A fake Coinbase login page stole your credentials. The attacker accessed your account and withdrew crypto. As a US-publicly-traded, FinCEN-registered exchange, Coinbase has the strictest compliance standards — including SSN-level KYC and Chainalysis KYT auto-flagging. This means the attacker's receiving account is identifiable, and Coinbase is legally obligated to respond to our legal requests. We trace and freeze.
Coinbase phishing attacks are sophisticated. The attacker creates a website that replicates Coinbase's clean, minimal login page — coinbase-secure-login.com, coinbase-verify-account.net, or coinbase-support-reset.com. The victim receives a phishing email that mimics Coinbase's exact email template: "Coinbase Security: New Device Login. If this was not you, please verify your account." Coinbase's branding is distinctive and trusted — which makes fake Coinbase emails highly effective.
The SMS 2FA weakness: Many Coinbase users still use SMS-based 2FA (despite Coinbase recommending authenticator apps). SMS 2FA is vulnerable to SIM swap attacks — the attacker doesn't even need to phish your credentials. They SIM-swap your phone, receive the 2FA SMS codes, and access your Coinbase account directly. Coinbase offers authenticator app 2FA and hardware security key (YubiKey) support — both are immune to SIM swaps. If you're using SMS 2FA on Coinbase, switch immediately.
Coinbase's automatic flagging: Unlike most exchanges, Coinbase uses Chainalysis KYT to automatically screen incoming deposits. If the attacker sends stolen funds from your account to another Coinbase account, Coinbase's system may flag the receiving deposit — because the sending address (your compromised Coinbase account) will be associated with suspicious activity. This means the attacker's account may already be "restricted" (Coinbase's term for frozen) before we file a legal request.
The "restricted" terminology: Coinbase rarely uses the word "frozen." They say an account is "restricted" or "under review." This means withdrawals are blocked but the account holder can still log in and see their balance. A restricted account is effectively frozen for recovery purposes — the attacker cannot withdraw.
Compliance structure: Coinbase operates under FinCEN regulation, NYDFS BitLicense, and state money transmitter licenses. As a publicly traded company (NASDAQ: COIN), Coinbase is subject to SEC oversight and must disclose material legal proceedings. This means Coinbase cannot ignore or indefinitely delay legitimate legal requests — shareholder accountability and regulatory oversight require timely responses.
Freeze capability: Coinbase can restrict the attacker's account within 1-5 business days of receiving a court order or law enforcement letter. Coinbase's automated risk system may have already flagged the transfer — in which case the account is already restricted and we just need to formalize the hold. This is faster than any other major exchange.
KYC disclosure: Coinbase collects the most comprehensive KYC of any major exchange: full name, SSN, date of birth, physical address, government ID, and linked bank account (Plaid-verified). Through a subpoena or court order, we can obtain all of this. The linked bank account is critical — if the attacker already withdrew stolen funds to fiat, we can trace and freeze at the bank level. No other exchange offers this.
The CFPB escalation route: As a US financial institution, Coinbase is subject to Consumer Financial Protection Bureau (CFPB) oversight. If Coinbase is unresponsive to a legitimate request involving stolen funds, a CFPB complaint forces Coinbase to respond within 15 days. This is a unique leverage point that doesn't exist with offshore exchanges — and Coinbase takes CFPB complaints seriously because they affect their regulatory standing.
SAR filing: Coinbase files Suspicious Activity Reports (SARs) with FinCEN for flagged transactions. While SARs are not shared with private parties, they create a paper trail that law enforcement can access. If Coinbase filed a SAR on the attacker's account, it strengthens our case when we coordinate with law enforcement.
A client received an email that looked exactly like a Coinbase security alert: "Coinbase: New Device Login from Chrome (Windows). If this was not you, secure your account." The email contained a link to coinbase-secure-device.com. The client clicked the link, entered their email and password on the fake page. The attacker captured the credentials and logged into the real Coinbase.
The attack: The attacker changed the client's password (locking the client out), updated the phone number (disabling SMS 2FA), and initiated a withdrawal of 1.8 ETH (~€6,300) and 45,000 USDT (~€45,000) to an external wallet. Total stolen: ~€51,300.
Coinbase's auto-flag helped: The external wallet that received the funds was already flagged by Chainalysis KYT as associated with phishing attacks. When the attacker sent the funds from the external wallet to a Coinbase deposit address (to cash out), Coinbase's system automatically restricted the receiving account. The attacker's account was "under review" — frozen — before we even filed a request.
Our response: We filed a formal legal request with Coinbase's compliance team, including a police report and blockchain evidence. Coinbase confirmed the restriction and shared the account holder's KYC (name, SSN, address) with law enforcement within 72 hours. The attacker was a US resident — civil litigation was straightforward.
Outcome: 94% recovery (€48,200 of €51,300). Coinbase's automated flagging caught the deposit before the attacker could withdraw. The attacker's account held €48,200 in ETH and USDT when formally frozen. The €3,100 gap was due to ETH price movement. Civil recovery proceedings initiated in US court.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
Was your own Coinbase account restricted? Coinbase may restrict victim accounts after phishing — especially if the attacker used your account to send funds to flagged addresses. Our Coinbase account unlock practice can resolve this.
Warning: After a phishing attack, fake "recovery services" will contact you. Read our recovery scam warning before engaging anyone.
Sometimes. Coinbase uses Chainalysis KYT to screen incoming deposits. If the sending address has been flagged by blockchain analytics as associated with phishing or scams, Coinbase's system may automatically restrict the receiving account. This is a significant advantage — it means the attacker's account may already be frozen before we file a legal request. However, sophisticated attackers use intermediary wallets to break the transaction trail.
1-5 business days for properly formatted legal requests with a court order or law enforcement letter. As a US publicly traded company (NASDAQ: COIN), Coinbase cannot ignore or indefinitely delay legitimate requests — SEC oversight and shareholder accountability require timely responses. In urgent cases with clear evidence of ongoing fund movement, Coinbase has responded within 24 hours.
Yes — through legal process. Coinbase requires linked bank accounts (Plaid-verified) for fiat withdrawals. Through a subpoena or court order, we can identify the attacker's bank and request a freeze at the bank level. US banks are subject to garnishment orders and freezing injunctions. This is a unique advantage of Coinbase cases — if the attacker withdrew to fiat, we can trace and freeze at the bank. No offshore exchange offers this.
This is a common phishing tactic — the attacker changes your phone number to disable SMS 2FA and lock you out. Contact Coinbase support through the official Coinbase app (not a web search, which could lead to another phishing site). Coinbase will require identity verification (government ID video selfie) to restore access. Once restored: switch to authenticator app 2FA (not SMS), change your password, and review all withdrawal history.
Yes. As a US financial institution, Coinbase is subject to CFPB oversight. If Coinbase is unresponsive to a legitimate legal request involving stolen funds, a CFPB complaint can accelerate their response — they must reply within 15 days. We use this as an escalation tool when Coinbase's compliance team is slow or when additional documentation is needed. This leverage doesn't exist with offshore exchanges.
No. SMS 2FA is vulnerable to SIM swap attacks — the attacker doesn't need to phish your credentials. They social-engineer your mobile carrier to port your phone number, receive your 2FA SMS codes, and access your Coinbase account directly. Coinbase offers authenticator app 2FA (Google Authenticator, Authy) and hardware security keys (YubiKey). Both are immune to SIM swaps. Switch from SMS 2FA to an authenticator app immediately — it's the single most important security improvement you can make on Coinbase.
Describe what happened. Include the phishing URL, withdrawal addresses, transaction hashes, and amount stolen. We respond within 6 hours.