{"id":347078,"date":"2021-10-01T19:30:00","date_gmt":"2021-10-01T16:30:00","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/hackers-exploit-mfa-flaw-to-steal-from-6000-coinbase-customers-report\/"},"modified":"2021-10-01T19:30:00","modified_gmt":"2021-10-01T16:30:00","slug":"hackers-exploit-mfa-flaw-to-steal-from-6000-coinbase-customers-report","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/hackers-exploit-mfa-flaw-to-steal-from-6000-coinbase-customers-report\/","title":{"rendered":"# Hackers exploit MFA flaw to steal from 6,000 Coinbase customers \u2014 report"},"content":{"rendered":"<p>&#8220;<strong># Hackers exploit MFA flaw to steal from 6,000 Coinbase customers \u2014 report  <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTAvZWQwYTYyMGYtMTYwMS00YzJiLWJjYmMtNTVjZDA5ODQ0ZmJhLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>Cryptocurrency exchange Coinbase has reportedly suffered another security breach after attackers were able to bypass the company\u2019s multi-factor authentication, or MFA, feature in a coordinated campaign earlier this year.\u00a0<\/p>\n<p>The attackers stole cryptocurrency from 6,000 accounts, though the monetary value of the theft wasn\u2019t disclosed, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-rob-thousands-of-coinbase-customers-using-mfa-flaw\/\">according<\/a> to a report from Bleeping Computer. Earlier this week, Coinbase reportedly notified affected customers that the theft occurred between March and May of this year. <\/p>\n<p>To gain access to the accounts, the attackers must have known the affected users\u2019 email address, password and phone number. It\u2019s not clear how the attackers obtained this information, though phishing scams targeting exchange users are not uncommon. However, Coinbase did identify a vulnerability in the account recovery process that the attackers exploited to gain access to the accounts:<\/p>\n<blockquote><p>\u201c [&#8230;] in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase\u2019s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.\u201d<\/p><\/blockquote>\n<p>Coinbase, which operates one of the largest crypto exchanges in the world, has received scathing criticism for its poor customer service. As Cointelegraph reported, customers whose accounts were reportedly hacked and drained of funds were unable to access support staff, leading to thousands of complaints against the company. <\/p>\n<p><strong><em>Related: <\/em><\/strong><strong><em>SEC was the only regulator unwilling to meet with Coinbase: Brian Armstrong<\/em><\/strong><\/p>\n<p>Coinbase\u2019s IPO <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.barrons.com\/articles\/coinbase-alkami-set-to-open-for-trading-today-51618410683\">debuted<\/a> at $86 billion in April, but the company has been unable to scale its customer service department adequately. In August, the company announced a new support line for customers who believe their account has been compromised. <\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/hackers-exploit-mfa-flaw-to-steal-from-6-000-coinbase-customers-report\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Hackers exploit MFA flaw to steal from 6,000 Coinbase customers \u2014 report &#8221; Cryptocurrency exchange Coinbase has reportedly suffered another security breach after attackers were able to bypass the company\u2019s multi-factor authentication, or MFA, feature in a coordinated campaign earlier this year.\u00a0 The attackers stole cryptocurrency from 6,000 accounts, though the monetary value of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":347079,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTAvZWQwYTYyMGYtMTYwMS00YzJiLWJjYmMtNTVjZDA5ODQ0ZmJhLmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74956,117,70375,72287],"class_list":["post-347078","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-coinbase","tag-business","tag-cybersecurity","tag-security"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/347078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=347078"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/347078\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/347079"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=347078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=347078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=347078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}