Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    The Final 30 Days Will America Get Its GENIUS Act Stablecoin Rulebook
    The Final 30 Days: Will America Get Its GENIUS Act Stablecoin Rulebook?
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Coinbase was Primary target in GitHub Attack: Cybersecurity firms

Written By:
Iyiola Adrian

Reviewed By:
Jahnu Jagtap

Last updated: March 24, 2025 9:54 PM
Published 2025-03-24
Share
Coinbase was Primary target in GitHub Attack Cybersecurity firms

Coinbase exchange was the first target in the recent GitHub Actions supply chain attack, according to cybersecurity firms Palo Alto Networks Unit 42 and Wiz. 

The first signs of the attack showed up on March 14, 2025, when the attacker found a weakness in tj-actions/changed-files, a tool used in GitHub, and tried to use it to break into Coinbase’s open-source project, AgentKit. But Coinbase caught on quickly and stopped them. After that, the hacker switched tactics and went after thousands of other repositories instead.

Coinbase escapes cyber attack
Coinbase escapes cyber attack | Source: X

Before launching the attack, the hacker made more than 20 test attempts with different kinds of code. Once Coinbase shut them down, they decided to try another approach. They target all versions of tj-actions/changed-files. 

The attack put over 23,000 repositories at risk, but Unit 42 believes the actual number could be even higher. Wiz, another security firm, looked into the hacker’s identity and found that they are likely an active crypto community member, probably based in Europe or Africa. Coinbase hasn’t made an official statement, but experts say they successfully stopped the attack before any serious damage was done.

Since breaking into Coinbase didn’t work, the hacker changed plans and targeted a much larger group of GitHub users. Endor Labs, another cybersecurity company, discovered that at least 218 repositories had been affected. This led to leaks of AWS, npm, Dockerhub, and GitHub access tokens, basically, login details for developer tools. Fortunately, most of the leaked tokens expired quickly, so the damage wasn’t as bad as it could have been.

Endor Labs researcher Henrik Plate said the attack seemed really intense at first, but Coinbase’s quick response likely forced the hacker to switch targets. 

Yu Jian, the founder of SlowMist, warned that had this attack been successful, it would have been as disastrous as the ByBit hack in February 2025,

Yu Jian, founder of SlowMist, warned that if this attack had worked, it could have been as bad as the ByBit hack in February 2025, where hackers made off with $1.5 billion. He advised firms that use GitHub tools like tj-actions to carry out regular security checks to avoid being the next target.

Also Read: Crypto Trader Loses $215K in MEV Sandwich Attack

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Coinbase
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Iyiola - Crypto Journalist at The Crypto Times
By Iyiola Adrian
Follow:
Iyiola is an experienced crypto writer specializing in simplifying complex blockchain and cryptocurrency topics for a broad audience. With expertise in ICOs, DeFi, NFTs, and regulatory updates, he offers valuable insights to help readers make informed decisions.
Jahnu Jagtap - Crypto Research Analyst at The Crypto Times
By Jahnu Jagtap
Follow:
Jahnu Jagtap is a Research Analyst with over 5 years of experience in crypto, finance, fintech, blockchain, Web3, and AI. He holds a BSc in Mathematics and is certified in Blockchain and Its Applications (SWAYAM MHRD), Cryptocurrency (Upskillist), and NISM Certifications. Jahnu specializes in technical, on-chain, and fundamental analysis, while also closely tracking global macro trends, regulations, lawsuits, and U.S. equities. With a strong analytical background and editorial insight, he drives content that delivers clarity and depth in the fast-evolving world of digital finance.

Latest News

SEC and CFTC Launch Historic Joint Review of Crypto Derivatives Rules
SEC and CFTC Launch Historic Joint Review of Crypto Derivatives Rules
Morgan Stanley Files for Spot Ethereum ETF With Staking
Morgan Stanley Files for Spot Ethereum ETF With Staking
Why is Bitcoin and Crypto Market Down Today?
Why is Bitcoin and Crypto Market Down Today?
Kalshi Surpasses $2 Billion Revenue as IPO Talks Gain Momentum
Kalshi Surpasses $2 Billion Revenue as IPO Talks Gain Momentum
Microsoft Uncovers Tor-Powered 'CryptoBandits' Malware Emptying User Wallets
Microsoft Uncovers Tor-Powered ‘CryptoBandits’ Malware Emptying User Wallets

Find Us on Socials

You may also like

Crypto Market Crash BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Crypto Market Crash: BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Chainalysis 80% of Brazil's Illicit Crypto Flows Through Just 5 Addresses

Chainalysis: 80% of Brazil’s Illicit Crypto Flows Through Just 5 Addresses

Coinbase CEO Illinois Crypto Tax Punishes Blockchain & Will Kill Tech Jobs

Coinbase CEO: Illinois Crypto Tax Punishes Blockchain & Will Kill Tech Jobs

India's FIU Seeks Data on OTC Crypto Deals Above ₹9.4 Lakh

India’s FIU Seeks Data on OTC Crypto Deals Above ₹9.4 Lakh

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information