Coinbaseâs recent data breach is prompting renewed calls to remove Know Your Customer (KYC) requirements in licensed cryptocurrency exchanges.
Illicit actors bribed the exchangeâs overseas customer service agents in December 2024 to gain access to the personal information of 70,000 users. In May, Coinbase admitted that hackers had obtained data such as government-issued ID photos and home addresses.
âAll this security theater needs to be abolished asap. Time and again it only benefits hackers and extortionists,â said pseudonymous developer Banteg on X. âKYC actually enables crime.â
However, itâs not feasible for exchanges to simply turn their backs on KYC, as it is a regulatory mandate in several jurisdictions. Meanwhile, privacy-enhancing alternatives like zero-knowledge (ZK) proofs remain limited by cost and technical complexity.
KYC becomes flawed gatekeeper for Coinbase
Coinbaseâs latest data scandal places the Nasdaq-listed company on the spot. But the concern applies to all centralized crypto platforms operating under regulatory licenses worldwide. Centralized exchanges now collect and manage passport scans, government IDs, selfies or even utility bills from users who just want to trade.
KYC was designed to curb fraud, money laundering and terrorism financing. But in practice, itâs everyday users who end up exposed while determined attackers find ways around the system.Â
âAnyone is able to generate a fake US passport or diploma from a leading law school. And 50% of businesses with identity checks are likely bypassable with generative AI,â Ilia Kolochenko, CEO of cybersecurity company ImmuniWeb, told Cointelegraph.
In February 2024, it was reported that people can successfully bypass crypto exchange KYC verification walls by generating passports using AI. Then in October 2024, another AI service popped up to add a video generation tool to bypass crypto KYC checks.
Related: AI agents are poised to be cryptoâs next major vulnerability
In 2023, renowned blockchain detective ZachXBT shared details of a demonstration where he bypassed Gate.ioâs verification system using a fake identity under the name of North Korean leader âKim Jong-Un.â He said it took him just minutes to do so.
Lisa Loud, executive director of Secret Foundation, suspects that her personal data was included in Coinbaseâs breach due to the rising frequency of suspicious spam messages she has received.
âJust yesterday, I got five texts about Coinbase, saying someone was trying to access my 2FA or withdraw funds,â Loud told Cointelegraph. âThe whole point of Web3 is to move beyond the problems of Web2, not to repeat them.â
In a financial sense, she considers herself lucky, as she doesnât hold much on the exchange. Sheâs more concerned about her private information that illicit actors may have access to.
Coinbase highlights how Web2 KYC fails Web3 users
KYC was not designed with crypto in mind, but itâs now a cornerstone of how regulators force the emerging industry to play by traditional rules.
âThe problem is not that weâre KYC-ing people; itâs that weâre doing it the Web2 way and not the new way,â said Loud. âTheir goal is to tighten their risk model. It makes sense from a business perspective â but itâs completely unfair to users.â
Related: Violent crypto robberies on the rise: Six attacks that targeted investors
KYC practices originated in the 1970s under the US Bank Secrecy Act and were significantly strengthened after the 9/11 attacks through the USA PATRIOT Act under the âCustomer Identification Program.â
Crypto emerged much later but increasingly relies on identity verification. Illicit actors can buy stolen identities or KYC-verified accounts on darknet marketplaces, or use advanced tools, like AI, to bypass these verifications with minimal cost.
Some users have called for KYC to be scrapped and replaced with modern innovations, like zero-knowledge (ZK) tech. This would allow a party to prove to another that the information is true without the need to reveal underlying data. In theory, it can let regulators tick their compliance boxes while users keep their privacy.
âThe problem is that exchanges and many Web3 companies are all doing KYC independently, over and over again. But if I could verify my identity once and then use that service to provide a zero-knowledge proof of identity, that would be so much better,â Loud said.
Coinbase scandal wonât push KYC away
Though modern blockchain-based solutions can improve privacy while verifying user identities, Kolochenko said KYC will continue to persist across borders despite its flaws.
âKYC is here to stay, and regulators wonât lower the bar. If anything, theyâll raise it. Without it, crypto risks becoming a tool for every imaginable crime,â he said.
Despite the security incident, Kolochenko declined to classify it as a data breach, noting that customer information was stolen through the bribery of overseas Coinbase staff rather than through infrastructure damage or a technical vulnerability.
Regardless of what itâs called, customersâ data has been compromised. Thereâs little they can do other than follow best practices to maintain a clean digital footprint.
Physical crime against crypto owners is on the rise.
âTurn on paranoid mode â in a good sense. Update everything. Enable 2FA. Never trust an incoming call asking for your seed phrase,â Kolochenko said.
Loud is an advocate of ZK technology, which can enhance privacy while satisfying identity verification requirements. But even she admits that the technology cannot be implemented immediately due to its heavy computational needs and expenses.
While crypto users are left scrambling to reclaim their privacy, regulators and exchanges remain locked in a compliance-first mindset that demands submission of personal data.
Loud has been especially cautious since Coinbaseâs data leak, which she suspects she was also affected by. She is now considering changing the phone number sheâs had for over a decade, as it has suddenly become flooded with Coinbase-related spam messages.
The breach has also set off fears about user safety, as data on home addresses were included in the leak. TechCrunch and Arrington Capital founder Michael Arrington said on X that the leaked information may put users at physical risk.
Magazine: Coinbase hack shows the law probably wonât protect you: Hereâs why