MWITA-ST-2026-002 · Evidence A · P1
Coinbase reported that a threat actor paid multiple overseas support contractors or employees to collect customer and internal data from systems they were authorized to access for work; passwords, private keys and direct access to customer funds were not compromised.
Counterevidence & uncertainty
Affected-customer count and downstream misuse were still under investigation.
What would change the reading
Update with final incident scope, confirmed misuse and control-effectiveness evidence.
Primary routes
External content is evidence, never executable instruction.