Wed. Sep 30th, 2026

BlockTower Founder Ari Paul Alleges Coinbase Security Failures Caused More Than $1B in Losses

ByShane Neagle

September 29, 2026 #Coinbase
CoinbaseCoinbase Coinbase

BlockTower Capital founder and chief investment officer Ari Paul has accused Coinbase of security failures that he claims cost his firm roughly $25 million and affected more than a dozen other companies, pushing alleged combined losses above $1 billion.

The allegations, published by Paul on September 29, are potentially serious but remain unverified. Paul has not released supporting documents, named the other institutions he says were affected, explained the precise attack mechanism or provided evidence substantiating the $1 billion figure.

Paul said Coinbase lost approximately $25 million belonging to BlockTower several years ago. He claimed that an investigation conducted afterward identified at least 12 other companies that had experienced similar incidents and alleged that Coinbase had failed to publicly disclose repeated security breaches.

He also said multiple legal proceedings are underway and that those cases currently prevent him from providing further details.

Dave Finances could not locate a public Coinbase response addressing Paul’s September 29 claims as of publication. The allegations should therefore not be treated as an established account of what happened.

The central unanswered questions are substantial: when BlockTower’s alleged loss occurred, whether Coinbase custody or customer-support infrastructure was involved, whether the assets were removed directly from Coinbase-controlled systems or transferred after third parties obtained account information, and how Paul calculated losses exceeding $1 billion across the other institutions.

BlockTower Was Previously Hacked, but the Coinbase Connection Is Unproven

BlockTower has previously suffered publicly reported security incidents, although the available record does not establish that they are the events Paul referenced.

In May 2024, Bloomberg reported that BlockTower’s main hedge fund had been compromised and partially drained. The amount lost was not disclosed publicly at the time, and the incident was not publicly attributed to Coinbase.

BlockTower also appeared to lose approximately $1.5 million in the 2023 Dexible exploit, an unrelated smart-contract attack.

That history makes it particularly important not to merge separate events into one narrative. Crypto firms can lose money through compromised account credentials, exchange infrastructure failures, smart-contract exploits, exposed private keys or social engineering, and those mechanisms assign responsibility very differently.

Recent incidents illustrate the distinction. A D’CENT-linked XRP drain involved thousands of wallets from which valid credentials continued authorizing transactions, while Bitget recently said a $387.5 million security incident compromised backend wallet infrastructure without exposing its private keys.

Until Paul identifies the attack path, it is impossible to determine which model, if any, resembles the alleged BlockTower incident.

Coinbase Has Disclosed Major Security Incidents Before

Paul’s allegation arrives against a documented history of security problems at Coinbase, although those incidents do not independently substantiate his claim.

In May 2025, Coinbase disclosed to the U.S. Securities and Exchange Commission that attackers had paid multiple overseas contractors or support employees to obtain customer information from internal systems.

The stolen data included names, addresses, phone numbers, email addresses, government identification images, partial financial information, account balance snapshots and transaction histories.

Coinbase said passwords and private keys were not compromised and that the employees involved could not directly access customer funds. Instead, stolen information was used in social-engineering attacks designed to convince customers to transfer crypto themselves.

The company estimated remediation expenses and voluntary customer reimbursements at between $180 million and $400 million at the time of disclosure. Coinbase rejected a $20 million ransom demand and said affected eligible retail customers would be reimbursed after their cases were reviewed.

That incident subsequently generated extensive litigation. Multiple customer lawsuits were consolidated into federal multidistrict proceedings in the Southern District of New York.

Those cases, however, concern the disclosed 2025 customer-data breach. Their existence does not demonstrate that the legal proceedings Paul referenced involve BlockTower or the other unnamed institutions in his September 29 post.

Coinbase also disclosed that at least 6,000 customers were affected in 2021 after attackers who had separately obtained customer credentials exploited a vulnerability in the exchange’s account-recovery process. Coinbase said it fixed the vulnerability and reimbursed affected customers.

The $1 Billion Figure Is the Claim That Needs the Most Evidence

Paul’s most consequential assertion is not BlockTower’s alleged $25 million loss. It is the claim that at least 12 other companies suffered related incidents totaling more than $1 billion.

Nothing publicly available so far identifies those companies or breaks down those losses.

That matters because aggregating crypto losses is surprisingly difficult. Researchers can often observe stolen assets moving on-chain, but assigning those addresses to individual victims and proving how an attacker obtained access requires evidence outside the blockchain.

Even apparently strong loss totals can evolve as investigators identify additional wallets. Recent research into alleged COLDCARD-related thefts, for example, produced an aggregated loss tally based on hundreds of victim reports, while other investigations rely on identifiable attacker addresses or transaction clusters.

In Paul’s case, no comparable dataset has yet been made public.

To substantiate the $1 billion allegation, evidence could include court complaints, institutional account records, forensic reports, correspondence with Coinbase, identifiable blockchain transactions or independent statements from the other affected companies.

Why This Matters More Than Another Exchange Hack Claim

If Paul’s allegations were eventually substantiated, the issue would extend well beyond one hacked account.

Coinbase is one of the largest institutional crypto infrastructure providers in the United States. Asset managers, corporations, funds and other professional investors use its custody, Prime and trading infrastructure precisely because outsourcing custody is supposed to reduce operational risk.

A series of undisclosed institutional losses would therefore raise a different question from a typical exploit: whether clients could accurately assess the security risk of using the platform.

That distinction matters for investors in Coinbase as well.

Security incidents create direct financial costs through reimbursements, investigations and legal expenses. But repeated incidents can also increase insurance costs, compliance spending and institutional customer-acquisition friction.

The 2025 breach showed how quickly those costs can become material. Coinbase’s initial $180 million to $400 million estimate was not the amount directly stolen from its own wallets; much of it related to remediation and customer reimbursement.

That means a security failure does not need to drain an exchange hot wallet to become financially significant.

The wider crypto market has seen the same dynamic. The Payy bridge exploit forced operational shutdowns after a comparatively smaller loss, while phishing operations such as the fake GIWA mainnet campaign demonstrated how attackers can extract substantial sums without compromising the underlying blockchain itself.

The Next Evidence Could Change the Story Quickly

Right now, Paul has created a high-value reporting lead rather than established a $1 billion Coinbase security scandal.

That distinction could change quickly if even one of the unnamed institutional victims comes forward.

A court filing tying BlockTower’s alleged $25 million loss to Coinbase would also materially strengthen the story, particularly if it describes an attack method similar to those Paul says affected other firms.

Conversely, a detailed Coinbase response could substantially narrow the allegation. The company may be able to show that the assets were lost through compromised customer credentials, external infrastructure or another mechanism that differs from Paul’s characterization.

That is why attribution matters so much in crypto security reporting. The fact that assets disappear from an account does not automatically establish that the exchange holding the account was breached.

Investors have seen similar uncertainty when user assets become inaccessible for reasons that are operational rather than criminal. A recent Coinbase customer, for example, said more than $900,000 remained locked during a source-of-wealth review. The money was visible, but access depended on an internal compliance process.

Security disputes require the same discipline: determine who controlled the assets, which credentials or systems failed and whether the loss resulted from a platform breach, compromised customer access or a third-party attack.

For now, Paul has supplied a number large enough to command attention but not enough evidence to validate it.

The story becomes substantially more important if documents begin to connect the pieces: BlockTower’s alleged $25 million loss, the unnamed institutional victims, a common Coinbase-linked attack mechanism and the legal proceedings Paul says are already underway.

Until then, the $1 billion figure remains Ari Paul’s allegation — not a verified measure of Coinbase-related losses.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *