Coinbase has notified the California Attorney General's office of a data security breach, which resulted in the theft of customer credentials. The breach occurred due to a flaw in Coinbase's SMS account recovery process, allowing attackers to bypass two-factor authentication. Coinbase has updated its protocols to prevent further bypassing of this authentication process and plans to reimburse affected customers. The exact nature of the breach is still being discussed, with some speculating that it may have involved SIM swapping or other forms of attack.