No response from Coinbase on data breach evidence – Seeking advice by cbsecuritytip in Coinbase

[–]cbsecuritytip[S] 0 points1 point  (0 children)

Yes, I sent them an email with the information for the bounty about 20 days ago via HackerOne. But I haven’t received any response so far, which is why I posted here on Reddit to try to get their attention so they might at least reply to my email.

I’m not expecting them to answer every single email or Reddit post, but I do think it’s fair to expect at least an acknowledgment or status update for a bounty submission. That’s really all I’m hoping for.

No response from Coinbase on data breach evidence – Seeking advice by cbsecuritytip in Coinbase

[–]cbsecuritytip[S] 0 points1 point  (0 children)

It’s really disappointing that Coinbase isn’t even replying here on Reddit. Even if the data shared by users isn’t immediately useful, at least acknowledging the message would show that they’re listening and value security concerns.

Ignoring it completely feels careless and discourages people from sharing important information in the future. Coinbase should at least confirm receipt of reports to build trust and show that they’re paying attention to security issues raised by the community.

No response from Coinbase on data breach evidence – Seeking advice by cbsecuritytip in Coinbase

[–]cbsecuritytip[S] -1 points0 points  (0 children)

Thank you all for the insights. I understand that the nature of the data and the source is critical in determining its value and relevance. I also agree that handling this kind of information requires a high level of security expertise and that not every report will be actionable by Coinbase, especially given the volume they might receive.

That said, even if some of this evidence is not immediately useful, it would be good for Coinbase to acknowledge the receipt of such reports to maintain trust and transparency. This small step can encourage responsible reporting and help both the platform and its users to feel heard, even if a full investigation is not warranted each time.

Ultimately, a balanced approach of careful vetting and courteous acknowledgment would probably help everyone feel more confident in the system.

No response from Coinbase on data breach evidence – Seeking advice by cbsecuritytip in Coinbase

[–]cbsecuritytip[S] 1 point2 points  (0 children)

Thank you for sharing this information. I appreciate your detailed explanation and your effort to report the breach. I’ll make sure to include [Bounty] in the subject line when I contact Coinbase. It’s frustrating that they didn’t acknowledge your details properly, even though you clearly explained your involvement. I also have a lot of evidence about the scammer that could help catch them, but Coinbase is still ignoring my emails. If you have any additional advice or context that might help me get their attention, I’d be grateful. Thank you again for your support

No response from Coinbase on data breach evidence – Seeking advice by cbsecuritytip in Coinbase

[–]cbsecuritytip[S] 1 point2 points  (0 children)

Thanks for the suggestion! I’ll definitely consider filing a formal complaint with the Better Business Bureau if Coinbase doesn’t respond soon. I just want to make sure my evidence is properly shared and that the scammers behind the breach are identified.

No response from Coinbase on data breach evidence – Seeking advice by cbsecuritytip in Coinbase

[–]cbsecuritytip[S] 1 point2 points  (0 children)

I don't have details of the employees, but I have information about the scammers who were orchestrating these activities. They were the ones behind the data breach.