Bitcoin Forum

Economy => Service Discussion => Topic started by: WhiteyZ on April 01, 2014, 08:43:11 AM



Title: Strange mail from Coinbase...
Post by: WhiteyZ on April 01, 2014, 08:43:11 AM
Hello @all, few minutes ago i recieved this mail:


Coinbase   
Hi xxx@xxx.com,

coinbasehack@mailinator.com just sent you a request to pay 732342.34425 BTC (worth $361,393,399.96 USD) using Coinbase.

Click here to create an account and complete this payment
Quote
https://coinbase.com/password_resets/xxxxxxxxxxxxxxxxxxxxx/edit

Kind regards,
The Coinbase Team


I have no account @ coinbase... Where did they get my email from? Has anyone an idea what they try to do? The email-adress sending this email is: contact@coinbase.com
The subject is: coinbasehack@mailinator.com sent you a payment request for 732342.34425 BTC

What should i do? I havnt clicked any link or something...


Title: Re: Strange mail from Coinbase...
Post by: huishipai on April 01, 2014, 09:04:40 AM
I think that is a scam. Maybe their motive is to know if the email their sending has bitcoin in coinbase so they can hack it. My advise is don't bother to enter any information to them even to log in with their links. :)


Title: Re: Strange mail from Coinbase...
Post by: Elwar on April 01, 2014, 09:05:21 AM
I know I can send bitcoins to someone from coinbase having just their e-mail. Perhaps someone can send a request in the same way.



Title: Re: Strange mail from Coinbase...
Post by: crazy987 on April 01, 2014, 09:08:17 AM
are you sure the link is going to coinbase?
Its a popular way to scam people.


Title: Re: Strange mail from Coinbase...
Post by: SackofBits on April 01, 2014, 09:08:22 AM
Hello @all, few minutes ago i recieved this mail:


Coinbase   
Hi xxx@xxx.com,

coinbasehack@mailinator.com just sent you a request to pay 732342.34425 BTC (worth $361,393,399.96 USD) using Coinbase.

Click here to create an account and complete this payment
Quote
https://coinbase.com/password_resets/xxxxxxxxxxxxxxxxxxxxx/edit

Kind regards,
The Coinbase Team


I have no account @ coinbase... Where did they get my email from? Has anyone an idea what they try to do? The email-adress sending this email is: contact@coinbase.com
The subject is: coinbasehack@mailinator.com sent you a payment request for 732342.34425 BTC

What should i do? I havnt clicked any link or something...


I just got the same email.. I also don't have an account at coinbase.

Are you on localbitcoins.com by any chance?


Title: Re: Strange mail from Coinbase...
Post by: SackofBits on April 01, 2014, 09:10:08 AM
even though I got the same message mine is from coinbasehacked@mailinator.com

similar email probably the same person i'm sure


Title: Re: Strange mail from Coinbase...
Post by: alani123 on April 01, 2014, 09:13:11 AM
I got those too. I just loged into coinbase and decline a coule of payment requests. I wonder where they got my email from.


Title: Re: Strange mail from Coinbase...
Post by: krystalwhite on April 01, 2014, 10:08:33 AM
Hi All,

I received the same email just under an hour ago.

Have deleted it as I don't use Coinbase as, at the time I signed up, they only accepted US Bank account details. 

However the email had my full name on it so they must have hacked the site to obtain this information.

Have deleted the email.

Cheers

KW


Title: Re: Strange mail from Coinbase...
Post by: C10H15N on April 01, 2014, 03:12:48 PM
It appears the Coinbase customer name/email address data is now in the wild:

https://dl.dropboxusercontent.com/u/64422931/coinbasehack.jpg


Title: Re: Strange mail from Coinbase...
Post by: seventie on April 01, 2014, 03:48:29 PM
i think just request money with the username URGENT: Coinbase hacked. We


Title: Re: Strange mail from Coinbase...
Post by: C10H15N on April 01, 2014, 04:14:41 PM
I would imagine the Coinbase staff has been slamming Starbucks since 2 AM. 


Title: Re: Strange mail from Coinbase...
Post by: pr0d1gy on April 01, 2014, 04:17:13 PM
Seems like it could be numerous reasons...

http://blog.shubh.am/full-disclosure-coinbase-security/

https://hackerone.com/coinbase

Damn it coinbase... Please don't be Gox 2.0


PS - I blame it on this guy: http://blog.coinbase.com/post/80711658417/welcome-ryan-mcgeehan-and-todd-edebohls-to-coinbase

Who hires security from Facebook to look over your money? lol


Title: Re: Strange mail from Coinbase...
Post by: C10H15N on April 01, 2014, 04:20:12 PM
Damn it coinbase... Please don't be Gox 2.0

Seriously, we need at least one BTC business that's not a complete f**k up. 


Title: Re: Strange mail from Coinbase...
Post by: vayvanne on April 01, 2014, 04:44:42 PM
Here is one I have received:
http://s22.postimg.org/8hydw87xd/coinbase.png
Links to coinbase are real. I do not remember I used coinbase but anyway password remind email does not come and a try to register was failed.


Title: Re: Strange mail from Coinbase...
Post by: pr0d1gy on April 01, 2014, 04:57:39 PM
https://i.imgur.com/cm9XLUY.jpg

I got emails, and even pending stuff in account... smh...


Title: Re: Strange mail from Coinbase...
Post by: C10H15N on April 01, 2014, 05:04:25 PM
Coinbase has a mess to clean up.   :P


Title: Re: Strange mail from Coinbase...
Post by: CurbsideProphet on April 01, 2014, 05:19:25 PM
What I want to know is where the hackers got the email addresses from.  The links are legit, they're originating from Coinbase but some users here don't even have an account so it has to be a leak from somewhere else.  Gox database maybe?


Title: Re: Strange mail from Coinbase...
Post by: OnkelPaul on April 01, 2014, 05:21:12 PM
I got those too. I just loged into coinbase and decline a coule of payment requests. I wonder where they got my email from.

Sure you logged into coinbase and not into a lookalike phishing site?

Onkel Paul


Title: Re: Strange mail from Coinbase...
Post by: pr0d1gy on April 01, 2014, 05:21:36 PM
Coinbase has a mess to clean up.   :P

Yea, BP oil spill sized mess...


https://i.imgur.com/Kbcv2jM.png
https://twitter.com/coinbase/statuses/451043329153572864

but then in replies you see...

http://pastebin.com/RzWipJFb


smh, hope its all April fools jokes or something... Definitely not funny...


Title: Re: Strange mail from Coinbase...
Post by: ajw7989 on April 01, 2014, 05:46:21 PM
I received 3 payment requests similar to you guys from mailinator. I talked to support and they said somehow they got our email and just can use that to send requests. Just decline the requests and no harm done. When I first logged in i was a little nervous but no big deal they spammed out coinbase like they would your email


Title: Re: Strange mail from Coinbase...
Post by: alani123 on April 01, 2014, 06:20:21 PM
I got those too. I just loged into coinbase and decline a coule of payment requests. I wonder where they got my email from.

Sure you logged into coinbase and not into a lookalike phishing site?

Onkel Paul

Yup. The links were real. Linking to the actualcoinbase.com domain. And besides that, any withdrawal would have to be confirmed through my email. Also access to my account from a diferent IP would send a SMS message to my phone for verification.


Title: Re: Strange mail from Coinbase...
Post by: CurbsideProphet on April 01, 2014, 06:20:33 PM
I received 3 payment requests similar to you guys from mailinator. I talked to support and they said somehow they got our email and just can use that to send requests. Just decline the requests and no harm done. When I first logged in i was a little nervous but no big deal they spammed out coinbase like they would your email

My advice would be to not deny the payment just yet, you might want to leave it sit.  What they're probably doing is phishing to see who has a Coinbase account and/or who is active on their account.  If you deny the payment it will let them know that you have an active Coinbase account and will likely lead to more spam.  Just my thoughts.  So long as you don't pay them, having the request sit shouldn't do anything.  Coinbase should be the ones removing.


Title: Re: Strange mail from Coinbase...
Post by: SackofBits on April 01, 2014, 07:04:35 PM
I received 3 payment requests similar to you guys from mailinator. I talked to support and they said somehow they got our email and just can use that to send requests. Just decline the requests and no harm done. When I first logged in i was a little nervous but no big deal they spammed out coinbase like they would your email

My advice would be to not deny the payment just yet, you might want to leave it sit.  What they're probably doing is phishing to see who has a Coinbase account and/or who is active on their account.  If you deny the payment it will let them know that you have an active Coinbase account and will likely lead to more spam.  Just my thoughts.  So long as you don't pay them, having the request sit shouldn't do anything.  Coinbase should be the ones removing.


+1!


Title: Re: Strange mail from Coinbase...
Post by: pr0d1gy on April 01, 2014, 07:49:27 PM
http://blog.coinbase.com/post/81407694500/update-on-coinbase-data-security


Title: Re: Strange mail from Coinbase...
Post by: r3wt on April 01, 2014, 08:15:35 PM
I received 3 payment requests similar to you guys from mailinator. I talked to support and they said somehow they got our email and just can use that to send requests. Just decline the requests and no harm done. When I first logged in i was a little nervous but no big deal they spammed out coinbase like they would your email

some big name will have been a target of this, and will sue the pants off of coinbase, and they will likely win a dispute. it doesn't matter what your terms of service say in the financial payments industry, the onus is on you(the company) to safeguard customer data, including a person's legal name.

you can't just have a form where anyone can enter an email and reveal the account holders legal name. that's lunacy. what on earth were they thinking? this isn't facebook, this is finance.


Title: Re: Strange mail from Coinbase...
Post by: alani123 on April 01, 2014, 08:34:32 PM
Sue coinbase for someone knowing the name asociated with their email? Coinbase even allows you to use a fake username to be displayied in public. And even if they do get the name associated with the accounts, that about all the information they're going to get. Coinbase does off chain transactions and you can't track a user's transaction data.

Maybe the fact that emails can be collected for phising is bad but there was no sensible user data leaked.


Title: Re: Strange mail from Coinbase...
Post by: C10H15N on April 01, 2014, 08:43:45 PM
Rather poor PR to throw a POS TOS in customer's faces as an excuse for this debacle.

Arrogance is obviously exceeding intelligence.   ::)


some big name will have been a target of this...

One can hope some of the large Coinbase private investors were included in the spamming. 


Title: Re: Strange mail from Coinbase...
Post by: clownius on April 02, 2014, 04:55:39 AM
Considering people who have not used Coinbase and dont have an account there are getting these emails....

WTF makes you think its Coinbases fault that names and email addresses leaked?  Its more probable they got the details from another source