Coinbase Faces €21.5 Million Fine After Millions Of Transactions Went Unmonitored
Coinbase Europe Limited has been hit with a €21.5 million fine by the Central Bank of Ireland after regulatory authorities discovered that its transaction monitoring system failed to properly review over 30 million customer transactions, valued at more than €176 billion, between 2021 and 2022.
Some of these transactions were later linked to serious criminal activity, including money laundering, fraud, drug trafficking, cyber-attacks, and child sexual exploitation.
Coding Errors Allowed Transactions To Slip Through
The Central Bank found that the failures arose from coding mistakes in Coinbase’s Transaction Monitoring System (TMS).
The system, designed to flag suspicious or high-risk activity, ran 21 different monitoring scenarios.
However, three errors caused five of those scenarios to miss certain transactions, particularly cryptocurrency wallet addresses containing special characters.
Coinbase said the errors were identified through internal testing and fixed within a few weeks.
However, completing a full review of all impacted transactions took almost three years.
During this period, approximately 184,790 transactions were flagged for further investigation, resulting in 2,708 Suspicious Transaction Reports (STRs) to Irish authorities, covering roughly €13 million.
The Central Bank stressed that while there is no evidence these transactions led to actual crimes, the failure to monitor them in real time represented a major breach.
Regulator Criticises Weak Internal Controls
Colm Kincaid, Deputy Governor of Consumer & Investor Protection at the Central Bank of Ireland, said the lapse exposed vulnerabilities that could be exploited by criminals.
He added:
“To be effective in combatting financial crime, law enforcement agencies rely on regulated financial institutions to have systems in place to monitor transactions and report suspicions. The failure of such a system within any financial institution creates an opportunity for criminals to evade detection. And criminals will take that opportunity.”
The regulator also highlighted that some customers involved in suspicious transactions retained access longer than they should have due to weak internal monitoring, reflecting broader deficiencies in Coinbase Europe’s compliance procedures.
Coinbase Responds With System Overhaul
Coinbase acknowledged the errors, describing them as coding mistakes that affected transaction monitoring in 2021 and 2022.
Source: Coinbase
The company stated it had swiftly corrected the faulty code, reviewed all relevant transactions, and filed the necessary STRs.
It also emphasised that it has strengthened internal controls, enhanced testing before implementing new code, and developed additional TMS scenarios to detect evolving financial risks.
The company said:
“Registered companies like CBEL are required to file STRs if they suspect or have reasonable grounds to suspect a party to the transaction is engaged in money laundering or other illicit activity. As part of this settlement, the CBI and CBEL cannot say that the transactions in these 2,700 reports actually resulted in criminal activity.”
Settlement And Fine Details
The fine of €21.5 million represents a reduction from an initial €30.7 million, reflecting Coinbase’s cooperation and settlement under the Central Bank’s Administrative Sanctions Procedure.
The regulator also considered the company’s average annual revenue of €417 million between 2021 and 2024 when determining the penalty.
This is the fourth-largest fine ever issued by the Central Bank and its first against a cryptocurrency firm.
Impact On Coinbase And European Operations
The sanction comes less than three years after Coinbase Europe was authorised by the Central Bank.
Despite the fine, Coinbase continues to expand in Europe and other markets, reporting $1.9 billion in revenue for Q3 2025, up 25% from the previous quarter.
The company has also announced plans to relocate its European business to Luxembourg by the end of the year.
Coinbase Global Inc., listed on NASDAQ as COIN, saw its share price fall 5.44% to $301.92 following the news, with analysts noting that its performance often tracks broader cryptocurrency trends, particularly Bitcoin.
How Could This Happen With Advanced Systems
The incident highlights the risks of relying heavily on automated systems without rigorous testing.
While most TMS scenarios continued to function correctly, the overlooked coding errors meant nearly a third of Coinbase Europe’s transactions in the 12-month period went unchecked.
It took years to fully assess the scale of the issue, illustrating how technical oversights can create regulatory and operational vulnerabilities.
Coinbase Pledges Stronger Compliance Oversight
Moving forward, Coinbase has committed to enhanced oversight of its compliance tools, improved internal controls, and continued investment in its monitoring systems.
The company emphasised that compliance remains a priority and that it will continue developing new TMS scenarios to address evolving threats in the cryptocurrency sector.
This regulatory episode serves as a reminder of the challenges crypto exchanges face in balancing automated transaction monitoring with the need for robust human oversight.