Listen to this episode

Is Coinbase as Much of a Hot Mess as it Seems?

0:0027:27

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella of Petronella Technology Group hosts Erin and BJ for a discussion of the security problems surrounding Coinbase at the time of recording. The team reviews large thefts tied to the platform, including a reported 11.6 million dollars lost in under ten minutes after a fake notification claiming to be from Coinbase, and the case of a retired attorney whose two factor authentication was changed while he watched his funds withdrawn.

Craig argues it is alarming that Coinbase Custody holds a SOC 2 Type 2 report while the main exchange appears to lack comparable public documentation. BJ describes a trade off between convenience and security, noting Coinbase draws many entry level crypto enthusiasts. The group dissects a phishing email Craig received, urging listeners never to log in through email links or call numbers included in messages. Craig explains cold wallets and the 24 word passphrase, BJ cautions that everything connected to a blockchain remains vulnerable, and both argue that public ledgers make stolen funds traceable over time. Craig notes that crypto regulation was still being hashed out at the time of recording.

Worth remembering

Key takeaways

  1. Never log in through links in emails and never call phone numbers in them; go directly to the official website instead.
    “And never called the phone number in the email. Always go direct to the manufacturer, the website, and call on the contact page.”
  2. Craig urges anyone holding crypto to protect the 24 word passphrase, which he says is where the money actually lives, and never digitize it.
    “You have to protect that like a golden bar. You can't share it with anybody. Don't type it on anything on your computer.”
  3. Craig warns listeners to buy hardware wallets only direct from the manufacturer, never from a reseller or eBay.
    “don't ever buy one of these, unless you buy it direct from the manufacturer, never buy from a reseller, never ever buy it from eBay.”
  4. BJ argues training is essential so employees know what to look for, and says many organizations do not train their staff.
    “As Craig always mentioned training is so important and we see a lot of organizations that don't do trainings with their employees. And so they don't know what to look for”
  5. BJ notes Coinbase attracts many entry level crypto enthusiasts because it is convenient, but that convenience comes with fewer security measures.
    “because you have a lot of entry-level crypto enthusiasts on Coinbase. And I use it too, because it's very convenient, right?”
  6. BJ cautions that even if the blockchain chain itself is considered secure, everything connected to it remains a vulnerability.
    “But nothing else other than the chain is considered secure, everything connected to the chain is still a vulnerability.”
  7. Craig points out that crypto transactions leave a permanent public record, which is why he believes stolen funds may eventually be traced.
    “if funds are moved without your authorization, even if you made a mistake, all of that's on a public blockchain.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

If you are a massive crypto exchange and tens of thousands of accounts are hacked, is it the tens of thousands of users' fault, or is it possible that maybe the company's cyber hygiene isn't passing the "sniff" test?

Join the Petronella Technology Group team as they discuss the hacks and explore what exactly is going on.

Host : Craig Cohosts : BJ & Erin

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.