Coinbase SIM-swap Lawsuit
SAMPLE COMPLAINT AGAINST COINBASE
COMPLAINT JURY TRIAL DEMANDED
Plaintiff is a resident of the State of New York, by his attorneys, Dilendorf Law Firm PLLC, as for the Complaint against Defendant COINBASE, INC. (“Coinbase” or “Defendant”) for gross negligence, violating requirements as imposed by the New York State Department of Financial Services (“DFS”) and the United States Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”), and failure to put proper measures to protect its customers from security breaches, which caused Plaintiff to sustain a loss of his life savings. Plaintiff now seeks to recover damages and equitable relief for harm sustained as the result of Defendant’s grossly negligent misconduct. Moreover, Defendant’s grossly negligent conduct in failing to protect users’ funds on its cryptocurrency exchange result in the facilitation of money laundering activities through offshore criminal syndicates. This willful misconduct in flagrant disregard of DFS’ and FinCen’s regulations raises a serious question as to whether Defendant should be permitted to continue operating its cryptocurrency exchange in the State of New York.
NATURE AND SUMMARY OF THE ACTION
- Defendant operates an online exchange for general consumers and the public to exchange, invest, and trade in digital cryptocurrencies. Defendant deceptively and intentionally promoted itself as “the most trusted cryptocurrency platform,” all the while failing to take reasonable and state-mandated steps to prevent cyberattacks.
- Defendant’s negligence, deceptive business practices, and ongoing violations of DFS and FinCEN regulations have caused extreme hardship to Plaintiff due to a preventable cyberattack that has resulted in tremendous and irrevocable financial damage.
- Defendant obtained a license from DFS to provide cryptocurrency services in the State of New York (“BitLicense”).
- Defendant, as a regulated cryptocurrency exchange and licensed money services business in the State of New York, is bound to (i) maintain stringent anti-hacking programs that monitor and filter transactions for potential violations of the Bank Secrecy Act (“BSA”) and anti-money laundering (“AML”) statutes; and (ii) implement measures designed to effectively detect, prevent and respond to fraud.
- This action arises out of Defendant’s negligence and grossly deceptive business practices, committed in its capacity as a public financial institution licensed in the State of New York, which resulted in a catastrophic financial loss to the Plaintiff. Due to Defendant’s gross negligence and the practically nonexistent cybersecurity measures on the Coinbase platform, Plaintiff lost his life savings.
- Because none of the customary cybersecurity systems were in place to prevent such a crime, Plaintiff’s assets were stolen from his account by a hacker who used a foreign device and a foreign IP address, from a location never before used by Plaintiff. Defendant thereby authorized an unknown party to access Plaintiff’s Coinbase account and immediately transfer funds into foreign wallets that have never been associated with Plaintiff, in violation of federal and state anti-money laundering regulations.
- Defendant failed to perform adequate anti-money laundering and “know your client” (combined as “AML/KYC”) procedures, as those procedures are commonly known under FinCen and DFS guidelines and enforcement rules. As such, Defendant failed to properly monitor Plaintiff’s account and ignored its duty to investigate suspicious activities under US and New York State anti-money laundering rules.
- Defendant failed to use its own promoted security measures “in the interest of keeping customer’s account(’s) secure,” such as increasing the processing time of transfers to 24 hours after a password reset is completed from a foreign device.
- Defendant also failed to remedy or restore Plaintiff’s losses, despite claiming that customers’ assets will be safeguarded with the same security, vigilance and diligence commonly afforded to members of the virtual currency industry.
- Upon information and belief, the earliest sim card phishing attacks against Coinbase go back to 2013 and have occurred countless times since then, as the result of which, Defendant’s users lost tens of millions of dollars in lifesavings.
- As of this date, Defendant is considered the largest cryptocurrency exchange in the world, yet Defendant lacks proper anti-fraud mechanisms to safeguard its users, including users that are residents of the State of New York.
- At all times, judging upon the history of cyber-security attacks on Defendant’s cryptocurrency exchange that resulted in the loss of users’ funds, Defendant’s actions were knowing, willful, and grossly negligent.
- Until Defendant can demonstrate that its cryptocurrency exchange cybersecurity measures meet the standards set forth by DFS regulations relating to the conduct of businesses involving cryptocurrencies in the State of New York, Defendant’s BitLicense should be suspended, and Defendant should be precluded from operating the platform in New York.
- Moreover, upon information and belief, Defendant failed to report to DFS and FinCEn information about Plaintiff’s theft of funds and to provide a statement of any actions taken or proposed to be taken with respect to Plaintiff’s loss of life savings, in violation of FinCen’s and DFS’s regulations and issued guidance to all virtual currency business entities.
PARTIES
- Plaintiff at all times hereinafter mentioned was and still remains a resident of State of New York.
- Defendant Coinbase is a Delaware corporation with its principal place of business in San Francisco, California. Coinbase holds itself out as a digital currency wallet and secure online platform where merchants and consumers can transact with new digital currencies like Bitcoin and Ethereum and where users can buy, sell, transfer and store their digital currency.
- Defendant operates a cryptocurrency exchange in the state of New York and licensed under 23 NYCRR Part 200. Defendant maintains offices within the State of New York, at 28 Liberty Street, New York 10005.
JURISDICTION AND VENUE
- The Court has jurisdiction over Defendant pursuant to CPLR § 301 because Defendant regularly transacts business in the State of New York, has a principal place of business in New York and is licensed in the state of New York under 23 NYCRR § 200.
- Venue is proper in this Court under CPLR § 503 because, upon information and belief, in September 2018 Coinbase opened a primary place of business in New York and because New York County is the venue chosen by Plaintiff.
FACTUAL BACKGROUND RELEVANT TO ALL CAUSES OF ACTION
- Defendant holds itself out as a regulated and fully compliant entity, registered with the FinCEN as a Money Services Business, and calling itself “the most trusted cryptocurrency platform.”
- Defendant is also bound by the regulations set forth by DFS, in order to maintain their BitLicense, which includes reporting on any suspicious transactions and taking immediate steps to prevent them in the future.
- Pursuant to Section 200.7 of the NYSDFS regulation, Coinbase is a licensee of the BitLicense issued to it by DFS and was thus obligated to comply with all applicable federal and state laws, rules and regulations.
- Section 200.16(a) “Cyber security program” of DFS states in pertinent part:
“Each Licensee shall establish effective cyber security program to ensure the availability and functionality of the Licensee’s electronic systems and to protect those systems and any sensitive data stored on those systems from unauthorized…tampering. The cyber security program shall be designed to perform the following five core cyber security functions: (1) identify…cyber risks by, at a minimum, identifying the information stored on the Licensee’s systems, the sensitivity of such information, and how and by whom such information may be accessed; (2) protect the Licensee’s electronic systems…from unauthorized access…or other malicious acts through the use of defensive infrastructure and the implementation of policies and procedures; (3) detect systems intrusions, data breaches, unauthorized access to systems or ….other Cyber Security Events; (4) respond to detected Cyber Security Events to mitigate any negative effects; and (5) recover from Cyber Security Events and restore normal operations and services.”
- Coinbase received a BitLicense from DFS to operate as an exchange of Cryptocurrencies within the State of New York, and thus, is a Licensee pursuant to Title 23, Chapter 1, Part 200 of the NYSDFS Regulations. Section 200.19(g) of DFS regulation mandates that:
“Licensees are prohibited from engaging in fraudulent activity. Additionally, each Licensee shall take reasonable steps to detect and prevent fraud, including by establishing and maintaining a written anti-fraud policy. The anti-fraud policy shall, at a minimum, include: (1) the identification and assessment of fraud-related risk areas; (2) procedures and controls to protect against identified risks; (3) allocation of responsibility for monitoring risks; and (4) procedures for the periodic evaluation and revision of the anti-fraud procedures, controls, and monitoring mechanisms.”
- Section 200.20(a) of DFS regulation further mandates that each Licensee shall establish and maintain written policies and procedures to fairly and timely resolve complaints.
- Coinbase’s negligence, carelessness, and recklessness arose from, but is not limited to the following:
-
- failing to provide adequate cyber security measures as mentioned above which constitutes non-compliance with industry standards, governmental regulations and its own policies;
- failure to implement adequate security protocols – including that which is required by industry standards, governmental regulations, and its own internal policies;
- failing to properly implement and/or consistently failing to follow security protocols such as requiring the input of a 2FA code as a condition to execute a transfer of cryptocurrency funds out of one account to another account or cryptocurrency wallet;
- failing to properly advise, patrol, respond, address, and monitor customer and industry wide complaints of hackers and scammers that were targeting Coinbase users for their personal and sensitive information in order to illegally obtain access to their accounts; such complaints of hackers and scammers were prevalent and known to Coinbase;
- failing to abide by its own internal security policies of requiring the input of a 2FA code in order to execute the transfer of funds out of Plaintiff’s account, as well as failing to provide the required security protection to do so;
- failing to abide by regulations mandated by Section 200.7 of NYSDFS Regulation and Coinbase’s own internal security policies, and thus, allowing hackers and scammers to illegally obtain access to Plaintiff’s Coinbase account and causing the transfer of Plaintiff’s digital assets into an unauthorized cryptocurrency wallet;
- neglecting to abide by Section 200.19(g) of the DFS regulations by failing to mitigate security risks created by hackers and scammers and failing to monitor the fraudulent conduct of hackers and scammers; Coinbase failed to act in good faith and to the detriment of Plaintiff by failing to fairly and timely resolve Plaintiff’s complaint as required by Section 200.20(a) of the NYSDFS Regulations.
- On February 7, 2018, DFS issued guidance to all virtual currency business entities licensed under 23 NYCRR Part 200 of NY Banking Law. Under this Guidance, virtual currency operators, such as Coinbase, are required to implement measures designed to effectively detect, prevent, and respond to fraud, attempted fraud, and similar wrongdoing.
- Furthermore, immediately upon the discovery of any wrongdoing, a virtual currency business operator must submit to DFS a report stating all pertinent details known at the time of the report. The operator must also submit to DFS, as soon as practicable, a further report or reports of any material developments relating to the originally reported events, along with i) a statement of the actions taken or proposed to be taken with respect to such developments, and ii) a statement of changes, if any, in the operator’s operations that have been put in place or are planned in order to avoid repetition of similar events.
- Defendant failed to take these actions, as presented in detail in the foregoing sections. Upon information and belief, Defendant failed to submit to the DFS the information relating to the theft of Plaintiff’s assets, arising out of Defendant’s grossly negligent misconduct.
- Similarly, upon information and belief, Defendant ignored said guidance by failing to report a countless number of similar security breaches, resulting in a total loss of funds deposited by New York residents onto the Coinbase platform.
- Furthermore, as a money services business, Defendant has strict obligations under the Currency and Foreign Transactions Reporting Act of 1970, a.k.a. the Bank Secrecy Act, to monitor customer transactions and report any suspicious activities to law enforcement authorities. See 31 U.S.C. § 5311; 12 C.F.R. § 208.63.
- The USA Patriot Act of 2001 (the “Patriot Act”) reinforced this obligation and underscored the importance of implementing robust internal systems to detect and report money laundering and other suspicious activities. Defendants failed to follow the regulations promulgated pursuant to the Patriot Act requiring financial institutions to institute an anti-money laundering (“AML”) program and allowed Plaintiff’s funds to be transferred to unknown wallets. Such actions are implicated in money laundering activities.
- Upon information and belief, Defendant failed to report to FinCen, per Patriot Act and BSA obligations, Plaintiff’s theft of funds incident and transfer of such funds to the unidentified wallet
Defendant describes themselves as the preeminent cryptocurrency exchange
- Defendant Coinbase released a Public Statement, pledging to “lead the way” in developing robust cyber security program. According to the Coinbase statement:
- Responsible Bitcoin exchanges are working together and are committed to the future of Bitcoin and the security of all customer funds.
- Bitcoin operators play a critical role over the Bitcoin they hold as assets for their customers.
- Acting as a custodian should require a high bar, including appropriate security safeguards that are independently audited and tested on a regular basis. Coinbase touted and positioned itself to be one of those “responsible Bitcoin exchanges.”
- As set forth herein, by such statements and its conduct in general, Coinbase assumed a duty to protect and safeguard the assets of its exchange customers.
Plaintiff Sets Up a Coinbase Account
- In or about 2017, Plaintiff created an account with Coinbase.
- The procedure for establishing a Coinbase account was and remains merely providing a name, email address, password, and Plaintiff’s state of residence, followed by verification.
- Coinbase does not use distinct usernames; a customer’s email address is their username. Plaintiff enabled Duo Two-Factor Authentication (Duo 2FA) as an added layer of security for Coinbase transactions. Upon information and belief, and according to the Coinbase website, Duo 2FA is endorsed by Coinbase, and it clearly states: “Authenticators like Duo … provide an extra layer of protection in addition to your password. When using an authenticator for your two-step verification codes, you’ll be protected even if your password is stolen or your phone number is ported since these apps are tied to your mobile device and not your phone number.”
- At all times, Defendant assured Plaintiff and continues to assure customers that it “collects and verifies” customer information “in order to (a) protect Coinbase and the community from fraudulent users and (b) keep appropriate records of Coinbase’s customers.” Coinbase states these efforts are made due to its status as “a regulated financial service company operating in the US,” and “ensures we remain in compliance with KYC/AML laws in the jurisdictions in which we operate….”
- At all times, Defendant assured Plaintiff and continues to assure its customers that their “withdrawal and trading limits … (and) USD Wallet transfer limits … are based on the identifying information and/or proof of identity (customers) provide to Coinbase.”
Plaintiff Loses Cellular Service and is Unable to Access Coinbase Account
- On August 26, 2020 at or around 10:00 pm EST, Plaintiff lost cellular service on his phone.
- Simultaneous to Plaintiff’s lost cellular service on August 26, 2020, Plaintiff was unable to access his Coinbase account through the Coinbase App or through his computer.
- At or around 10:00 pm EST on August 26, 2020, Plaintiff attempted to call Coinbase Customer Service at 1(888)908-7930, but due to lack of cellular service, was unable to place this call.
- At or around 10:15 pm EST on August 26, 2020, Plaintiff emailed Coinbase Customer Service and notified them of his loss of cellular service.
- At or around 10:15 pm EST on August 26, 2020, Plaintiff directed Coinbase to lock his account. This direction was given via email to Coinbase Customer Service.
- At all relevant times herein, Coinbase failed to adequately keep Plaintiff informed regarding the status of Plaintiff’s funds deposited with Coinbase.
Plaintiff Attempts for Five Days to Reach Coinbase
- For five days, between August 26, 2020 and August 31, 2020, Plaintiff was unable to access his Coinbase account and was unaware of the status of the account.
- During the five days between August 26, 2020 and August 31, 2020, Plaintiff sent several emails to Coinbase Customer Service, requesting that Coinbase clarify the status of his account.
- On or before August 27, 2020, Plaintiff was told by his mobile carrier, Sprint, that his mobile number was ported to an unknown third-party carrier.
Coinbase Fails to Protect Plaintiff’s Account
- At all times, Coinbase stated and continues to state: “Coinbase takes a number of steps to ensure the security of our customers’ accounts.” At all times, Coinbase stated and continues to state: “When a Coinbase customer attempts to reset their password, we take precautions to ensure that it is a legitimate request. This means that our customers may only reset their passwords from devices they have previously verified, or from locations they have previously logged in from.” At all times, Coinbase stated and continues to state: “If you are having trouble resetting your password, you will need to: 1. Reset it from a device you have previously used to access Coinbase. 2. Reset it from a location (IP address) you’ve previously used to access Coinbase.”
- On August 26, 2020, Coinbase received three sequential requests for a password reset for Plaintiff’s account. Each of the above-mentioned password reset requests were made from a foreign, web-enabled device never before used by Plaintiff. These communications were received from a device containing information not stored by Coinbase to identify Plaintiff.
- Each of the above-mentioned password reset requests were made from a device with an IP address never before used by Plaintiff. The IP address from which these requests were made was geographically located in Denver, Colorado; Plaintiff resides in New York. Per the Coinbase website, the Plaintiff’s state of residence is one of only four identification markers used by Coinbase.
- As such, a password reset request from a Colorado-based IP address was a clear marker of suspicious activity.
- After the third password reset request, 19 Sign-out Sessions were recorded from the same, foreign IP address and foreign device.
Coinbase Authenticates a Foreign Device for Access to Plaintiff’s Account, then Authorizes a Password Reset
- Coinbase authenticated a foreign device after this suspicious activity, first by a Verified Second Factor and then by a Device Confirmation.
- Coinbase violated its own policy and procedure in authenticating this foreign device without Plaintiff’s authorization. Coinbase’s own policy states: “Coinbase uses Device Verification, a security feature that requires all devices (mobile and computer) and IP addresses to be authorized before accessing your account.”
- Coinbase then authorized a password reset for Plaintiff’s account from a foreign device, to an unknown party.
- This password reset was in violation of Coinbase’s own policy, which states, “Coinbase only processes password reset requests from devices that have been previously authorized to access your account.”)
- Coinbase also contradicts itself and states: “If you are resetting your password from a new device, our system may delay the processing time for 24 hours in the interest of keeping your account secure.”
- Coinbase authorized an unknown party with a foreign device and foreign IP address to access Plaintiff’s Coinbase account.
Coinbase Allows Immediate Transfer of All Funds from Plaintiff’s Account
- Coinbase allowed this Coinbase-authorized but unknown party, using a foreign device and foreign IP address, to immediately transfer Plaintiff’s funds, which is inconsistent with its own policy and with industry standards. These standards call for a 24-hour security period before transfer of funds following suspicious activity. See 23 NYCRR § 200.16 Cybersecurity; licensees must establish and maintain an effective cybersecurity program.
- After granting the password reset, Coinbase immediately allowed funds to be transferred to unknown wallets, which is inconsistent with industry-standard of other crypto firms, and which would have immediately frozen transfers for at least 24 hours to minimize risks of theft.
- Coinbase allowed this authorized but unknown party, using a foreign device with a foreign IP address, to immediately transfer funds into wallets never before used by Plaintiff. See 23 NYCRR § 200.16.
- Coinbase authorized all of Plaintiff’s funds to immediately be depleted, an action unlike previous activity of Plaintiff and inconsistent with industry standards and safety protocol.
- Coinbase authorized the entirety of Plaintiff’s funds to be transferred in violation of its own Transaction Limits.
Coinbase Refuses to Remedy Plaintiff’s Losses
- The transactions in question were authorized by Coinbase.
- The transactions in question were NOT authorized by Plaintiff.
- The transactions in question, authorized by Coinbase but not by Plaintiff, were known to Coinbase and Coinbase thus had notice, per Coinbase policy.
- Coinbase refuses to return or restore Plaintiff’s losses, despite assuring Plaintiff and all Coinbase customers that (i) cryptocurrency stored on Coinbase’s servers is covered by their insurance policy and (ii) customers will be protected even if customer’s password is stolen or phone number is ported.
- Upon information and belief, Coinbase has not reported the above-referenced cyberattack to proper regulatory authorities.
- Upon information and belief, Coinbase failed to notify its customers of numerous cyberattacks on its site, resulting in multi-million dollar thefts from Coinbase users.
FIRST CAUSE OF ACTION
NEGLIGENCE
- Plaintiff repeats, realleges, and incorporates by reference all preceding and succeeding paragraphs as if set forth in their entirety herein.
Duty to protect Plaintiff’s funds
- Defendant assumed responsibility for providing Plaintiff with the highest standards of cryptocurrency custody, including safeguarding Plaintiff’s cryptocurrency from cyberattacks.
- At all relevant times, Defendant held itself out to be a financial institution in compliance with 23 NYCRR § 200.
- At all relevant times, Defendant held itself out to be a financial institution in compliance with KYC/AML monitoring and reporting, including to the industry standards and stringent requirements of FinCEN, DFS and BitLicense.
- As detailed above, Defendant’s negligent actions include, but are not limited to:
-
- Authenticating a foreign device after numerous failed password reset requests and 20 log-ins from a foreign IP address never before used by Plaintiff.
- Authenticating a foreign device through an erroneous Device Confirmation.
- Authenticating a foreign device through an erroneous Verified Second Factor.
- Allowing a password reset from a foreign device.
- Failing to delay, “in the interest of keeping customer’s account(’s) secure,” the processing time of transfers for 24 hours after a password reset from a foreign device.
- Authorizing an unknown party with a foreign device and foreign IP address to access Plaintiff’s Coinbase account.
- Authorizing an unknown party with a foreign device and foreign IP address to immediately transfer funds from Plaintiff’s account into foreign wallets never before used by Plaintiff.
- Failing to ensure Plaintiff’s funds despite claiming Coinbase is responsible for all authorized transactions.
- Failing to remedy Plaintiff’s losses despite assuring Plaintiff and other Coinbase customers they will be protected even if customer’s password is stolen or phone number is ported.
- Defendant owed Plaintiff a duty of care to provide cryptocurrency custody, safeguarding and keeping services with the security, and vigilance and diligence
- Defendants breached this duty by providing cryptocurrency custody services that did not meet this standard, as demonstrated above.
- Plaintiff has incurred substantial financial damages as a direct result of Defendant’s breach of duty of reasonable care, as alleged herein.
- As a consequence of Defendant’s breach of duty of reasonable care, Plaintiff has been damaged in the sum to be determined by this Court. Today, the Plaintiff’s portfolio would be worth more than $400,000
- Defendant had a duty to protect all funds in Plaintiff’s account and failed in this duty by not locking the account or having proper mechanisms in place to stop a cyberattack and fraudulent transfer of assets.
- Under DFS regulations, it was the duty of the Defendant to take the proper precautions to ensure that security breaches could not occur.
- Twenty (20) consecutive failed attempts to log in from unknown IP address should have raised red flags for Coinbase.
- Defendant has previously been accused of similar breaches in customer accounts due to a lack of appropriate cybersecurity and has clearly been “on notice” for an ongoing problem over the past two to three years.
- Defendant failed to address this issue, resulting in Plaintiff suffering undue financial damages.
- As a licensed Money Services Business in the State of New York, Defendant is the holder of customer funds, and therefore the responsible party for protecting customer assets. Rather than protecting these assets in accordance with DFS, BSA, FinCEN, and BitLicense regulations, Defendant allowed an unknown party to transfer a basket of crypto held by the client from Plaintiff’s account to unknown wallets held by foreign IP addresses.
- Defendant failed to perform adequate “anti-money laundering” and “combined KYC/AML procedures, as those procedures are commonly known under FinCen guidelines and enforcement rules.
- Defendant was also negligent in allowing a foreign IP address to access funds owned by the Plaintiff when so many red flags were present.
Duty to Report Suspicious Activity
- Defendant was negligent in its failure to abide by DFS regulations and take such precautions, failure to file a report with DFS, and failure to freeze Plaintiff’s account for a period of at least 24 hours following suspicious activity.
- Defendant’s compliance department should have reached out to the Plaintiff to make him aware of the situation before the Plaintiff reached out to them.
Duty of Care
- As detailed above, beginning in 2017 when Plaintiff opened a Coinbase account, and continuing through the present, Coinbase made false and misleading representations to Plaintiff.
- Coinbase’s false and misleading representations include, but are not limited to the following statements:
-
- Coinbase is the most trusted cryptocurrency platform.
- You will be protected even if your password is stolen or your phone number is ported.
- Coinbase takes a number of steps to ensure the security of our customers’ accounts.
- When a customer attempts to reset their password, we take precautions to ensure that it is a legitimate request.
- Our customers may only reset their passwords from devices they have previously verified, or from locations they have previously logged in from.
- If you are having trouble resetting your password, you will need to: 1. Reset it from a device you have previously used to access Coinbase (or) 2. Reset it from a location (IP address) you’ve previously used to access Coinbase.
- Coinbase uses Device Verification, a security feature that requires all devices (mobile and computer) and IP addresses to be authorized before accessing your account.
- Coinbase only processes password reset requests from devices that have been previously authorized to access your account.
- If you are resetting your password from a new device, our system may delay the processing time for 24 hours in the interest of keeping your account secure.
- The use of all Coinbase Services is subject to a limit on the amount of volume, stated in U.S. dollar terms, you may transact or transfer in a given period (e.g. daily).
- Customers will be protected even if customer’s password is stolen or phone number is ported.
- We are not responsible for any claim for unauthorized or incorrect transactions unless you have notified us in accordance with this section.
- These misleading representations resulted from Coinbase’s negligence and/or lack of due diligence and/or lack of adherence to virtual currency industry standards.
- Plaintiff, at the time these representations were made and at the time Plaintiff engaged the services of Coinbase, was ignorant of the falsity of Coinbase’s representations and believed them to be true.
- Coinbase was fully aware that its representations were and continue to be essential to the safekeeping and security of Plaintiff’s and all customers’ virtual currency.
- Coinbase owed a duty to Plaintiff to use reasonable care to impart correct and accurate information to Plaintiff because of the nature of the relationship that existed between them.
- Coinbase is entrusted to possess unique and specialized expertise as a cryptocurrency custodian that is licensed by the State of New York and adheres to the highest of cryptocurrency standards and requirements including KYC/AML compliance and reporting, and those required by FinCEN, DFS and BitLicense.
- Defendant knew that Plaintiff intended to rely and in fact relied on such expertise and representations.
- In justifiable reliance on Coinbase’s representations, Plaintiff entrusted Coinbase with the security and safekeeping of his assets.
- As a direct and proximate result of the negligent misrepresentations made by Defendant alleged herein, and Plaintiff’s reliance on such, Plaintiff suffered monetary damages.
- Plaintiff seek damages based upon the unlawful conduct of Coinbase in failing to properly monitor customer accounts that held Plaintiff’s money and ignoring its duty to investigate suspicious activities under the US and New York State anti-money laundering rules.
SECOND CAUSE OF ACTION
GROSS NEGLIGENCE
- Plaintiff repeats, realleges, and incorporates by reference all preceding and succeeding paragraphs as if set forth in their entirety herein.
- Defendant owed the duty to the Plaintiff and its users to provide security, consistent with industry standards and requirements, governmental regulations, and its own internal policies, to ensure that its computer systems, networks, and personnel adequately protect the financial information of users who utilized the Coinbase, as well as ensuring that the user’s account information would not be attacked by hackers.
- Plaintiff was aware and under the assumption and belief, and relied upon Defendant’s misleading misrepresentations that they are the most trusted and safest cryptocurrency platform in the world.
- Upon information and belief, between 2013 and to this date, Coinbase’s users’ accounts were subject to countless sim card phishing attacks, which Defendant failed to prevent, resulting in tens of millions of dollars in life saving losses by the residents of New York State.
- Defendant owed a duty of care to Plaintiff and its users because Plaintiff and other Coinbase users were foreseeable and probable victims of hackers.
- DFS imposes a duty upon Defendants to implement cyber security measures to protect the exchange, and its users’ accounts, sensitive information, and funds, from unauthorized access, use or tampering.
- Given the history of countless sim card phishing attacks on Defendant’s users’ accounts, Defendant was aware and could reasonably foresee that the inadequate security would cause Plaintiff and other such users to sustain substantial financial harm and was therefore charged with a duty to adequately prevent users’ accounts from hacker attacks.
- As a direct and proximate result of Defendant’s grossly negligent conduct, Plaintiff has suffered injury and is entitled to punitive damages in an amount to be proved at trial.
THIRD CAUSE OF ACTION
DECEPTIVE BUSINESS PRACTICES IN VIOLATION OF GENERAL
BUSINESS LAW § 349
- Plaintiff repeats, realleges and incorporates by reference all preceding and succeeding paragraphs as if set forth in their entirety herein.
- New York’s General Business Law (“GBL”) § 349 prohibits deceptive and misleading business practices. Specifically, under the plain language of GBL § 349(a), “deceptive acts and practices” in the conduct of any business, trade, or commerce “are hereby declared unlawful.”
- GBL § 349(h) grants a “right of action” to “any person who has been injured by reason of any violation of this section.”
- Coinbase’s practice of claiming to adhere to the highest standards of cryptocurrency custody is deceptive and misleading and led to material damages for the Plaintiff.
- Coinbase’s practice of negligence, detailed herein, is deceptive, misleading and resulted in material damages for Plaintiff.
- Coinbase’s practice of significant, continuous, negligent misrepresentations about services and safeguards, detailed herein, is deceptive, misleading and lead to material damages for Plaintiff. Coinbase’s practice of falsely advertising to the public that it insures its client’s funds is deceptive and misleading under GBL § 349.
- Coinbase’s practice of falsely advertising to the public that customers will be protected even if customer’s password is stolen or phone number is ported is deceptive and misleading under GBL § 349.
- Coinbase’s practice of falsely advertising to the public that it adheres to the highest standards of cryptocurrency standards and requirements including KYC/AML compliance and reporting, and those required by FinCEN, DFS and BitLicense are deceptive and misleading under GBL § 349.
- Plaintiff relied upon Coinbase’s advertised and represented capabilities and assurances when Plaintiff entrusted Coinbase with his assets.
- Pursuant to GBL § 349, Plaintiff is entitled to a right of action against Coinbase, to be heard in this Court.
- Pursuant to GBL § 349, this Court is granted authority to award to Plaintiff reasonable attorneys’ fees expended in prosecuting this action.
- Pursuant to GBL § 349, Plaintiff is entitled to a judgment for deceptive business practices, awarding damages against Coinbase in an amount to be determined by this Court.
WHEREFORE, Plaintiff demands a judgment as follows:
(a) A judgment awarding Plaintiff actual compensatory damages;
(b) A judgment awarding Plaintiff exemplary and punitive damages for Defendant’s knowing, willful and intentional misconduct;
(c) Pre-judgment and post-judgment interest;
(d) Attorney’s fees, expenses, and the costs of this action; and
(e) All other and further relief as this Court deems necessary, just and proper.
JURY TRIAL DEMANDED
Plaintiff demands a trial by jury on all issues so triable.
Resources:
- MSB Registrant Search | FinCen.gov
- House.Gov Report | Here’s How Hackers Can Hijack Your Online Bitcoin Wallet
- TechCrunch: Coinbase vulnerability is a good reminder that SMS-based 2FA can wreak havoc
- Forbes: All That’s Needed To Hack Gmail And Rob Bitcoin: A Name And A Phone Number
- Report on Investigation of Twitter’s July 15, 2020 Cybersecurity Incident and the Implications for Election Security
- Three Individuals Charged for Alleged Roles in Twitter Hack
- Report of the Joint economic committee | Congress of The United States – Chapter 9: Building a secure future, one blockchain at a time
- VIRTUAL CURRENCIES. Additional Information Reporting and Clarified Guidance Could Improve Tax Compliance | GAO
- Virtual Currency Businesses: The Market and Regulatory Issues – Joint Informational Hearing Assembly Banking and Finance Committee Assembly Select Committee on Technological Advances
- The Future of Cryptocurrency: Countering Fraud and Regulating Digital Assets
- Virtual Currency: Financial Innovation and National Security Implications
- Risks and Vulnerabilities of Virtual Currency. Cryptocurrency as a Payment Method
- DFS Authorizes Coinbase To Form Coinbase Custody Trust Company LLC
- Treasury Sanctions Individuals Laundering Cryptocurrency
- Bitcoin Dealer Indicted on Money Laundering Charges