Coinbase estimated the combined cost of customer reimbursement and remediation arising from the May 2025 insider incident at between $180 million and $400 million, for a breach affecting approximately 69,500 people.
Between $2,600 And $5,700 Per Affected Person
Set that against the standard remediation offer recorded throughout this corpus: twelve or twenty-four months of credit monitoring, worth perhaps twenty dollars wholesale, provided by a company frequently in the credit-data business itself.
The difference is not generosity. It is that Coinbase committed to making customers whole for funds lost to the fraud the breach enabled — an actual loss, in a specific amount, traceable to the incident.
The Loss Was Legible, Which Is The Whole Story
Almost every other file in this database involves harm that cannot be quantified per person. What is the loss to someone whose date of birth and national identifier are circulating? It is real, it is permanent, and there is no method that converts it into a number a company could write a cheque against.
Here the harm was a transfer of a known amount on a known date. That legibility, not any difference in corporate character, is why reimbursement was possible — and it explains why the biometric file at 26-0324, the children’s file at 26-0113 and the declined-applicant file at 25-1105 all end with no compensation.
A Precedent, But A Narrow One
It is worth resisting the conclusion that this establishes a standard other organisations could adopt. A retailer that lost six million records cannot reimburse a loss nobody can compute, and demanding that it try would produce arbitrary numbers rather than justice.
What the file does establish is that the near-universal absence of compensation elsewhere is not principled. It follows from the measurement problem, and it means the cost of a breach is systematically understated by exactly the amount that could not be quantified — the accountability gap filed at 26-0403 and 26-0511.
Graded medium: the estimate is the company’s own, is a range, and combines reimbursement with remediation without separating them.
Compiled from public reporting of company estimates, listed below. The per-person figures are our arithmetic on the reported range and combine reimbursement and remediation. Corrections: corrections@forensicpost.com.
- Top 10 cyber-attacks of 2025Infosecurity Magazine
- From Bybit to Coinbase: 2025’s biggest crypto hacks and breachesYahoo Finance