Coinbase, the leading cryptocurrency exchange, is facing a lawsuit from investor Brady Nessler. He alleges that the company’s failure to promptly disclose details of its recent data breach and other business dealings caused shareholders to suffer “significant losses and damages.” The legal complaint, filed on May 22 in the U.S. District Court for the Eastern District of Pennsylvania, accuses Coinbase of violating securities laws and issuing “misleading” statements to its investors.
Adding to the mounting pressure, Coinbase is also facing at least six other similar lawsuits following its confirmation of the data breach. These lawsuits accuse the exchange of failing to implement necessary security measures to protect user information. They also cite lacking transparency and mishandling the breach response.
Allegations of Misleading Statements and Omissions
The lawsuit centers around Coinbase’s delayed disclosure of a data breach that began in December 2024 but was only revealed to the public on May 15. According to the complaint, this revelation caused Coinbase’s stock to plummet 7%, closing at $244 on the day of the announcement.
Nessler claims that Coinbase’s failure to inform shareholders about the breach constituted a “wrongful act and omission.” This led to financial harm for investors. The complaint also highlights alleged omissions related to Coinbase’s dealings with U.K. regulators in 2020. This occurred roughly a year before the company went public in the U.S.
“As a result of Defendants’ wrongful acts and omissions, and the precipitous decline in the market value of the Company’s common shares, Plaintiff and other Class members have suffered significant losses and damages,” Nessler’s lawyers stated in the filing.
While Coinbase has not yet responded to requests for comment, the allegations underscore growing concerns about transparency and accountability among publicly traded crypto companies.
The Rising Tide of Legal Challenges

In addition to Nessler’s lawsuit, three lawsuits filed in New York federal court on May 16 further accuse Coinbase of exposing sensitive personal data belonging to millions of users. They also allege Coinbase responded ineffectively after being attacked. Plaintiff Paul Bender argued that Coinbase failed to take adequate steps to safeguard user information. Consequently, customers are vulnerable to identity theft and fraud.
A fourth lawsuit adds another layer of criticism, alleging that Coinbase has “unjustly benefited” by failing to invest sufficiently in data security measures. This lawsuit suggests that the company prioritized cost-cutting over protecting its users, exacerbating the impact of the breach.
Meanwhile, a fifth lawsuit filed in California seeks a court order compelling Coinbase to delete all sensitive data related to the plaintiff. It also demands that Coinbase hire an independent auditor to evaluate its security systems. This case underscores growing demands for stricter oversight and accountability in how crypto exchanges handle user data.
Finally, a lawsuit filed in Illinois on May 13 takes aim at Coinbase’s handling of biometric data. The complaint alleges that the exchange collects and stores biometric information without providing adequate notice regarding the purpose and duration of data retention. This allegation highlights broader concerns about privacy violations in the digital asset space.
The Data Breach Fallout
In a May 15 blog post, Coinbase disclosed that “less than 1%” of its users had their sensitive information compromised. The data included names, addresses, masked bank details, identity documents, and other personal data. The breach prompted a ransom demand of $20 million in exchange for the stolen data. In response, Coinbase publicized the leak and offered a bounty for information leading to the arrest of those responsible.
Despite the initial near-double-digit drop in its stock price following the announcement, Coinbase’s shares have since rebounded. As of this writing, the stock is trading at $263, reflecting a 7% increase since the breach is out.
The negative impact of the breach was partially offset by Coinbase’s announcement earlier that week. The company revealed it had been added to the S&P 500. This is a significant milestone for any publicly traded company in the U.S. This inclusion likely helped stabilize investor confidence amid the controversy.
Legal Challenges and Regulatory Scrutiny

The lawsuit against Coinbase comes amid increasing scrutiny of crypto exchanges and their compliance with regulatory standards. Investors are calling for greater transparency, particularly regarding incidents like data breaches. Such incidents could materially affect stock performance.
Legal experts note that while lawsuits are relatively easy to file in the U.S., they must meet specific criteria to proceed.
“While almost anyone can try to sue for many reasons, there are important rules and limits,” said Andrew Rossow, a reputation management attorney and founder of Rossow Law.
“For example, courts can quickly dismiss cases that have no legal basis, even if everything the person says is true.”
Rossow emphasized that plaintiffs must demonstrate they were directly affected by the issue and suffered a tangible injury to have their case heard in court.
What’s Next for Coinbase?
Nessler’s lawsuit seeks a trial by jury, though the complaint does not specify the amount of damages being sought. The outcome of this case, along with the six other lawsuits, could have significant implications for Coinbase. It could also affect other crypto companies navigating the complex intersection of digital assets, securities laws, and regulatory compliance.
For now, Coinbase’s stock appears to be recovering, buoyed by its inclusion in the S&P 500 and its efforts to address the breach proactively. However, the lawsuits serve as a reminder of the challenges crypto companies face in maintaining investor trust while operating in a rapidly evolving regulatory landscape.
Final Thoughts
The lawsuit against Coinbase highlights the growing importance of transparency and timely disclosures in the crypto industry. As regulatory scrutiny intensifies, companies must strike a delicate balance between protecting user data and maintaining investor confidence.
For investors like Brady Nessler, the case underscores the potential risks of investing in a sector still grappling with regulatory uncertainty. Whether these lawsuits will lead to meaningful changes in how Coinbase and other crypto exchanges handle data breaches and shareholder communications remains to be seen.