Customer Gives Coinbase 14 Days Before Threatened Dutch Lawsuit
Coinbase is facing the prospect of civil proceedings in the Netherlands after a customer issued a formal notice of default demanding €170,874.18 over an alleged 2024 account takeover and unauthorized removal of funds.
The notice, made public on September 12, gives Coinbase 14 calendar days to pay the claimed amount or provide an unconditional commitment to do so before the customer says Dutch litigation counsel will be instructed to serve a writ of summons, or dagvaarding.
No lawsuit has yet been shown as filed. The document therefore represents a pre-litigation escalation rather than an existing Dutch court proceeding.
According to the claimant, the dispute stems from a January 27, 2024 cyberattack on a Coinbase consumer account. The customer alleges that an attacker gained access through session-cookie hijacking and ultimately caused €53,674.95 in fiat funds to leave Coinbase in four transactions executed within less than two minutes.
The claimant says Coinbase rejected liability in a final response dated July 4, 2024, attributing the incident to compromised customer credentials. Coinbase’s response itself has not been independently reviewed for this article.
The new demand challenges that position primarily under Dutch payment-services law.
Article 7:522 of the Dutch Civil Code provides that a payment transaction requires the payer’s consent and is considered unauthorized in the absence of that consent. More importantly for disputes involving stolen credentials, Article 7:527 states that the mere fact that use of a payment instrument was recorded is not necessarily sufficient evidence that the customer authorized the transaction or acted fraudulently or with gross negligence. The payment service provider must provide supporting evidence where it alleges fraud or gross negligence.
Article 7:528 generally requires a payer’s payment service provider to refund an unauthorized transaction immediately and, at the latest, by the end of the following business day after becoming aware of it, subject to specified exceptions, including reasonable grounds for suspecting fraud that are reported to the Dutch Authority for the Financial Markets.
The rules are also substantially mandatory for consumers. Article 7:550 says the payment-services provisions generally cannot be varied to the detriment of a payment-service user unless the law expressly provides otherwise.
That does not automatically establish Coinbase’s liability. Article 7:529 provides that a payer can bear losses from unauthorized transactions when they result from fraud or an intentional or grossly negligent failure to comply with security obligations. The factual dispute over how the account was compromised would therefore remain central.
The customer is also attacking Coinbase’s transaction controls, alleging the platform failed to react to a sudden geographical change and four rapid high-value transactions and did not require transaction-linked Strong Customer Authentication.
PSD2 generally requires SCA when a payer initiates an electronic payment, and for remote electronic payments the authentication must dynamically link the authorization to the amount and payee. However, European rules provide exemptions, including some transactions identified as low risk through transaction-risk analysis. That means whether SCA legally had to be repeated for each disputed transfer would depend on the payment flow and any exemption Coinbase relied on.
Beyond recovering the original money, the claimant is seeking €106,397.02 in alleged missed portfolio profits.
The customer says 1.40402148 BTC and 12,031.26215895 DOGE were forcibly liquidated during the incident and calculates the consequential loss using the portfolio’s claimed peak value on October 6, 2025.
Dutch law does recognize lost profit as a form of financial damage. Article 6:96 states that property damage includes both losses suffered and profit forgone, while Article 6:98 limits compensation to damage sufficiently connected to the event giving rise to liability.
The notice also claims €9,990.91 of statutory interest, producing the total demand of €170,874.18.
That portion of the calculation may require revision. The letter applies a flat 7% annual rate from January 27, 2024 through September 9, 2026. Dutch consumer statutory interest was 7% in 2024, but dropped to 6% on January 1, 2025 and then to 4% on January 1, 2026. Article 6:119 also provides for the interest base to increase after each full year by the interest already accrued.
The exact interest amount would additionally depend on when Coinbase legally entered default.
The notice itself seeks to put Coinbase into default under Article 6:82, which provides for default after a written demand gives the debtor a reasonable period to perform and that period expires without performance. It also invokes Article 3:317 to interrupt the limitation period by expressly reserving the claimant’s right to performance.
A Dutch forum is legally plausible for a qualifying consumer claim. Under the EU’s Brussels I Recast Regulation, a consumer can generally sue the other party to a consumer contract in the courts of the member state where the consumer is domiciled, provided the consumer-jurisdiction requirements are met.
A Court Case Would Turn a Support Dispute Into an Evidence Dispute
The strongest aspect of this case is not the size of the €170,874 demand. It is the possibility that a long-running customer-support dispute could move into a process where both sides may have to produce technical evidence.
Coinbase’s apparent position, according to the claimant, is that customer credentials were compromised. But under the Dutch payment rules cited in the demand, proving that Coinbase’s systems authenticated a transaction is not necessarily the end of the matter.
That is exactly what Article 7:527 is designed to address.
If proceedings are filed, the important evidence could include login records, session-token history, device fingerprints, IP data, SCA events, withdrawal authorization logs, destination bank information and whatever risk signals Coinbase’s systems generated during the two-minute transaction sequence.
The claimant’s assertion that Coinbase itself identified session-cookie hijacking would be particularly significant if supported by Coinbase records. But at present that remains an allegation from the customer rather than independently verified evidence.
There are also weaknesses Coinbase could challenge.
The €106,397 missed-profit claim is likely to be substantially harder to establish than the original cash loss. Dutch law permits recovery of lost profits, but selecting the highest subsequent portfolio valuation does not by itself prove that the customer would have held every asset until that exact date and sold at the peak. The claimant’s historical buy-and-hold behavior could be relevant evidence, but causation and valuation would remain questions for the court.
There is also an entity problem that deserves attention.
Coinbase’s own description of its 2025 European restructuring says crypto services for Dutch customers moved from Coinbase Europe Limited to Coinbase Luxembourg S.A., while e-money services continued to be provided by Coinbase Ireland Limited. Coinbase also said Dutch customers’ governing law for e-money services subsequently changed from Dutch to Irish law.
Because the incident occurred in January 2024, the contracts and entity structure in force at that date—not Coinbase’s current structure—will matter. If the central claim concerns unauthorized euro e-money payments, identifying the precise Coinbase entity responsible for those services could become important before proceedings are served.
The SCA allegation is similarly less automatic than the notice suggests. PSD2 establishes SCA as the rule for payer-initiated electronic transactions, but regulated exemptions exist. The real issue would therefore be whether an exemption applied and, if so, whether Coinbase’s risk analysis reasonably treated transactions following the alleged account anomaly as sufficiently low risk.
None of those issues makes litigation inevitable.
Coinbase could respond during the 14-day period, contest the calculation, challenge the responsible entities or maintain its original rejection entirely.
But if a summons is actually served, the dispute changes character. Instead of a customer arguing through Coinbase’s support system about who was responsible for an account takeover, a Dutch court could be asked to decide authorization, gross negligence, authentication, payment-security controls and causation under European payment law.
That would be the point at which Coinbase is genuinely “in open court” in the Netherlands. The September 12 notice brings the dispute closer to that stage, but it has not reached it yet.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

