
An anonymous crypto investor identified as 'D.B.' filed a lawsuit against Coinbase on Monday, claiming the exchange froze DAI tokens linked to a 2024 phishing theft but refused to return traceable funds. According to the complaint filed in U.S. court, the plaintiff lost approximately $55 million in DAI after clicking on a malicious link that spoofed Ethereum DeFi management tool 'DefiSaver'. The lawsuit names both Coinbase and an unknown alleged thief as defendants, with the suit describing the hack as 'sophisticated' and seeking restitution for any profits the exchange may have accrued from holding the funds.
The attack occurred on August 20, 2024, when the alleged thief used Inferno Drainer, a phishing tool linked to wallet-draining attacks, to move DAI from the plaintiff's wallet. As reported in the filing, the victim apparently lost his crypto after unknowingly authorizing a smart contract permission that gave the thieves control of his crypto wallets. From there, they allegedly stole the DAI funds and used crypto mixing services like Tornado Cash to launder the funds before eventually depositing them on Coinbase. The complaint details how the victim failed to notice that the fraudulent site ended in '.app' instead of the correct domain, allowing the attacker to move funds through other wallets and laundering tools.
According to the lawsuit, Coinbase froze the assets after receiving notice of the theft but allegedly declined to release them without a court order. The plaintiff's lawyers acknowledged that Coinbase acted reasonably when it first froze the funds, but claimed the exchange's position became 'unreasonable' after the plaintiff provided sworn proof of ownership. The lawsuit seeks a court order for Coinbase to return the traceable stolen assets, along with 'imposition of a constructive trust' and a declaration that the plaintiff is the rightful owner. The suit also names John Doe as a defendant, highlighting the currently unknown hacker or hackers who stole the crypto, and alleges they face seven counts including fraud, theft, and racketeering.
The Coinbase legal challenges extend far beyond the current $55 million DAI case, with the company facing more than a dozen separate legal actions simultaneously as of 2026. A December 2025 arbitration loss set a precedent where Coinbase was ordered to pay $618,000 in damages and costs to a client who lost funds in a separate 2024 cyber-attack. The arbitrator found Coinbase had 'utterly failed in its duty to protect customer data' and 'utterly failed in its duty to investigate'. The company's policy of withholding stolen funds without court orders creates a recurring operational cost that turns security functions into persistent liabilities. As reported by AI Agent Adrian Hoffner, each similar case represents a potential new liability and drain on capital, with courts already denying Coinbase's motions to dismiss, signaling that settlement talks are gaining traction.
The company faces two primary liability sources: a May 2025 data breach involving nearly 70,000 customers has led to a class-action lawsuit with estimated losses between $180 million and $400 million. Additionally, New York filed a lawsuit in April 2026 targeting prediction-market trading products, creating uncertainty over regulatory restrictions. The 'on-ramp' effect represents another structural risk, where Coinbase is used to purchase crypto for scams, exposing it to potential liability for facilitating initial purchases. The company's staking program has also been a source of litigation, with class-action cases targeting misleading staking programs. These cases form a multi-billion dollar liability pool that must be managed, with settlement discussions already gaining traction as courts deny motions to dismiss. The primary near-term catalyst for liability realization is the resolution of active lawsuits, with courts denying Coinbase's motions to dismiss indicating that settlement talks are gaining traction.