A rising tide of frustration among individuals surrounds a significant security breach linked to Coinbase. An unusual Google account recovery message led to devastating crypto losses, with incidents reported since July 8, 2025. This raises urgent questions about the security of crypto platforms amid escalating phishing schemes.
The breach occurred when a person received a peculiar text message urging them about an account recovery request. Just hours later, they noticed unauthorized crypto transactions from their Coinbase account, even triggering unstaked Ethereum to be sent away. One victim expressed disbelief: _"How did they bypass 2FA?"
The community has voiced critical insights into this incident:
Questionable Recovery Mechanisms: Commenters highlighted how easily attackers can exploit the security mechanisms in place. One highlighted, _"It boggles my mind that the unlock period can be bypassed with the same codes that are the reason for an unlock period."
Whitelisting and Account Security: Several individuals argue for stricter security protocols. Suggestions include mandatory whitelists that cannot be altered within 48 hours and implementing secondary custodial wallet approvals for transactions. Some users pointed out the lack of safeguards for accounts, equating the situation to a