Securities Regulation Daily Wrap Up, BLOCKCHAIN—E.D. Pa.: Coinbase sued for allegedly concealing anti-money laundering deficiencies, (May 29, 2025)
Law Firms Mentioned:Edelson Lechtzin LLP
Organizations Mentioned:Coinbase Global, Inc.
By Kristin J. Angelino, J.D.
According to the complaint, the company failed to disclose that its United Kingdom-based subsidiary had been found by a UK regulatory agency to have inadequate anti-money laundering controls.
A putative class action complaint filed in the Eastern District of Pennsylvania against Coinbase Global, Inc., a digital currency wallet and platform (Coinbase), and two of its executive officers, alleges that Coinbase violated federal securities laws by making false and misleading statements in its 2021 IPO offering documents and subsequent periodic reports by failing to disclose material adverse facts related to the company’s anti-money laundering systems. The plaintiffs claim that Coinbase’s false and misleading information and failure to disclose violated Section 10(b) of the Exchange Act and Rule 10b-5 thereunder (Nessler v. Coinbase Global, Inc., No. 2:25-cv-02637 (E.D. Pa. May 22, 2025)).
The class action suit was filed on behalf of investors who bought Coinbase securities between April 14, 2021 and May 14, 2025 (the Class Period).
The complaint alleges that Coinbase and its CEO and CFO (collectively, Defendants), violated federal securities laws by issuing materially false and misleading statements in its public filings because such filings omitted adverse facts regarding the company’s business, operations and prospects.
Specifically, the complaint alleges that the defendants made false and/or misleading statements and/or failed to disclose that:
In 2020, following an investigation, the United Kingdom’s Financial Conduct Authority (the FCA) determined that efforts by CB Payments Ltd., a UK-based subsidiary of Coinbase (CBPL), to prevent criminals from using its platform, were inadequate;
The FCA reached an agreement with CBPL (the FCA Agreement), which put requirements in place that were designed to prevent high-risk customers from using CBPL’s platform;
CBPL subsequently breached the FCA Agreement, which resulted in 13,416 high-risk individuals receiving services, resulting in a heightened regulatory risk;
In December 2024, Coinbase had been hacked and its accounts compromised; and
The SEC was investigating Coinbase for its account problems.
FCA fine. On July 25, 2024, the FCA published a press release entitled, “FCA takes first enforcement action against firm enabling cryptoasset trading.” The press release stated that CBPL had repeatedly breached the FCA Agreement (which agreement was entered into after the FCA found “significant weaknesses and gaps” in CBPL’s financial crime control framework) and was being fined approximately £3.5 million. The same day, Reuters also released an article about the breach entitled “Coinbase UK unit fined for breaching financial crime requirements.” The complaint alleges that this news caused CGI’s common stock to close at $231.52 that day, a drop of $13.52 per share, or 5.52%, causing significant losses to Plaintiffs.
Cybersecurity incident. According to the complaint, NBC News and other media outlets reported on May 5, 2025 that Coinbase was among a group of companies affected by the hack of TeleMessage, an archiving and messaging platform that allows organizations to capture and store mobile communications.
However, Coinbase did not publicly disclose the hack until May 14, 2025, when it filed a report on Form 8-K describing a “Material Cybersecurity Incident.” The company also addressed the hack in a statement made on May 15, 2025, where it disclosed that cybercriminals had successfully bribed Coinbase customer service agents outside the US to hand over sensitive personal data on Coinbase customers. The company also disclosed that it refused to pay the $20 million ransom demanded by the hackers in exchange for the return of the information.
The complaint alleges that, upon receipt of this news, Coinbase’s common stock fell by $19.85 per share, or 7.2%, to close at $244 on May 15, 2025, causing significant additional losses to Plaintiffs.
Section 20(a) claim. In addition to the primary security count alleged, the complaint seeks to hold the company’s CEO and CFO liable as controlling persons pursuant to Section 20(a) of the Exchange Act.
Relief sought. The complaint seeks a determination that the action may be maintained as a class action. In addition, the complaint seeks to recover damages against all defendants, jointly and severally, by awarding the plaintiff and other members of the class damages, including interest, for losses sustained by the company’s acts, and reasonable costs and expenses, including attorney’s fees and expert fees.
The case is No. 2:25-cv-02637.
Attorneys: Eric Lechtzin (Edelson Lechtzin LLP) for Brady Nessler.
Companies: Coinbase Global, Inc.
LitigationEnforcement: Blockchain ExchangesMarketRegulation FinancialIntermediaries FraudManipulation PublicCompanyReportingDisclosure PennsylvaniaNews