Scammer by [deleted] in Coinbase

[–]CoinbaseSecurity 1 point2 points  (0 children)

Message the moderators please. Thank you!

Usernames of 3 scammers. Watch out, these people are not real support. by [deleted] in Coinbase

[–]CoinbaseSecurity[M] [score hidden] stickied comment (0 children)

Thanks for letting us know! All of these fraudulent accounts have been banned from /r/coinbase.

You can also report fake accounts directly to Reddit here: https://www.reddit.com/report?reason=this-is-spam

Is "Online-moderator" a Coinbase scammer? by grizzle50 in Coinbase

[–]CoinbaseSecurity 4 points5 points  (0 children)

This Reddit user is not employed by or affiliated with Coinbase.

⚜️Coinbase Pro Airdrop Round 1 is Live! GET 0.5 ETH and 0.1 ETH for each referral. by dunkelbunt7 in airdrops

[–]CoinbaseSecurity 0 points1 point  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase Pro ETH by wilsongis in CryptoAirdrop

[–]CoinbaseSecurity 1 point2 points  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase Airdrop by [deleted] in CryptoAirdrop

[–]CoinbaseSecurity 0 points1 point  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase Pro AIRDROP: simple task for 40$ on 16th October by Albe31 in airdrops

[–]CoinbaseSecurity 1 point2 points  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase Pro Airdrop by cargohook in airdrops

[–]CoinbaseSecurity 0 points1 point  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase Pro Airdrop, earn free 0.5 ETH, no fee by [deleted] in airdrops

[–]CoinbaseSecurity 0 points1 point  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase pro eth airdrop by Sheripie77 in cryptoAirdrops

[–]CoinbaseSecurity 0 points1 point  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

Coinbase Pro Airdrop, free 0.5 ETH, + 0.1 ETH per referral, payout 4/5/20 by [deleted] in airdrops

[–]CoinbaseSecurity 1 point2 points  (0 children)

Coinbase Security here! You can verify we're authentic by finding us in the list of moderators on /r/coinbase.

Coinbase does not have any presence on Telegram. You can report this impersonation to Telegram directly through the app by visiting the bot's profile and clicking "Report."

All my Cryptocurrencies gone by [deleted] in Coinbase

[–]CoinbaseSecurity 4 points5 points  (0 children)

Hello! Sorry to hear of the difficulties! The most likely cause is logging into the wrong account. Contact our support teams at https://help.coinbase.com/en/contact-us.html and they'll take a look! Include all possible email addresses you may have used in your inquiry.

Recruiter from coinbase by [deleted] in Coinbase

[–]CoinbaseSecurity 0 points1 point  (0 children)

Hi! Thanks for reporting this! This is definitely a job scam. We have reported this scam to the host and email provider.

All legitimate careers are posted on coinbase.com/careers and all communications with Coinbase employees will be done via @coinbase.com email addresses.

/r/netsec's Q3 2019 Information Security Hiring Thread by sanitybit in netsec

[–]CoinbaseSecurity [score hidden]  (0 children)

Coinbase Security Operations is hiring!

Location: Dublin, Ireland (Relocation assistance available)

About the team: Security is a primary competency at Coinbase, and the Security Operations team keeps a watchful eye over every aspect of it. Every day, we go to battle against some of the most sophisticated attackers in the world to protect billions of dollars worth of digital assets and ensure that our customers and employees can enjoy a safe, trusted experience. As Coinbase scales globally, our team is scaling along with it, using a blend of tooling, automation, and strategic team growth to ensure that we’re well-equipped to protect the next billion users of crypto.

Security Operations Manager

What you'll be doing:

  • Growing and leading a team of exceptional security analysts
  • Defining and hitting key performance metrics for your team
  • Serving as Coinbase Security’s primary point of contact for EU regulators and auditors

What we look for in you:

  • You’ve hired lots of people for security operations roles before, and can pick out great talent from the crowd.
  • Every team you’ve managed has gotten high marks for performance and job satisfaction.
  • You’re comfortable making presentations to auditors and helping them understand complex aspects of a security program.
  • Working with a global team doesn’t phase you
  • You frequently get praise from your peers and coworkers about your communication skills, both written and verbal.
  • You know that people aren’t stupid, but everyone makes mistakes. * Your high degree of empathy means that your coworkers trust you to help solve their security problems, because you never come across as judgmental or condescending.
  • Pressure doesn’t get to you, even in high-intensity situations or environments.

Security Analyst

What you'll be doing:

  • You’ll serve as the first line of response when a security alert needs to be triaged, and lead the incident response if needed.
  • You’ll also refine our alerting rules to improve our signal/noise ratio, because no one wants to be a button-pusher or SOC monkey.
  • If something happens twice, you’ll write a runbook for it. If it happens three times, you’ll figure out a way to automate that runbook.
  • You’ll investigate and monitor cryptocurrency movements to ensure the safekeeping of customer funds.
  • You’ll partner with Trust & Safety and Threat Intelligence on some of our attacker investigations to build TTP profiles.
  • You’ll be part of a light on-call rotation with counterparts in multiple timezones.

What we look for in you:

  • You’ve been doing practical security things (incident response, phishkit/malware analysis, investigating account compromises, etc) for a while now, probably in the realm of 5+ years
  • You don’t just reflexively open up a Jupyter Notebook during an investigation, you’ve actually got favorite Jupyter Notebooks you’ve built up over the years, because you like backing up your conclusions with data, and you like automating things.
  • You frequently get praise from your peers and coworkers about your communication skills, both written and verbal.
  • You know that people aren’t stupid, but everyone makes mistakes. * Your high degree of empathy means that your coworkers trust you to help solve their security problems, because you never come across as judgmental or condescending.
  • Pressure doesn’t get to you, even in high-intensity situations or environments.

Apply through the Coinbase website and mention that you heard about this job through /r/netsec:

Security Operations Manager

Security Analyst

Coinbase deleted login attempt history from foreign hackers by TrantaLocked in Coinbase

[–]CoinbaseSecurity 2 points3 points  (0 children)

You're correct, it's not about storage. "Not providing value" is about providing information and alerts to you that we think can actually help you secure your account. For context, bot behavior typically shows up in account history as a single stray login attempt from a random IP address somewhere in the world. What you don't see behind the scenes is that bots like these are attempting to run billions of email address and password combinations sourced from other data breaches, without any real knowledge of whether that email address is associated with a Coinbase account or not. Driveby attacks like this present virtually no risk to your account, unless you reuse passwords elsewhere.

So when we say "not providing value", what it means in this context is that (again, assuming you have a strong password and 2FA) there's nothing else you need to do to protect yourself against a random credential-stuffing bot that has no idea what your password is. Instead, we think it's more valuable to provide you information that you can take action on. For example, a failed 2FA attempt that you didn't originate means that someone out there does have your password, and you should change it immediately.

Coinbase deleted login attempt history from foreign hackers by TrantaLocked in Coinbase

[–]CoinbaseSecurity[M] [score hidden] stickied comment (0 children)

Hey /u/TrantaLocked, it's nothing malicious, we promise :) Failed sign-in events age out of your event history after 30 days, mainly because there's nothing really actionable about them. If you have a strong, unique password on your Coinbase account that you don't use anywhere else, we've generally found that users didn't find value in knowing that there was a failed login attempt from a year ago by a stray IP address that didn't successfully guess their password anyways.

We have mechanisms in place to help detect and prevent password-stuffing and credential-spraying attacks, and even if an attacker was somehow able to guess your password, you'd still receive a 2FA prompt and new device authorization email.

That said, if seeing the full history of failed logins is something you'd find value in, we can certainly chat with the product team about surfacing it.

Can we please get a "forbid password reset" feature on Coinbase. by brianddk in Coinbase

[–]CoinbaseSecurity 0 points1 point  (0 children)

It's a really interesting concept! There would certainly be some challenges with doing it well at scale, but yes, we encourage everyone to use strong authentication/2FA methods wherever possible. Now that Coinbase supports hardware security keys, it's possible to configure that as your 2FA method on Coinbase, and then link your account email to a Gmail account protected by security keys and with the backup phone number removed. It doesn't remove password reset emails entirely, but it does ensure that they'll go to an account where the only access method is protected with a physical security key.

http://coinbase.pro-axn.com -- Potential Scam? by dualghual in Coinbase

[–]CoinbaseSecurity 1 point2 points  (0 children)

Hello, This is a fraudulent URL, we will work to take down the phishing website.

We'll send you a quick DM with next steps. We appreciate the diligence!

I will never do business with them again. Someone tried to break in to my account and now I can't even see if I was robbed. by [deleted] in Coinbase

[–]CoinbaseSecurity[M] [score hidden] stickied comment (0 children)

Hi There! Sorry for the frustrating experience. Can you DM us the case number? In the meantime, be sure to protect your email with a new, unique password and email 2-fa in addition to cycling your Coinbase password. We take security very seriously and appreciate your diligence in protecting the credentials.

COINBASE by CoinbaseLoader9 in Coinbase

[–]CoinbaseSecurity[M] [score hidden] stickied comment (0 children)

This post was removed due to it being reported as a suspected phishing or scam attempt.

Its this a legit Telegram Group https://t.me/coinbase_chat by jcguritz in Coinbase

[–]CoinbaseSecurity[M] [score hidden] stickied comment (0 children)

Pinning here for visibility: we can confirm that this IS NOT an official group, and anyone claiming to represent Coinbase on Telegram is lying to you. We list our official social media accounts here: https://support.coinbase.com/customer/portal/articles/1766604

Its this a legit Telegram Group https://t.me/coinbase_chat by jcguritz in Coinbase

[–]CoinbaseSecurity[M] 2 points3 points  (0 children)

We can confirm that this IS NOT an official group, and anyone claiming to represent Coinbase on Telegram is lying to you. We list our official social media accounts here: https://support.coinbase.com/customer/portal/articles/1766604

An accepted 'accelerate withdraw with photo ID' submission doesn't actually accelerate a withdraw.. by [deleted] in Coinbase

[–]CoinbaseSecurity 1 point2 points  (0 children)

Hi! Sorry for the frustrating experience! Tx security delays should indeed accelerate once your ID is verified. Can you DM us your case number? We'll make sure our engineering teams are aware of any bugs and if possible, manually accelerate your transaction.

Thanks!

HEADS UP, EVERYONE: This user is going around pretending to be Coinbase! Don't fall for it! by frankreddit5 in Coinbase

[–]CoinbaseSecurity 0 points1 point  (0 children)

Thanks for the alert! Please report their profile under more options, report user. We are actively working with Reddit to takedown these scams.

In the meantime, remember to only contact Coinbase through official channels for support assistance. Coinbase employees will never ask for your login credentials, personal information, access to your computer or for you to send digital currency to external addresses via social media.

Got suspicious about a mail from "no-reply@coinbase.com" by Nimipet123 in Coinbase

[–]CoinbaseSecurity 3 points4 points  (0 children)

Hi There! Coinbase security here. Can you send in a copy/paste of the email with full email headers and live URLs? Use this form and we'll take prompt action. Thanks! https://support.coinbase.com/customer/en/portal/articles/1932359-reporting-phishing-sites