CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Ari Paul Accuses Coinbase of Losing $25M and Hiding $1B in Hacks

CryptaCount Editorial · · 9 min read
ENFORCEMENT Ari Paul Accuses Coinbase of Losing$25M and Hiding $1B in Hacks

BlockTower Capital founder Ari Paul has made a series of serious public allegations against Coinbase, claiming the exchange lost $25 million belonging to his firm and has been concealing more than $1 billion in repeated hacks affecting at least a dozen counterparties. Coinbase has flatly denied the claims. Whatever the eventual outcome, the episode surfaces concrete custodial, accounting, and disclosure risks that every accounting firm, auditor, and CFO with digital asset exposure needs to assess right now.

Ari Paul Accuses Coinbase of Losing $25M and Hiding $1B in Hacks

What Paul Has Alleged

Paul took to social media to state that Coinbase "still wouldn't return our money," characterising the situation as one involving "massive and repeated hacks" that the exchange had actively covered up. He said at least a dozen firms are caught up in the alleged cover-up but added that legal constraints limit what he can disclose publicly at this stage.

The API key custody question

Coinbase's response is worth reading carefully. When contacted for comment, the exchange directed reporters to a support post that denied hiding any hack series and denied losing $1 billion. The exchange also noted that it advises clients on security practices such as maintaining their own API keys, and that, like most platforms offering API-based access, it does not retain the information required to transact on customer accounts directly.

That last point matters enormously for anyone structuring a custodial arrangement through an exchange API. If an exchange does not hold the keys and does not retain transactional authority, the customer bears the residual risk of key compromise. That is a very different risk profile from a qualified custodian holding assets in a segregated account. Accounting teams and auditors need to be clear on which model their clients are actually using.

Context: the broader Coinbase hack narrative

Paul's posts were triggered partly by a thread involving prominent crypto investor Cobie, who was publicly pointing out that an X user had been ignoring Coinbase's outreach. Cobie characterised the situation as potentially involving a fabricated grievance and an "engagement farm," while Paul used the thread as a springboard for his own, more serious claims. The two sets of allegations are distinct, and conflating them would be a mistake. Paul's $25 million claim relates to BlockTower Capital specifically, not to the X user Cobie was addressing.

The allegations also arrive against a backdrop of a separate, earlier incident. Coinbase was sued in May over claims that it withheld a portion of $55 million in crypto stolen in a wallet-draining hack that reportedly occurred in August 2024. In that case, the victim alleges they clicked a malicious link that spoofed a legitimate Ethereum DeFi management interface, unknowingly authorising a smart contract permission that gave attackers control of their wallets. That case is unresolved, but it adds texture to the environment in which Paul's claims are being made.

Custodial Risk: What Firms Must Examine

When a fund or corporate treasury holds digital assets at a centralised exchange, the legal and accounting treatment depends on the precise nature of that arrangement. The two are not interchangeable, and this case puts the distinction in sharp relief.

Segregated custody vs. exchange balances

A qualified custodian holding assets in a segregated account creates a relationship where the firm can argue the assets remain under its beneficial ownership, subject to the custodian's fiduciary duties. An exchange balance, by contrast, is typically an unsecured creditor claim against the exchange. Under US GAAP and FASB ASC 820 fair value measurement, the accounting for an impaired or unrecoverable exchange balance is different from the accounting for a custodial loss. Auditors reviewing 30 September 2026 period-end balances should be asking whether any client exchange balances are subject to active disputes, pending litigation, or claims of unrecoverable funds.

Loss contingency recognition

Under ASC 450 (Contingencies), a loss is recognised when it is probable and can be reasonably estimated. If a firm has a live dispute with an exchange over missing funds, and internal legal counsel considers recovery less than probable, the position should be written down or written off, not left at cost. CFOs and their advisers need to consider whether the $25 million figure Paul cites, if it remains unrecovered at his fund's balance sheet date, has been properly reflected in BlockTower's accounts. More broadly, any firm in a similar position with any exchange should be applying the same test.

API key governance and internal controls

Coinbase's specific defence, that it does not retain the data needed to transact on customer accounts, points to a gap in how many firms govern their API credentials. API keys that grant withdrawal or trading authority to a third-party exchange represent a material internal control risk. If those keys are compromised, the exchange may have no practical ability to reverse the resulting transactions, and the firm bears the loss. Firms relying on exchange APIs for treasury operations or trading should be conducting periodic key rotation, limiting key permissions to the minimum necessary, and logging all API-authenticated activity. This is not optional hygiene; it is the minimum standard for any digital asset accounting environment that aspires to be auditable.

For a deeper look at how AML screening intersects with on-chain transaction integrity, see our piece on AML screening decisions for on-chain infrastructure.

Disclosure Implications for Accounting Firms and Auditors

At this stage, Paul's allegations are unproven. Coinbase denies them. No regulatory body has made a finding. But the allegations themselves, if material to a client's financial position, may require disclosure even before any adjudication.

Going concern and related disclosures

For a fund like BlockTower Capital, $25 million is a material sum. If the amount remains in dispute at a year-end or a reporting period, auditors applying AS 2101 (Audit Planning) and AS 2415 (Going Concern) standards will need to assess whether the dispute affects the entity's ability to meet obligations. This is especially acute for funds that mark assets to market and report net asset values to investors. A missing or disputed balance that is not reflected in NAV calculations could constitute a material misstatement.

Exchange-level disclosures and related parties

Auditors should also revisit whether any client has a related-party relationship with Coinbase, whether through equity stakes, business partnerships, or director overlaps, that might affect the objectivity of management's assessment of the recoverability of disputed funds. Any such relationship would need to be disclosed under ASC 850.

The broader "dozen firms" claim

Paul has stated that at least a dozen other firms are affected by the alleged cover-up. If that claim has substance, it implies a systemic issue rather than a one-off incident. Accounting firms with multiple clients holding exchange balances at Coinbase should consider issuing a standard information request to those clients asking whether any funds are subject to dispute, freeze, or irrecoverability claims. This is standard practice for any auditor managing a portfolio of digital asset clients and is precisely the kind of proactive inquiry that separates a credible digital asset practice from one that is simply processing transactions.

For context on how a separate exchange-level security event triggered similar custodial and accounting questions, see our analysis of how the Bitget hack tested stablecoin freeze mechanisms.

What Coinbase Has Said

Coinbase's denial is direct. Its support post states the exchange "is not hiding a series of hacks" and did not lose $1 billion. The exchange points to its customer security guidance, which covers API key management, as evidence that it takes security seriously. Its position on API keys, that it cannot transact on customer accounts because it does not retain that data, is a structural defence: responsibility for key security sits with the customer, not the exchange.

That framing, if legally accurate, places a large portion of the dispute in the domain of contract interpretation. What did BlockTower Capital's service agreement with Coinbase actually say about custodial responsibility, key management, and liability for losses? That question will likely determine the outcome of any litigation far more than the public back-and-forth.

Practical Steps for Firms Right Now

Whether or not Paul's allegations are ultimately upheld, the episode is a prompt for immediate action across three areas.

Review custodial agreements

Pull every service agreement, custody agreement, and API terms document for each exchange or custodian your clients use. Identify which arrangements involve segregated custody with a regulated custodian and which are simply exchange balances. Flag the latter as higher risk for loss-contingency purposes and for auditor attention.

Audit API access controls

Map all active API keys across client accounts. Identify keys with withdrawal authority. Confirm that key rotation schedules exist and are being followed. Where keys have not been rotated in the past 90 days, escalate. Where keys have broader permissions than necessary, restrict them. This applies whether the exchange is Coinbase or any other platform.

Assess period-end balance disclosures

For any client with material exchange balances, confirm that the balances have been independently verified against exchange statements as of the reporting date. Where a dispute exists, apply ASC 450 and determine whether a loss provision or contingent liability disclosure is required. Do not rely on management representations alone for this assessment. Using robust crypto accounting software or digital asset accounting software to pull independent transaction records directly from the exchange or the blockchain adds an objective layer of verification that manual reconciliation cannot provide.

Ari Paul Accuses Coinbase of Losing $25M and Hiding $1B in Hacks

Frequently Asked Questions

Does Coinbase's denial change the accounting treatment for firms with disputed balances?

No. The accounting treatment under ASC 450 depends on the probability of recovery, not on whether the counterparty has denied wrongdoing. If internal or external legal counsel assesses recovery as less than probable, a provision should be recognised regardless of the exchange's public position.

Are exchange balances protected the same way as balances held with a qualified custodian?

Generally, no. Exchange balances are typically unsecured creditor claims. A qualified custodian holding assets in a segregated account provides stronger legal and accounting protection. Firms should verify the exact nature of each custodial arrangement in their service agreements.

What should an auditor do if a client has funds in dispute with an exchange?

The auditor should obtain written representations from management, assess the probability and estimability of the loss under ASC 450, consider whether the disputed amount is material, and determine whether a provision, contingent liability note, or going-concern disclosure is required.

How does API key compromise typically arise, and who bears the loss?

API key compromise can result from phishing, malware, insider access, or inadequate key rotation. Where an exchange's terms assign responsibility for key security to the customer, and where the exchange has no transactional authority of its own, the customer typically bears the resulting loss. This makes robust key governance a first-line financial control, not just an IT matter.

Should firms pause Coinbase-related operations while this is unresolved?

That depends on the firm's risk appetite, the size of its Coinbase exposure, and the terms of its custodial agreements. A proportionate response is to increase monitoring and verification frequency, ensure independent balance reconciliation is in place, and escalate material exposures to audit committees or boards pending further clarity.

Source: Protos

USGeneralEnforcementEnforcement

Related articles

Enforcement
Kalshi Ends Volume Incentive Program Amid Wash Trading Scrutiny
Enforcement
OFAC Sanctions Tornado Cash Developer Roman Semenov
Enforcement
Hester Peirce Leaves the SEC: What Firms Need to Know
Enforcement
CFTC Sues Cash FX Over $950M Crypto-Linked Forex Scheme