A security researcher, Jonathan Clark, has publicly challenged Coinbase's official timeline regarding a major data breach that exposed sensitive information of nearly 70,000 customers. Clark claims he was targeted by scammers on January 7, 2025, who possessed detailed personal and financial information that should have only been accessible through Coinbase, including his Social Security number and exact Bitcoin balance. He immediately reported the incident to Coinbase, receiving an initial acknowledgment from the company's Head of Trust & Safety, but received no further response despite multiple follow-ups.
Coinbase later disclosed to the US Securities and Exchange Commission in May 2025 that the breach occurred on December 26, 2024, but was not discovered until May 11, 2025, when attackers attempted to extort the company for $20 million. Clark disputes this timeline, providing emails and call records as evidence that the breach was known to Coinbase months before their public disclosure. The incident raises serious questions about Coinbase's breach notification practices and the security of customer data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The Register covered the researcher's claims that Coinbase's breach disclosure timeline was inaccurate, amplifying allegations that the attack activity predated the company's stated discovery date by months. The article did not add a separate confirmed incident date beyond the dispute itself.
A security researcher published recordings and emails alleging that attacks tied to the Coinbase breach started months before the company's stated discovery timeline. The report challenges Coinbase's public account of when the incident began.
2 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcejonathanclark.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.