Coinbase Tells User Missing $96,000 After Security Breach Is His Problem
bloomberg.com
bloomberg.com
> Ferguson argues that under state and federal laws, Coinbase, the largest US cryptocurrency exchange, bears responsibility for unauthorized withdrawals. But the company has refused to reimburse him, saying in an email that security of passwords and two-factor authentication codes are his responsibility, according to the lawsuit. Two-factor authentication offers extra security by sending a code, usually to a user’s phone or email.
> “Please note you are solely responsible for the security of your e-mail, your passwords, your 2FA codes, and your devices,” Coinbase wrote Ferguson, according to the complaint, filed Monday in San Francisco federal court. “Coinbase’s email disclaimed any responsibility for the hacking of its customers’ accounts,” Ferguson said.
So yes, a reason to keep it at your bank (which is regulated heavily).
[1]https://www.theguardian.com/money/2023/mar/06/i-paid-70000-t...
https://www.consumerfinance.gov/rules-policy/regulations/100...
Not your keys, not your coins. If one has significant savings in bitcoin, one needs to hold the private keys oneself, not trusting any third-party like Coinbase or a bank. Ideally in a geographically distributed multisignature setup to mitigate against loss, user-error, or theft.
Do we know if the OP's 96k was coins sitting on Coinbase, or if he had a linked bank account and the attacker used the SIM card swap attack via Coinbase to drain his bank account?
In a case like that you can reverse the ACH. It's more likely that assets on Coinbase were stolen.
If you don't trust the full faith and credit of the US government, than who do you trust?
https://help.coinbase.com/en/coinbase/getting-started/verify...
Instead Coinbase have decided that it is a sufficiently secure form of identification by which they will assume authorization for payment initiation.
If this users SMS was hacked, then the user didnt authorise payment, and coinbase incorrectly assumed that it was based on their own lax security requirements.
If this was regulated in the same way as a Bank, an EMI or a PISP then Coinbase would definitely be at fault here. I hope the legal system sees it in the same way and this guys assets are returned.
The only 2 large banking institutions I have been working with (Chase and Wells Fargo) do not support OTP 2FA afaik (last time I checked was about a year ago). I think WF might support dedicated hardware 2FA tokens, but you gotta order it from them, and I would rather prefer to use only one device (my phone + printed our backup recovery keys in physical storage + Google/Microsoft Authenticator backup in the cloud). Otherwise, it is all just good old SMS 2FA, and I am not ok with it.
It's freaking mind boggling.
I presume from the article an email account was hacked (password available?), which gave means for a Coinbase password reset, and then a SIM swap occurred on his account leading to a withdrawal.
One might argue Coinbase has a duty to do more here -- nothing on their site (at least the security/mfa section) suggests SMS isn't good enough. PcMagazine[1] suggests 95% of users rely on SMS 2FA/MFA, and Coinbase seems aware that these phishing campaigns are happening against SMS 2FA/MFA [2].
[1]: https://www.pcmag.com/news/95-of-coinbase-users-rely-on-sms-...
[2]: https://www.bankinfosecurity.com/crypto-exchange-coinbase-de...
https://help.coinbase.com/en/coinbase/getting-started/verify...
It would be far better if Coinbase defeated to TOTP for 2FA.