I have recordings proving Coinbase knew about breach months before disclosure
Mood
controversial
Sentiment
negative
Category
security
Key topics
Coinbase
data breach
security disclosure
The Hacker News discussion revolves around a post claiming to have recordings that prove Coinbase knew about a security breach months before disclosing it. Although the top comments are not available, the discussion likely centers on the implications of the alleged delayed disclosure and potential accountability. The conversation may have touched on the security practices of Coinbase and the ethics of disclosure timing. Without the top comments, the exact key points and conclusions are unclear, but the topic appears to be a contentious issue.
Snapshot generated from the HN discussion
Discussion Activity
Active discussionFirst comment
5h
Peak period
12
Day 1
Avg / period
12
Based on 12 loaded comments
Key moments
- 01Story posted
11/16/2025, 8:18:10 PM
2d ago
Step 01 - 02First comment
11/17/2025, 1:19:20 AM
5h after posting
Step 02 - 03Peak activity
12 comments in Day 1
Hottest window of the conversation
Step 03 - 04Latest activity
11/17/2025, 2:57:14 PM
1d ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
Did the support agents have the ability to send arbitrary emails from commerce@coinbase.com? If not, how did the scammers send a properly signed email?
What does this mean?
> While both amazonses.com and coinbase.com DKIM checks passed, this is exactly how phishing works—attackers can configure Amazon SES to send "from" coinbase.com
How does Amazon SES let you sign an email from a domain you don't control? I'm very confused.
- excessive em-dashes - useless words, verbosity
They paid a pittance and permanently buried the report even though its release wouldn't have posed a risk anymore.
The whole industry (except deribit) is a shit show of barely working apis that aren’t reliable or accurate in any way. It’s completely routine to not be able to get an order status for minutes at a time. Or to get fills after an order has been rejected. Or a week after a cancel confirmation message.
Coinbase is actually one of the worst offenders for this. Coinbase Prime, their supposed institutional grade offering especially so.
So it doesn’t surprise me at all that the same issues are happening more widely.
To be clear: deribit have always been efficient, accurate, reliable and generally excellent. If you must trade crypto, do it there so you’re Ops and Support people don’t have to suffer.
Then I reached out to customer service several times - no answer. Then I contacted dedicated channel for privacy related questions with all proofs of mishandling - radio silence.
It’s sad to see these companies mishandle our very personal data and get away with this.
Even if they find the inside individuals, how could anyone ever present a legal case?
36 more comments available on Hacker News
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.