Meet the Top 101 in Crypto
Regulation
Complexity Icon Easy
10 min read

Coinbase’s Inverted Bank: Where Surveillance Is Mandatory but Protection Is Optional

Published 10 October 2025
Dr. Lorena Nessi
Authors

Key Takeaways

  • Coinbase applies full compliance screening; users get limited legal protection.
  • Pass-through coverage may protect U.S. cash at partner banks, not crypto.
  • UK and EU balances are safeguarded, not insured, and may take time in insolvency.
  • Real protection comes from self-custody, hardware 2FA and strict withdrawal controls.

In traditional banking, the relationship between the user and the institution is clear. Users place money in a regulated system that protects them under rules established by the government. The bank holds those funds, and if it fails, deposit insurance, which reimburses depositors up to a legal limit, steps in. The safety net is not always infallible, but it is backed by law.

Coinbase has inverted that model. The exchange is not a bank, and cryptocurrency is not covered by public insurance through the same regulators.

Comments about Coinbase announcement | Source: X
Comments about Coinbase announcement | Source: X

Users put money in, but what they receive is not the same kind of protection. There is no public guarantee, insurance, or public safety mechanism for their digital assets. 

While Coinbase carries a private crime policy, it only covers large-scale platform breaches and explicitly excludes losses resulting from an individual user’s compromised password or phishing scam. Thus, the user trades control for convenience and inherits nearly all the risk.

Surveillance, however, remains, but without offering the same legal safeguards in return. Users face bank-style scrutiny with none of the protection that normally comes with it.

This article explains why Coinbase subjects users to bank-style surveillance without offering the same protection for their assets as a bank. It shows how the company’s user agreement limits liability to protect the exchange and why the risk of loss ultimately falls on users, not the company. It also outlines essential security practices for crypto users.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Experience a 1-minute swap on a non-custodial platform.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
Show More

Why Coinbase Monitors Like a Bank but Protects Unlike One

Coinbase behaves like a bank when it comes to monitoring but not when it comes to protection. It watches every transaction, verifies every identity, and records every movement. Yet none of this scrutiny guarantees safety for your assets.

Surveillance and Compliance Obligations

To use Coinbase is to enter a system designed for oversight. Every action leaves a trace. Every account comes with rules that mirror traditional banking compliance. Users must satisfy a checklist that includes:

  • Full identity disclosure: Coinbase requires government-issued identification, a verified address, date of birth, and other personal details.
  • Source verification: Users are often asked to confirm where their funds originate and how they were earned.
  • Transaction tracking: Every movement of money or crypto is monitored and analyzed for irregular activity under Anti-Money Laundering (AML) standards.
  • Sanctions enforcement: The platform screens users against the Office of Foreign Assets Control (OFAC) and other international watchlists.
  • Permanent data retention: Coinbase stores user data, device information, and Internet Protocol (IP) logs for regulatory review and audit compliance.

These requirements satisfy Know Your Customer (KYC) and AML laws. They also create an uneven balance of visibility: Coinbase can see everything, while users remain in the dark about how their information is used or shared.

Where FDIC Coverage Stops and Crypto Risk Begins

It is important to note that Coinbase clearly states that it is not an FDIC-insured institution. Digital currencies are not protected by the FDIC, the National Credit Union Share Insurance Fund (NCUSIF), or the Securities Investor Protection Corporation (SIPC).

It works according to the following:

  • Cash balances: U.S. dollar holdings are kept in custodial accounts at partner banks. These balances may qualify for pass-through FDIC insurance up to $250,000 per depositor, but only for the cash, not for any cryptocurrency.
  • Crypto holdings: Assets such as Bitcoin (BTC), Ether (ETH), or USD Coin (USDC) have no government-backed insurance. If Coinbase fails, experiences a hack, or suffers a protocol error, the loss belongs to the user
  • Crime insurance: Coinbase maintains limited coverage to protect against internal theft or corporate-level breaches. This policy does not cover most user-side incidents, such as phishing, account takeovers, or lost credentials.

United Kingdom (UK) and European Union (EU): Safeguarding, Not Insurance

In the UK and EU, Coinbase uses safeguarding, not insurance. A legal distinction under the Electronic Money Regulations 2011 (EMRs), enforced by the Financial Conduct Authority (FCA), points out that funds are held separately from Coinbase’s own operational accounts. If Coinbase goes bankrupt, those funds should be returned after insolvency proceedings. There is no government payout guarantee (unlike the FDIC’s).

Additionally, for an unauthorised transaction in an e-money wallet caused by lost or stolen credentials, users are liable for the first £35 ($45). If users act fraudulently or negligently, they can be liable for the full loss.

While dollar balances may rest under a partial safety net in the U.S., and some Canadian accounts may qualify for limited CDIC coverage, UK and EU customers operate under a segregation model, not an insurance one.

Digital assets everywhere exist entirely outside these safety nets. Coinbase borrows the language of banking words like “custody” and “balance,” but not its guarantees.

 The next section outlines the structure in simple terms.

Coinbase Insurance Overview

Coinbase separates the way it treats cryptocurrency holdings from how it treats cash balances.

The difference matters. While crime insurance exists for limited theft scenarios, government-backed protection applies only to certain cash holdings, not to digital assets.

Category Type of coverage Who provides it What it covers What it excludes Coverage limit
Cryptocurrency Crime insurance Coinbase Global, Inc. Theft or cyber breach User account breaches Limited, undisclosed
Cryptocurrency Government insurance None None All crypto losses No protection
U.S. cash Federal Deposit Insurance Corporation (FDIC) Partner banks Cash in custodial accounts Crypto, corporate funds Up to $250,000
U.S. credit unions National Credit Union Share Insurance Fund (NCUSIF) Partner credit unions Cash in pooled accounts Digital assets Up to $250,000
Canada cash Canada Deposit Insurance Corporation (CDIC) Partner with Canadian banks Cash in trustee accounts Crypto, non-PTA funds Up to C$100,000
Canada crypto None None None All digital assets No protection

Even with these layers of institutional and government protection, the gap between insured cash and uninsured crypto remains stark. Coinbase’s insurance only addresses limited operational losses; it does not shield users from hacks on individual accounts, phishing attacks, or exchange insolvency. In practice, the burden of safeguarding digital assets still rests on the user, not the platform. 

This reality makes personal security discipline, not deposit insurance, the most reliable form of protection in the crypto ecosystem.

Before getting into the main practices to follow it is important to note the surveillance aspect. 

How Coinbase Extends Oversight Beyond Onboarding

Compliance is ongoing. Monitoring runs in the background. Users should expect the following controls: 

  • Financial Action Task Force (FATF) Travel Rule: Identity data may accompany transfers between Virtual Asset Service Providers (VASPs) once thresholds apply.
  • Crypto-Asset Reporting Framework (CARF): Once implemented, Coinbase will share standardized cross-border transaction data with tax authorities under the OECD’s CARF, aligning crypto oversight with traditional financial reporting systems.
  • Suspicious Activity Reports (SARs): Coinbase reports suspicious activity to regulators and cannot notify the user.
  • Law enforcement requests: Subpoenas, production orders and preservation requests can compel data sharing and account holds.
  • Automated risk screening: Blockchain analytics score wallet history, mixer exposure and sanctions links, which can trigger reviews.
  • Freezes and withdrawal holds: Accounts or withdrawals may be paused during compliance checks or sanctions screening.
  • Geofencing and sanctions blocking: Location, device and Internet Protocol (IP) checks enforce regional rules and sanctions lists.
  • Record retention: Identity, device and IP logs are stored for years to meet legal duties.
  • Enhanced due diligence: Higher risk profiles or higher limits can require repeat checks on source of funds and source of wealth.

The community has reacted. 

Criticism of Coinbase | Source: X
Criticism of Coinbase | Source: X

The immediate priority is practical security.

Not Your Keys, Not Your Funds? Top Security Measures To Protect Digital Assets

Because CEXs shift risk to the user, the only safe posture is assuming full responsibility for security. If using Coinbase or similar platforms, the following practices form a realistic defense strategy in 2025.

Major key security practices are the following: 

  • Withdraw major holdings to self-custody: Keep long-term assets in hardware wallets such as Ledger or Trezor, or in multi-signature vaults. Exchanges should serve as temporary venues for trading, not storage.
  • Use strong, unique passwords: Generate long random passwords and store them in an encrypted password manager. Reusing credentials across platforms remains one of the most common causes of account breaches.
  • Enable two-factor authentication (2FA): Use physical devices that follow the Fast Identity Online (FIDO) standard, such as Universal 2nd Factor (U2F) keys like YubiKey. Avoid text-message or app-based codes, which can be intercepted through SIM swaps or malware.
  • Whitelist withdrawal addresses: Restrict transfers to verified wallet addresses only. This simple measure blocks most unauthorized withdrawals.
  • Activate withdrawal delays or vault features: When available, enable time-locked withdrawals or vault mechanisms. These settings allow users to cancel suspicious transactions before funds leave the platform.
  • Monitor account activity: Turn on notifications for all logins, withdrawals, and device changes. Review logs frequently for irregular activity.
  • Limit external integrations: Keep Application Programming Interface (API) connections on read-only mode. Revoke access to bots, tax software, or analytic tools when they are no longer needed.
  • Distribute and segregate holdings: Spread assets across multiple wallets or exchanges. Diversification reduces exposure if one service fails or is compromised.
  • Keep devices and software current: Update operating systems, firmware, and security tools regularly. Avoid jailbroken or rooted devices that disable built-in protections.
  • Use decentralized tools: Use non-custodial wallets or decentralized exchanges (DEX) whenever possible. Reducing dependence on centralized intermediaries lowers systemic risk.
  • Adopt multi-signature security: Multi-signature (multisig) vaults that require several approvals (such as 2-of-3 or 3-of-5 keys) create strong resistance to single-point compromise.
  • Maintain an offline seed backup: Write recovery phrases on durable, offline materials such as metal or laminated paper. Never store them on connected devices or cloud services.
  • Stay alert to phishing and social engineering: In 2025, attackers bribed insiders at several exchanges to obtain user data. Never engage with unsolicited messages or calls claiming to be from customer support. Always verify through official channels.
  • Run test transfers before moving funds: Send small test transactions to verify addresses and network accuracy before transferring large amounts.
  • Track exchange policy updates: Follow official blog posts and legal notices. In 2025, Coinbase quietly updated its insurance overview, underscoring why users must stay informed of ongoing policy changes.

Conclusion

Coinbase runs rigorous monitoring that mirrors banking compliance. Identity checks, sanctions screening and transaction analysis are built in. Visibility is one-way. The platform sees everything; users see little about downstream data use.

Protection, however, is limited. Cash at U.S. partner banks may have pass-through protection from the Federal Deposit Insurance Corporation (FDIC). UK and EU balances are safeguarded, not insured. Cryptocurrency everywhere sits outside government guarantees.

Practical safety rests with the user. Move long-term holdings to self-custody, use two-factor authentication (2FA) with hardware keys, whitelist withdrawals and enable delays. Treat centralized platforms as venues for liquidity, not storage.

FAQs

Are non-fungible tokens (NFTs) covered by Coinbase’s crime insurance?

No. Coinbase crime insurance excludes non-fungible tokens (NFTs) and does not cover user account breaches.

Can UK users take crypto disputes to the Financial Ombudsman Service (FOS)?

Generally no. The Financial Ombudsman Service (FOS) handles e-money issues; Digital Asset Services fall outside its scope.

Is Coinbase Vault a multisignature wallet?

No. Coinbase Vault provides withdrawal delays and approvals, but Coinbase does not support multisignature vaults on-platform.

Does safeguarding in the UK or EU guarantee quick payout if Coinbase fails?

No. Safeguarding under the Electronic Money Regulations (EMRs) means segregation, not insurance, and funds are returned after insolvency proceedings.

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Dr. Lorena Nessi

Dr. Lorena Nessi is an award-winning journalist and media technology expert with 15 years of experience in digital culture and communication. Based in Oxfordshire, UK, she combines academic insight with hands-on media practice.

She holds a PhD in Communication, Sociology, and Digital Cultures, and an MA in Globalization, Identity, and Technology.

Lorena has taught at Fairleigh Dickinson University, Nottingham Trent University, and the University of Oxford. She is a former producer for the BBC in London, with additional experience creating television content in Mexico and Japan.

Her research focuses on digital cultures, social media, technology, capitalism, and the societal impact of blockchain innovation.

She has written extensively on digital media and emerging technologies, with her work featured in both academic and media platforms. Her Web3 expertise explores how blockchain technologies shape culture, economics, and decentralized systems.

Outside of work, Lorena enjoys reading science fiction, playing strategic board games, traveling, and chasing adventures that get her heart racing. A perfect day ends with a relaxing spa and a good family meal.

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status