BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Coinbase Faces €170,874 Dutch Lawsuit Threat Over Account…

Why Is a Coinbase Customer Threatening Legal Action? Coinbase is facing the prospect of civil proceedings in the Netherlands after a customer issued a formal notice of default demanding €170,

AnonymousCryptoCompass newsroom
September 12, 2026
5 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

Coinbase Revives Direct Deposit Feature

Coinbase is facing the prospect of civil proceedings in the Netherlands after a customer issued a formal notice of default demanding €170,874.18 over an alleged 2024 account takeover and unauthorized removal of funds. The notice, made public on September 12, gives Coinbase 14 calendar days to pay the claimed amount or provide an unconditional commitment to do so. If that does not happen, the customer says Dutch litigation counsel will be instructed to serve a writ of summons, or dagvaarding. No lawsuit has yet been shown as filed, making the document a pre-litigation escalation rather than an existing Dutch court case. The claimant says the dispute began with a January 27, 2024 cyberattack on a Coinbase consumer account. An attacker allegedly gained access through session-cookie hijacking and caused €53,674.95 in fiat funds to leave Coinbase through four transactions completed in less than two minutes. The customer says Coinbase rejected liability in a July 4, 2024 final response and attributed the incident to compromised customer credentials. That response has not been independently reviewed.

Why Does Dutch Payment Law Matter?

The new demand relies heavily on Dutch payment-services rules governing unauthorized transactions. Article 7:522 of the Dutch Civil Code generally requires the payer's consent for a payment transaction to be considered authorized. Article 7:527 adds that the mere recorded use of a payment instrument is not necessarily enough to prove that the customer approved a transaction or acted fraudulently or with gross negligence. That distinction could be important if the case reaches court. Coinbase may need more than evidence that valid account credentials or an authenticated session were used if it argues that the customer should bear the loss. Article 7:528 generally requires payment service providers to refund unauthorized payments promptly after becoming aware of them, subject to exceptions. Article 7:529, however, allows losses to fall on the customer where fraud or an intentional or grossly negligent breach of security obligations is established. The central factual dispute would therefore remain how the Coinbase account was compromised and whether the customer's conduct met the legal threshold for gross negligence.

Investor Takeaway

The legal risk is not determined by the €170,874 demand alone. If proceedings are filed, the dispute could force detailed scrutiny of Coinbase's authentication records, transaction controls and handling of unauthorized-payment claims under European law.

Could Coinbase's Security Controls Come Under Scrutiny?

The claimant is also challenging Coinbase's transaction monitoring, alleging the platform failed to react to a sudden geographical change and four rapid high-value transfers and did not require transaction-linked Strong Customer Authentication. European payment rules generally require SCA when a payer initiates an electronic payment, with remote payments requiring authentication linked to the amount and payee. Exemptions exist, however, including for certain transactions assessed as low risk. That means the SCA argument is unlikely to turn simply on whether additional authentication occurred. A court could instead need to determine the payment flow, whether an exemption applied and what risk signals were available when the disputed transfers were processed. If litigation begins, potentially important evidence could include login records, device fingerprints, session-token history, IP data, SCA events, withdrawal authorization records and internal fraud-monitoring alerts generated during the short transaction sequence. The claimant says Coinbase itself identified session-cookie hijacking as part of the incident. That claim could become important if supported by Coinbase's records, but it remains an allegation until independently established.

Why Is the €170,874 Claim More Complicated Than the Original Loss?

The customer is seeking substantially more than the €53,674.95 allegedly removed from the account. The demand also includes €106,397.02 in claimed missed portfolio profits tied to 1.40402148 BTC and 12,031.26215895 DOGE that the customer says were forcibly liquidated. The calculation uses the portfolio's claimed peak value on October 6, 2025. Dutch law can permit recovery for profit forgone, but proving that the customer would have retained the assets until a later market peak could be considerably harder than establishing the original cash loss. Causation, trading history and the method used to value the lost opportunity would likely face scrutiny. The demand also includes €9,990.91 in statutory interest. That calculation may be disputed because the letter applies a flat 7% rate from January 2024 through September 2026, while Dutch consumer statutory interest changed during that period. Another issue is which Coinbase entity was legally responsible for the customer's euro payment services at the time of the January 2024 incident. Coinbase later reorganized parts of its European business, but any litigation would need to examine the contractual and entity structure in force when the disputed transactions occurred. Coinbase could respond during the 14-day period, contest the damages calculation, dispute the applicable entity or maintain its earlier rejection. But if a summons is served, what began as a customer-support dispute could become an evidence-heavy Dutch proceeding over authorization, authentication, gross negligence and payment-security controls. For now, the September 12 notice moves the dispute closer to court without putting Coinbase there yet.