Hackers Exploit MFA Flaw to Steal From 6,000 Coinbase Customers

2021-10-2 13:32

The giant cryptocurrency exchange informed some customers that they had been victimized by a hack. 

Coinbase has sent thousands of emails to customers informing them of an attack that took place between March and May 2021. The exploit targeted a flaw in the exchange’s two-factor authentication system and saw a significant number of customers affected. 

The email says that “At least 6,000 Coinbase customers had funds removed from their accounts, including you. In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox.”

Coinbase plugging holes and investigating the hack

Coinbase admits that it has yet to determine exactly how these third parties managed to gain access to users’ personal information. However, “this type of campaign typically involves phishing attacks or other social engineering techniques to trick a victim into unknowingly disclosing login credentials to a bad actor. ” says the letter. Coinbase adds that they have found no evidence that the bad actors obtained any personal information from within the Coinbase platform. The letter elaborates on how the authentication works, saying that even with all of the aforementioned personal information, additional authentication would be required to access Coinbase accounts. 

The exchange concluded that customers who use SMS text messages to manage two-factor authentication were targeted specifically. The attackers used a flaw in the SMS account recovery process to be sent a recovery token and take control of user accounts. The email goes on to state, “Once in your account, the third party was able to transfer your funds to crypto wallets unassociated with Coinbase.” Coinbase claims that the issue has since been rectified and the SMS account recovery system will no longer bypass other authentication processes. Happily, for the victims of the theft, Coinbase will be depositing funds into their accounts equal to the amount stolen by the bad actors. 

According to the news, the third-party thieves were able to access personal email, phone numbers, full name, home address, date of birth. The exchange adds that its team has been working with law enforcement to help investigate the individuals involved in the cybercrime. 

What do you think about this subject? Write to us and tell us!

The post Hackers Exploit MFA Flaw to Steal From 6,000 Coinbase Customers appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Safe Exchange Coin (SAFEX) на Currencies.ru

$ 0.0054306 (-0.25%)
Объем 24H $1.742k
Изменеия 24h: 1.41 %, 7d: -8.63 %
Cегодня L: $0.0053635 - H: $0.0055227
Капитализация $6.099m Rank 99999
Доступно / Всего 1.123b SAFEX

customers coinbase exploit hackers mfa flaw steal

customers coinbase → Результатов: 126


Фото:

Coinbase Announces New ‘e-gift Card’ Allowing Users to Spend Cryptos With Nike, Tesco, Uber, and More

Good news for Coinbase users as the trading platform launches a new use for cryptocurrency balances on the exchange. Talking on the platform’s Medium page earlier today, Zeeshan Feroz, the exchange’s UK CEO, wrote that customers of Coinbase in selected regions will now be able to spend their cryptocurrency balances on e-gift cards.

2018-7-25 16:04


Coinbase позволит клиентам конвертировать криптовалюты в подарочные сертификаты

Американская компания Coinbase в партнерстве с лондонским стартапом WeGift позволит клиентам обменивать криптовалютные активы на подарочные сертификаты на товары и услуги более чем 120 ритейлеров. Coinbase will let customers in Europe cash out their crypto coins for gift cards https://t.

2018-7-25 12:51


How Cardano (ADA) Plans to Solve Proof of Stake

Cardano (ADA)–Coming off the positive news of a potential partnership with Coinbase, Cardano’s ADA has benefited from a pump in price over the weekend.  Investors and enthusiasts alike seek to reverse the losses of 2018’s bear cycle, both in anticipation of the buying power of Coinbase’s 13 million+ customers and also in appreciation for what […] The post How Cardano (ADA) Plans to Solve Proof of Stake appeared first on Ethereum World News.

2018-7-15 19:49


New Cryptocurrency Additions, Kraken Trolls as Prices React Coinbase ‘Exploring’

Notes Coinbase: We are making this announcement internally at Coinbase and to the public at the same time to remain transparent with our customers about support for future assets. Coinbase has come under fire in the past — particularly regarding its listing of Bitcoin Cash (BCH), which preceded allegations of insider trading. Today we are

2018-7-14 20:35


The Daily: Akon introduces A

Additional stories include an ICO mogul who bought land worth $19 million with bitcoin, a massive trove of Coinbase customers’ complaints and more. Also Read: Control of Highly Demanded Crypto Classes May Spark Turf War at Universities Akon Launches Akoin Akon, the Senegalese-American singer, is launching his own cryptocurrency token called Akoin. ICO Mogul Buys

2018-6-21 16:45