This week news broke that up to 6,000 Coinbase customers were hacked between March and May 2021. Here are the basics of the situation via Coindesk:
- Between March and May 20, the hacker or hackers used a flaw in Coinbase’s account recovery process to get the SMS two-factor authentication token to break into customers’ accounts and transfer funds out of them.
- The bad actor or actors also had access to the email address, password and phone number associated with each Coinbase account. Coinbase believes that the hacker stole those credentials through a phishing scheme.
Coinbase will be reimbursing all funds lost.
It sounds like both Coinbase and the users were at fault here. Coinbase’s two-factor authentication (2FA) via SMS (text message) was compromised. And the users fell prey to a phishing attack. They likely received a fake email that looked like it was from Coinbase and logged in to a fake version of the site.
Using SMS as 2FA is notoriously risky. Hackers can “sim swap” your phone and intercept your texts. And now we know of at least one other vulnerability. I strongly recommend using Google Authenticator for 2FA. It’s far more secure.
This attack’s phishing aspects are a reminder that we all need to be VERY careful about the links we click, the emails we open and especially the programs and browser extensions we install.
If you get a message from an exchange or other crypto company, don’t click on the links in an email or text. Go directly to the site. And don’t search for the company’s name on Google, because sometimes hackers place ads that send people to fake versions of the site in order to steal their credentials.
One of the simplest ways to avoid getting hacked is to have a dedicated new laptop that you use ONLY for crypto. Don’t do anything else on it. That way you’re highly unlikely to become infected with malicious software that could end up stealing your private info, including logins and passwords.