They probably discovered phishing attempts with a link to a page deploying a curious payload.
Regardless of my post above, keep in mind I do use Firefox primarily and see nothing wrong with it.
Nowhere in article it is said that any Coinbase employee was using Firefox. It only says that attack targeted Firefox, not that Coinbase employees use Firefox.
I don't know, maybe because they need to get work done...? Even traditional banks allow JS.
Hint: if your environment feels like a concentration camp, users will find ways to work outside of it most of the time - which will be even more disastrous.
Security is a tradeoff; nuking browsers for everyone is just a bad tradeoff in 2019.