BlockTower's Ari Paul Accuses Coinbase of Hiding $1 Billion in Hack Losses, Coinbase Denies It

BlockTower Capital founder Ari Paul says Coinbase concealed more than $1 billion in hacking losses across at least a dozen firms, and that his own fund never got back $25 million Coinbase lost years ago. Coinbase says that did not happen. Simply Bitcoin covered the dispute on air with Build with Bitcoin co-host Israel Munoz, a Bitcoiner since 2014, and the conversation moved quickly past the unresolved accusation to a harder question: does it actually matter who is right.
A BLOCKTOWER FOUNDER'S BILLION DOLLAR ACCUSATION
Paul's claim, posted on X in late September, is specific: Coinbase told BlockTower a couple of years ago that $25 million of the fund's money was lost, and Paul says a later investigation traced that incident to a broader pattern, at least twelve affected firms and over $1 billion in combined concealed losses. He has not published supporting documents and says ongoing legal proceedings limit what he can disclose.
Coinbase has denied hiding a series of hacks and denied losing $1 billion, though it has not specifically addressed Paul's $25 million claim about BlockTower. The company has pointed instead to a disclosed 2025 incident involving bribed overseas contractors who improperly accessed customer data, which it says is unrelated to Paul's allegations.
ON THE SHOW, THE VERDICT DIDN'T WAIT ON THE EVIDENCE
Asked directly whether he believes the allegations are real, Munoz did not hedge toward either side. He said the specifics are almost beside the point next to what the industry is actually being forced to confront.
"I think ultimately it doesn't matter much. The main lesson which we've clearly been going through in the past few months is we need to take a serious look at custody setups."
His reasoning: whether or not Paul's numbers hold up, the pattern of custody failures this year, from exchange disputes to a hardware wallet exploit that drained real user funds, is already pushing both individuals and institutions toward harder setups. Munoz pointed to multi key, multi institutional custody arrangements, naming Anchorwatch as one example, as the direction the industry is being pushed whether or not any single allegation is ever proven.
THE COLDCARD LESSON STILL HASN'T FULLY LANDED
Munoz's comparison was not abstract. In late July, a firmware flaw dating back to a 2021 code change let attackers brute force private keys on affected Coldcard hardware wallets, draining roughly 1,816 BTC, worth about $116 million, from more than 5,200 addresses across four waves. The bug had nothing to do with physical theft: it silently weakened the randomness behind seed generation on some devices from 128 bits of entropy down to as little as 40, making the keys guessable without ever touching the wallet.
Munoz called the Coldcard exploit a genuine surprise, the one thing in 2026 he said he did not see coming, and tied it directly to the custody argument: self custody has always been sold as the safe alternative to trusting an exchange, and this year made clear that the hardware side of that promise can fail too.
WHY INSTITUTIONS ARE WATCHING BOTH STORIES AT ONCE
Munoz connected the dispute to something he had heard directly from a large allocator at a recent industry event: investment committees made up mostly of people in their fifties and sixties are already cautious about Bitcoin, and a billion dollar exchange allegation, proven or not, is exactly the kind of headline that extends their hesitation. The specific number in Paul's claim may never be settled in public. The custody standard it is pushing the industry toward is the part that will outlast the dispute either way.
This story comes from the Simply Bitcoin Live show. Watch the full episode.



