Bitcoin Forum

Economy => Service Discussion => Topic started by: damiano on December 02, 2013, 08:00:58 PM



Title: My Coinbase was just compromised
Post by: damiano on December 02, 2013, 08:00:58 PM
As the title states. 

I have SMS verification and Google 2FA on the account.

Here is the hash/txid

https://blockchain.info/tx/5ed1434a78fcba878f18693f63e7ddaf98f0154d77e6ffa84f32dfa1395c2060

It's been almost 3 hours since I submitted a support ticket and still nothing




Title: Re: My Coinbase was just compromised
Post by: goxed on December 02, 2013, 11:30:27 PM
As the title states. 

I have SMS verification and Google 2FA on the account.

Here is the hash/txid

https://blockchain.info/tx/5ed1434a78fcba878f18693f63e7ddaf98f0154d77e6ffa84f32dfa1395c2060

It's been almost 3 hours since I submitted a support ticket and still nothing



This doesn't bode well. :(


Title: Re: My Coinbase was just compromised
Post by: damiano on December 03, 2013, 12:09:58 AM
As the title states. 

I have SMS verification and Google 2FA on the account.

Here is the hash/txid

https://blockchain.info/tx/5ed1434a78fcba878f18693f63e7ddaf98f0154d77e6ffa84f32dfa1395c2060

It's been almost 3 hours since I submitted a support ticket and still nothing



This doesn't bode well. :(

Still no response from anyone. 

I just got off the phone with Wells Fargo and they froze everything.





Title: Re: My Coinbase was just compromised
Post by: pdawg on December 03, 2013, 02:19:49 AM
Sounds like you did not get an SMS confirmation, so it was not logged in via 2FA?  So then they are internally compromised.  So much for cold storage wallets they claim to be using???


Title: Re: My Coinbase was just compromised
Post by: geofflosophy on December 03, 2013, 02:49:36 AM
Scary stuff, I'm watching closely.


Title: Re: My Coinbase was just compromised
Post by: crazy_rabbit on December 03, 2013, 02:58:07 AM
As the title states. 

I have SMS verification and Google 2FA on the account.

Here is the hash/txid

https://blockchain.info/tx/5ed1434a78fcba878f18693f63e7ddaf98f0154d77e6ffa84f32dfa1395c2060

It's been almost 3 hours since I submitted a support ticket and still nothing




I don't quite understand- what happened?


Title: Re: My Coinbase was just compromised
Post by: BitcoinWalker on December 03, 2013, 03:22:24 AM
Looks like the coins were sent out from his account without permission. But a lot of people are making claims like this one so the truth can't be told.


Title: Re: My Coinbase was just compromised
Post by: damiano on December 07, 2013, 05:08:18 PM
Here is a brief update.

I have spoken to Olaf once and it wasn't very productive conversation.  I believe my 2FA code was stolen (neglegence on my part was keeping it around in the first place)

I just woke up to find my checking account with Wells Fargo to be 100% drained with overdraft kicking in,

My Coinbase account was linked to a savings account which was linked to a Wells Fargo Visa.  On Monday 12/02/13 I spoke with Wells Fargo and they froze both accounts.  On Wednesday they attempted to withdraw and failed.  Now this morning I woke up and found my checking account drained with overdraft kicking in

When I first signed up with Coinbase this year I had linked my checking account, but within a month I DELETED IT and relinked a savings instead.

My CHECKING account wasn't even being listed at all on Coinbase, but it appears they keep that information..

I still cant reach Olaf, I messaged him on here as well and submitted a new ticket.



Title: Re: My Coinbase was just compromised
Post by: bitmarket.io on December 07, 2013, 05:11:21 PM
Here is a brief update.

I have spoken to Olaf once and it wasn't very productive conversation.  I believe my 2FA code was stolen (neglegence on my part was keeping it around in the first place)

I just woke up to find my checking account with Wells Fargo to be 100% drained with overdraft kicking in,

My Coinbase account was linked to a savings account which was linked to a Wells Fargo Visa.  On Monday 12/02/13 I spoke with Wells Fargo and they froze both accounts.  On Wednesday they attempted to withdraw and failed.  Now this morning I woke up and found my checking account drained with overdraft kicking in

When I first signed up with Coinbase this year I had linked my checking account, but within a month I DELETED IT and relinked a savings instead.

My CHECKING account wasn't even being listed at all on Coinbase, but it appears they keep that information..

I still cant reach Olaf, I messaged him on here as well and submitted a new ticket.



Your bank will cancel all transactions from coinbase if the requested amount puts your account in the negative.  It may say your account is in the negative while the transaction is pending, but the closer it gets to that delivery date the sooner they will cancel the transaction.

Had the same thing happen to me. I accidentally placed a huge order from my phone app while i checking prices.


Title: Re: My Coinbase was just compromised
Post by: damiano on December 07, 2013, 05:14:51 PM
Here is a brief update.

I have spoken to Olaf once and it wasn't very productive conversation.  I believe my 2FA code was stolen (neglegence on my part was keeping it around in the first place)

I just woke up to find my checking account with Wells Fargo to be 100% drained with overdraft kicking in,

My Coinbase account was linked to a savings account which was linked to a Wells Fargo Visa.  On Monday 12/02/13 I spoke with Wells Fargo and they froze both accounts.  On Wednesday they attempted to withdraw and failed.  Now this morning I woke up and found my checking account drained with overdraft kicking in

When I first signed up with Coinbase this year I had linked my checking account, but within a month I DELETED IT and relinked a savings instead.

My CHECKING account wasn't even being listed at all on Coinbase, but it appears they keep that information..

I still cant reach Olaf, I messaged him on here as well and submitted a new ticket.



Your bank will cancel all transactions from coinbase if the requested amount puts your account in the negative.  It may say your account is in the negative while the transaction is pending, but the closer it gets to that delivery date the sooner they will cancel the transaction.

Had the same thing happen to me. I accidentally placed a huge order from my phone app while i checking prices.

The funds are withdrawn and gone.  I had to file a dispute. 


Title: Re: My Coinbase was just compromised
Post by: michiganmushrooms on December 07, 2013, 06:28:43 PM
This is scary stuff... Please keep us updated on all this. I would be very interested to hear if any others had issues like this(bad actors getting into check/save accounts).


Title: Re: My Coinbase was just compromised
Post by: Martijnvdc on December 07, 2013, 07:28:37 PM
Oh god... Not a second inputs.io...
Here we go again.


Title: Re: My Coinbase was just compromised
Post by: kireinaha on December 07, 2013, 09:44:25 PM
Doesn't make sense. How can a 2FA be stolen? It's a randomly generated value and only valid for a matter of seconds.

Unless you select Coinbase's option to not require 2FA again for 30 days from the same computer? If that PC is compromised with a keylogger, then it could be a problem.


Title: Re: My Coinbase was just compromised
Post by: Martijnvdc on December 07, 2013, 09:52:36 PM
Doesn't make sense. How can a 2FA be stolen? It's a randomly generated value and only valid for a matter of seconds.

Unless you select Coinbase's option to not require 2FA again for 30 days from the same computer? If that PC is compromised with a keylogger, then it could be a problem.
It could be compromised from inside Coinbase itself. Just like with the so called "inputs.io hack".


Title: Re: My Coinbase was just compromised
Post by: naphto on December 07, 2013, 09:55:09 PM
Did you activate 2FA and SMS before the hack? ::)


Title: Re: My Coinbase was just compromised
Post by: damiano on December 07, 2013, 10:02:41 PM
Doesn't make sense. How can a 2FA be stolen? It's a randomly generated value and only valid for a matter of seconds.

Unless you select Coinbase's option to not require 2FA again for 30 days from the same computer? If that PC is compromised with a keylogger, then it could be a problem.

Every time I enabled a 2FA I would take a screen shot of the code and keep it.  I believe it was either taken from my email or my desktop.  I only found some malware on my desktop, but then I said fuck it and wiped the whole disk.





Title: Re: My Coinbase was just compromised
Post by: damiano on December 07, 2013, 10:04:36 PM
Did you activate 2FA and SMS before the hack? ::)

Both were active before it of course.

Although this week SMS doesn't work for me anymore.

I have to do the phone call where they tell me the code


Title: Re: My Coinbase was just compromised
Post by: balanghai on December 07, 2013, 10:30:50 PM
So how was this possible? Coinbase employee needs to make ends meet?


Title: Re: My Coinbase was just compromised
Post by: Martijnvdc on December 07, 2013, 10:36:00 PM
Does anybody know if there have been any similar reports?
This seems like quite a serious issue...


Title: Re: My Coinbase was just compromised
Post by: michiganmushrooms on December 08, 2013, 01:34:57 PM
This is an extremely serious issue! And I'm really surprised it's not getting more traction on the board here... I guess everyone is used to bitcoin services being inherently unsafe. But wasn't coinbase 'supposed to be different'?


Title: Re: My Coinbase was just compromised
Post by: vm1990 on December 08, 2013, 02:52:03 PM
This is an extremely serious issue! And I'm really surprised it's not getting more traction on the board here... I guess everyone is used to bitcoin services being inherently unsafe. But wasn't coinbase 'supposed to be different'?

coinbase sucks ass... the only person that has a chance to keep coins remotely safe is yourself.... if you take the correct steps ofcorse
your basically asking strangers to keep hold of your money and defend it for free...

anyhow sorry for your loss and in theory coinbase should refund you... in theory.


Title: Re: My Coinbase was just compromised
Post by: btcton on December 08, 2013, 03:54:32 PM
Login to Coinbase, go to history and check if it says you actually bought coins with them. Something similar happened to me. In te transaction history it said I "sent" Coinbase BTC to exchange for USD, but it does not appear in history. I also have not received any money from Coinbase and never wanted to sell my BTC. Luckily for me, I only lost around $1.50 worth of BTC because I only use web wallets for convenience and I usually put all I have in my local wallet/cold storage.


Title: Re: My Coinbase was just compromised
Post by: axilla on December 08, 2013, 06:54:54 PM
not surprising.. its not called Conbase for nothing.


Title: Re: My Coinbase was just compromised
Post by: zackclark70 on December 08, 2013, 06:59:43 PM
a big hack would explain the huge btc drop the last couple of days 


Title: Re: My Coinbase was just compromised
Post by: takagari on December 09, 2013, 12:07:36 AM
Why were you taking screen caps?


Title: Re: My Coinbase was just compromised
Post by: damiano on December 09, 2013, 06:36:25 PM
Doesn't make sense. How can a 2FA be stolen? It's a randomly generated value and only valid for a matter of seconds.

Unless you select Coinbase's option to not require 2FA again for 30 days from the same computer? If that PC is compromised with a keylogger, then it could be a problem.

Every time I enabled a 2FA I would take a screen shot of the code and keep it.  I believe it was either taken from my email or my desktop.  I only found some malware on my desktop, but then I said fuck it and wiped the whole disk.





Keeping a screenshot of the 2FA code in a place that itself is not protected is almost as dangerous as not having 2FA in the first place.

I suspect that Coinbase may stop allowing instant purchases + instant withdrawals to an external address because of incidents like this.

I am aware of that now.

I think moving forward I will keep a copy on a flash drive, so its offline.





Title: Re: My Coinbase was just compromised
Post by: pbody on December 09, 2013, 07:32:57 PM
What am I missing here? 2FA constantly changes. Taking a snapshot of it is pointless and will not compromise the account.


Title: Re: My Coinbase was just compromised
Post by: damiano on December 09, 2013, 07:38:10 PM
What am I missing here? 2FA constantly changes. Taking a snapshot of it is pointless and will not compromise the account.

Your missing quite a bit.  I just tested this with a dummy account on cex.io, go ahead and try it.



Title: Re: My Coinbase was just compromised
Post by: pbody on December 14, 2013, 11:41:35 PM
I believe I am dealing with the same issue. coinbase pulled the money out of my bank account and I am yet to recieve anything after a week. there used to be a pending message that suddenly disappeared and now there is nothing. I was not robbed. I never even had the btc. Coinbase just lost my btc. Now Im dealing with the extreme headache of trying to get it back.

I would steer clear from this place and use localbitcoins with a wallet on your personal pc.  At least you get the transaction completely instantly and can immediately get your btc to safety.

Using Coinbase is like running through South Central LA with a wad of cash and a shirt with a huge dollar sign on it. Kiss your money goodbye.


Title: Re: My Coinbase was just compromised
Post by: btcton on December 15, 2013, 04:49:25 AM
Login to Coinbase, go to history and check if it says you actually bought coins with them. Something similar happened to me. In te transaction history it said I "sent" Coinbase BTC to exchange for USD, but it does not appear in history. I also have not received any money from Coinbase and never wanted to sell my BTC. Luckily for me, I only lost around $1.50 worth of BTC because I only use web wallets for convenience and I usually put all I have in my local wallet/cold storage.
I got this fixed, not their fault. Anyway, they're back on the green for me.


Title: Re: My Coinbase was just compromised
Post by: pbody on December 15, 2013, 06:32:51 AM
Login to Coinbase, go to history and check if it says you actually bought coins with them. Something similar happened to me. In te transaction history it said I "sent" Coinbase BTC to exchange for USD, but it does not appear in history. I also have not received any money from Coinbase and never wanted to sell my BTC. Luckily for me, I only lost around $1.50 worth of BTC because I only use web wallets for convenience and I usually put all I have in my local wallet/cold storage.

Im on the same boat as the OP. I logged into coinbase and it showed I had made a purchase under buy history. I checked back later in the day and now that has been deleted! So the only proof I have is a printout of the screen and my checking account shows the money being sent to Coinbase. All week it was listed as pending until 12/14. Now there is nothing. The transaction just vanished.

I would not be posting here if Coinbase responded to my email other than an automated response. There is no way to get in contact with them.

I am warning others to be cautious. I met the guys who run Coinbase and I imagine that they would have gotten back to me if something was not seriously wrong.


Title: Re: My Coinbase was just compromised
Post by: damiano on December 15, 2013, 04:03:26 PM
Coinbase customer service is piss poor.  There simply isn't enough customer service techs or peeps (what ever you want to call them) to handle all the volume.

Ultimately if they can't pull it together for the long run they will fail.  There are a lot of smaller up and coming companies with  a similar model.



Title: Re: My Coinbase was just compromised
Post by: whiskers75 on December 15, 2013, 04:12:22 PM
Doesn't make sense. How can a 2FA be stolen? It's a randomly generated value and only valid for a matter of seconds.

Unless you select Coinbase's option to not require 2FA again for 30 days from the same computer? If that PC is compromised with a keylogger, then it could be a problem.

Every time I enabled a 2FA I would take a screen shot of the code and keep it.  I believe it was either taken from my email or my desktop.  I only found some malware on my desktop, but then I said fuck it and wiped the whole disk.





Keeping a screenshot of the 2FA code in a place that itself is not protected is almost as dangerous as not having 2FA in the first place.

I suspect that Coinbase may stop allowing instant purchases + instant withdrawals to an external address because of incidents like this.
STOP PANICKING!

OP just screencap'd the 2FA code, which is a stupid idea, and lost it. Caveat emptor.


Title: Re: My Coinbase was just compromised
Post by: pbody on December 15, 2013, 06:40:34 PM
Coinbase customer service is piss poor.  There simply isn't enough customer service techs or peeps (what ever you want to call them) to handle all the volume.

Ultimately if they can't pull it together for the long run they will fail.  There are a lot of smaller up and coming companies with  a similar model.



There is no support. I have been trying to get a hold of them for days and all I get is an automated response. I agree with you that if they do not get their act together adn wake up to realize that customer service is HUGE when dealing with people's money, they will quickly go out of business. They have no listing for a customer service tech support rep on their site. Seriously idiotic move.

Cryptsy got back to me within 2 hrs and followed up with the issue. I'm gaining more trust in some of the European exchanges. Nice thing about btc is that it can easily be moved anywhere, and is actually way faster on the other exchanges than it is on coinbase.