Sec+ (i.e., me) knows this.
I started getting fake text messages and calls from “coinbase support” today saying someone logged into my account from Paris. I haven’t used coinbase since like 2019.
bjorn's avatar
bjorn 1 year ago
How do we know they had such access?
Lucas M's avatar
Lucas M 1 year ago
I got one a few weeks ago saying it was logged into from Tokyo even though I deleted my account ages ago.
Lucas M's avatar
Lucas M 1 year ago
I don't mind it if it's with a trusted company like Strike. But, I would never leave more than $100 on ANY exchange. That's for sure.
Lucas M's avatar
Lucas M 1 year ago
I'm aware. That's why I said i barely keep any money on an exchange. To be clear, I don't use Strike for purchases. I use Robosats for that. I just use strike to pay bills with whatever cash balance is needed.
Lucas M's avatar
Lucas M 1 year ago
A lot of people are intimidated by the purchasing process. It's much easier than it seems, though.