FULLTEXT DEL 2 AV 4
10-K – 2026-02-12 – coin-20251231.htm
Because Coinbase Spot Market, Coinbase Prime and Coinbase app are not registered or licensed with the SEC or foreign authorities as a broker-dealer, national securities exchange, or ATS (or foreign equivalents), we only permit trading of those crypto assets, and offer products and services, for which we determine there are reasonably strong arguments to conclude that the crypto asset, product or service is not a security. We believe that our process reflects a comprehensive and thoughtful analysis and is reasonably designed to facilitate consistent application of available legal guidance on crypto assets, products and services and to facilitate informed risk-based business judgment. In addition, as we shared in our petition for SEC rulemaking, we remain open to registering or relying on an exemption to facilitate and offer the sale of securities involving crypto assets. We recognize that the application of securities laws to the specific facts and circumstances of crypto assets, products and services may be complex and subject to change, and that a listing determination does not guarantee any conclusion under the U.S. federal securities laws. Regardless of our conclusions, we have been, and could in the future be, subject to legal or regulatory action in the event the SEC or a state or foreign regulatory authority were to assert, or a court were to determine, that a supported crypto asset, product or service offered, sold, or traded on our platform or a product or service that we offer is a “security” under applicable laws. There can be no assurance that we will properly characterize over time any given crypto asset, product or service offering as a security or non-security, or that the SEC, foreign regulatory authority, or a court having final determinative authority on the topic, if the question was presented to it, would agree with our assessment. We expect our risk assessment policies and procedures to continuously evolve to take into account case law, legislative developments, facts, and developments in technology. If an applicable regulatory authority or a court, in either case having final determinative authority on the topic, were to determine that a supported crypto asset, product or service currently offered, sold, or traded on our platform is a security, we would not be able to offer such crypto asset for trading, or product or service on our platform, until we are able to do so in a compliant manner. A determination by the SEC, a state or foreign regulatory authority, or a court that an asset that we currently support for trading on our platform, or product or service that we offer on our platform, constitutes a security may result in us removing that crypto asset from or ceasing to offer that product or service on our platform, and may also result in us determining that it is advisable to remove assets from our platform, or to cease offering products and services on our platform, that have similar characteristics to the asset, product or service that was alleged or determined to be a security. Alternatively, we may determine not to remove a particular crypto asset from Coinbase Spot Market or to continue to offer a product or service on our platform even if the SEC or another regulator alleges that the crypto asset, product or service is a security, pending a final judicial determination as to that crypto asset, product or service’s proper characterization, and the fact that we waited for a final judicial determination would generally not preclude penalties or sanctions against us for our having previously made our platform available for trading that crypto asset or offering that product or service on our platform without registering as a national securities exchange or ATS or registering tokens that we may issue, such as our cbETH and cbBTC tokens or our staking services, with the SEC. As such, we could be subject to judicial or administrative sanctions for failing to offer or sell the crypto asset, product or service in compliance with the registration requirements, or for acting as a broker, dealer, or national securities exchange without appropriate registration. Such an action could result in injunctions, cease and desist orders, as well as civil monetary penalties, fines, and disgorgement, criminal liability, and reputational harm. Customers that traded such supported crypto asset on our platform and suffered trading losses could also seek to rescind a transaction that we facilitated on the basis that it was conducted in violation of applicable law, which could subject us to significant liability. We may also be required to cease facilitating transactions in the supported crypto asset other than via our licensed subsidiaries, which could negatively impact our business, operating results, and financial condition. Additionally, the SEC has brought and may in the future bring enforcement actions against other industry participants and their product offerings and services that may cause us to modify or discontinue a product offering or service on our platform. If we were to modify or discontinue any product offering or service or remove any assets from trading on our platform for any reason, our decision may be unpopular with users, may reduce our ability to attract and retain customers (especially if similar products, services or such assets continue to be offered or traded on unregulated exchanges, which includes many of our competitors), and could adversely affect our business, operating results, and financial condition. 38 Table of Contents Further, if Bitcoin, Ethereum, stablecoins or any other supported crypto asset is deemed to be a security under any U.S. federal, state, or foreign jurisdiction, or in a proceeding in a court of law or otherwise, it may have adverse consequences for such supported crypto asset. For instance, all transactions in such supported crypto asset would have to be registered with the SEC or other foreign authority, or conducted in accordance with an exemption from registration, which could severely limit its liquidity, usability and transactability. Moreover, the networks on which such supported crypto assets are utilized may be required to be regulated as securities intermediaries, and subject to applicable rules, which could effectively render the network impracticable for its existing purposes. Further, it could draw negative publicity and a decline in the general acceptance of the crypto asset. Also, it may make it difficult for such supported crypto asset to be traded, cleared, and custodied as compared to other crypto assets that are not considered to be securities. Specifically, even if transactions in such supported crypto asset were registered with the SEC or conducted in accordance with an exemption from registration, the current intermediary-based framework for securities trading, clearance and settlement is not consistent with the operations of the crypto asset market. For example, the SEC has not permitted public permissionless blockchain-based clearance and settlement systems for securities. We currently rely on third-party service providers for certain aspects of our operations, and any interruptions in services provided by these third parties may impair our ability to support our customers. We rely on third parties in connection with many aspects of our business, including payment processors, financial institutions, and payment gateways to process transactions; cloud computing services and data centers that provide facilities, infrastructure, smart contract development, website functionality and access, components, and services, including databases and data center facilities and cloud computing; as well as third parties that provide outsourced customer service, compliance support and product development functions, which are critical to our operations. Because we rely on third parties to provide these services and to facilitate certain of our business activities, we face increased operational risks. We do not directly manage the operation of any of these third parties, including their data center facilities that we use. These third parties may be subject to financial, legal, regulatory, and labor issues, cybersecurity incidents, data theft or loss, break-ins, computer viruses or vulnerabilities in their code, denial-of-service attacks, sabotage, acts of vandalism, loss, disruption, or instability of third-party financial institution relationships, privacy breaches, service terminations, disruptions, interruptions, and other misconduct. They are also vulnerable to damage or interruption from human error, power loss, telecommunications failures, fires, floods, earthquakes, hurricanes, tornadoes, pandemics and similar events. In addition, these third parties may breach their agreements with us, disagree with our interpretation of contract terms or applicable laws and regulations, refuse to continue or renew these agreements on commercially reasonable terms or at all, fail or refuse to process transactions or provide other services adequately, take actions that degrade the functionality of our services, impose additional costs or requirements on us or our customers, or give preferential treatment to competitors. There can be no assurance that third parties that provide services to us or to our customers on our behalf will continue to do so on acceptable terms, or at all. If any third parties do not adequately or appropriately provide their services or perform their responsibilities to us or our customers on our behalf, such as if third-party service providers close their data center facilities without adequate notice, are unable to restore operations and data, fail to perform as expected, or experience other unanticipated problems, we may be unable to procure alternatives in a timely and efficient manner and on acceptable terms, or at all, and we may be subject to business disruptions, losses or costs to remediate any of the deficiencies, customer dissatisfaction, reputational damage, legal or regulatory proceedings, or other adverse consequences which could adversely affect our business, operating results, and financial condition. Loss of a critical financial institution or insurance relationship could adversely affect our business, operating results, and financial condition. We rely on financial institution relationships to provide our platform and custodial services. In particular, customer cash holdings on our platform are held with one or more financial institutions. As a registered money services business with FinCEN under the Bank Secrecy Act, as amended by the USA 39 Table of Contents PATRIOT Act of 2001, and its implementing regulations enforced by FinCEN, or collectively, the BSA, a licensed money transmitter in a number of U.S. states and territories, a licensee under NYDFS’s Virtual Currency Business Activity regime, commonly referred to as a BitLicense, a licensed electronic money institution and a registered Virtual Asset Service Provider with the U.K. Financial Conduct Authority, a licensed electronic money institution under the Central Bank of Ireland, a MiCA-licensed crypto asset service provider supervised by the Commission de Surveillance du Secteur Financier in Luxembourg, and a limited purpose trust company chartered by the NYDFS, our financial institution partners view us as a higher risk customer for purposes of their anti-money laundering programs. We may face difficulty establishing or maintaining such relationships due to instability in the global banking system, increasing regulatory uncertainty and scrutiny, or our partners’ policies and some prior partners have terminated their relationship with us or have limited access to services. The loss of these partners or the imposition of operational restrictions by these partners and the inability for us to utilize other redundant financial institutions may result in a disruption of business activity as well as regulatory risks. In addition, as a result of the myriad of regulations or the risks of crypto assets generally, financial institutions in the United States and globally may decide to not provide, or be prohibited from providing, account, custody, or other financial services to us or our industry generally. Further, we have existing redundancies in U.S. and global financial institutions that work with crypto companies with which we engage. However, if these financial institutions are subject to bank resolution or failure, or limit or end their crypto market activity, or if such relationships become severely limited or unavailable to crypto market participants in a certain country, there could be temporary delays in or unavailability of services in such country that are critical to our or our partners’ operations, developers or customers, a further limit on available vendors, reduced quality in services we, our partners, our developers or our customers are able to obtain, and a general disruption to the onchain economy, potentially leading to reduced activity on our platform which could adversely affect our business, operating results, and financial condition. For example, while our business and operations have not been materially affected by the closures of Silvergate Capital Corp. and Signature Bank and the cessation of their real-time fiat currency payment networks in March 2023, large industry participants, including us and our institutional customers, experienced a temporary inability to transfer fiat currencies outside of standard business hours. We also rely on insurance carriers to insure customer losses resulting from a breach of our physical security, cybersecurity, or by employee or third party theft and hold surety bonds as required for compliance with certain of our licenses under applicable state laws. Our ability to maintain crime, specie, and cyber insurance, as well as surety bonds, is subject to the insurance carriers’ ongoing underwriting criteria and our inability to obtain and maintain appropriate insurance coverage could cause a substantial business disruption, adverse reputational impact, inability to compete with our competitors, and regulatory scrutiny, and could adversely affect our business, operating results, and financial condition. Any significant disruption in our products and services, in our information technology systems, or in any of the blockchain networks we support, could result in a loss of customers or funds and adversely affect our brand, reputation, business, operating results, and financial condition. Our reputation and ability to attract and retain customers and grow our business depends on our ability to operate our service at high levels of reliability, scalability, and performance, including the ability to process and monitor, on a daily basis, a large number of transactions that occur at high volume and frequencies across multiple systems. Our platform, the ability of our customers to trade, and our ability to operate at a high level, are dependent on our ability to access the blockchain networks underlying the supported crypto assets, for which access is dependent on our systems’ ability to access the internet. Further, the successful and continued operations of such blockchain networks will depend on a network of computers, miners, or validators, and their continued operations, all of which may be impacted by service interruptions. Our systems, the systems of our third-party service providers and partners, and certain crypto asset and blockchain networks have experienced from time to time, and may experience in the future service interruptions or degradation because of hardware and software defects or malfunctions, distributed 40 Table of Contents denial-of-service and other cyberattacks, insider threats, break-ins, sabotage, human error, vandalism, earthquakes, hurricanes, floods, fires, and other natural disasters, power losses, disruptions in telecommunications services, fraud, military or political conflicts, terrorist attacks, computer viruses or other malware, or other events. In addition, extraordinary Trading Volumes or site usage could cause our computer systems to operate at an unacceptably slow speed or even fail. Some of our systems, including systems of companies we have acquired, or the systems of our third-party service providers and partners are not fully redundant, and our or their disaster recovery planning may not be sufficient for all possible outcomes or events. If any of our systems, or those of our third-party service providers, are disrupted for any reason, our products and services may fail, resulting in unanticipated disruptions, slower response times and delays in our customers’ trade execution and processing, failed settlement of trades, incomplete or inaccurate accounting, recording or processing of trades, unauthorized trades, loss of customer information, increased demand on limited customer support resources, customer claims, complaints with regulatory organizations, lawsuits, or enforcement actions. Further, when these disruptions occur, we have in the past, and may in the future, fulfill customer transactions using inventory to prevent adverse user impact and limit detrimental impact to our operating results. A prolonged interruption in the availability or reduction in the availability, speed, or functionality of our products and services could harm our business. Significant or persistent interruptions in our services could cause current or potential customers or partners to believe that our systems are unreliable, leading them to switch to our competitors or to avoid or reduce the use of our products and services, and could permanently harm our reputation and brands. Moreover, to the extent that any system failure or similar event results in damages to our customers or their business partners, these customers or partners could seek significant compensation or contractual penalties from us for their losses, and those claims, even if unsuccessful, would likely be time-consuming and costly for us to address. Problems with the reliability or security of our systems would harm our reputation and the cost of remedying these problems could negatively affect our business, operating results, and financial condition. Because we are a regulated financial institution in certain jurisdictions, interruptions have resulted and in the future may result in regulatory scrutiny, and significant or persistent interruptions could lead to significant fines and penalties, and mandatory and costly changes to our business practices, and ultimately could cause us to lose existing licenses or financial institution relationships that we need to operate or prevent or delay us from obtaining additional licenses that may be required for our business. In addition, we are continually improving and upgrading our information systems and technologies. Implementation of new systems and technologies is complex, expensive, time-consuming, and may not be successful. If we fail to timely and successfully implement new information systems and technologies, or improvements or upgrades to existing information systems and technologies, or if such systems and technologies do not operate as intended, it could adversely affect our internal controls (including internal controls over financial reporting), and our business, operating results, and financial condition. Our failure to securely store and manage our and our customers’ fiat currencies and crypto assets could adversely affect our business, operating results, and financial condition. We hold cash and store crypto assets on behalf of our customers and hold fiat and crypto for corporate investment and operating purposes. In addition, following the acquisition of Coinbase Asset Management, formerly One River Digital Asset Management (“CBAM”), we additionally store an immaterial amount of cryptocurrencies at third-party custodians for asset management products. Further, following our acquisition of Deribit, certain amounts of cryptocurrencies are stored at third-party custodians to support trading activity on Deribit’s platform. Securely storing customers’ cash and crypto assets is integral to the trust we build with our customers. We believe our policies, procedures, operational controls and controls over financial reporting, protect us from material risks surrounding the storing of these assets and conflicts of interest. Our controls over financial reporting include among others, controls over the segregation of corporate crypto 41 Table of Contents asset balances from customer crypto asset balances, controls over the processes of customer crypto asset deposits and customer crypto asset withdrawals and corporate and customer fiat balances. Our financial statements and disclosures, as a whole, are available through periodic filings on a quarterly basis, and compliant with annual audit requirements of Article 3 of Regulation S-X. We hold cash at financial institutions in accounts designated as for the benefit of our customers. We have also entered into partnerships or joint ventures with third parties, such as with Circle, where we or our partners receive and hold customer funds. Our and our financial partners’ abilities to manage and accurately hold customer cash and cash we hold for our own investment and operating purposes requires a high level of internal controls. We are limited in our ability to influence or manage the controls and processes of third-party partners or vendors and may be dependent on our partners’ and vendors’ operations, liquidity and financial condition to manage these risks. As we maintain, grow and expand our product and services offerings we also must scale and strengthen our internal controls and processes, and monitor our third-party partners’ and vendors’ ability to similarly scale and strengthen. Failure to do so could adversely affect our business, operating results, and financial condition. This is important both to the actual controls and processes and the public perception of the same. Any inability by us to maintain our procedures, perceived or otherwise, could harm our business, operating results, and financial condition. Accordingly, we take steps to ensure customer cash is always secure. Customer cash and crypto asset balances are maintained through our internal ledgering processes. Customer cash is maintained in segregated Company financial institution accounts that are held for the exclusive benefit of customers with our financial institution partners or in government money market funds or other permissible investments. We store crypto assets using proprietary technology and operational processes. Crypto assets are not insured or guaranteed by any government or government agency, however we have worked hard to securely store our customers’ crypto assets and our own crypto assets for investment and operational purposes with legal and operational protections. Any material failure by us or our partners to maintain the necessary controls, policies, procedures or to manage the crypto assets we hold for our own investment and operating purposes could also adversely affect our business, operating results, and financial condition. Further, any material failure by us or our partners to maintain the necessary controls or to manage customer crypto assets and funds appropriately and in compliance with applicable regulatory requirements could result in reputational harm, litigation, regulatory enforcement actions, significant financial losses, lead customers to discontinue or reduce their use of our and our partners’ products, and result in significant penalties and fines and additional restrictions, which could adversely affect our business, operating results, and financial condition. Moreover, because custodially held crypto assets may be considered to be the property of a bankruptcy estate, in the event of a bankruptcy, the crypto assets we hold in custody on behalf of our customers could be subject to bankruptcy proceedings and such customers could be treated as our general unsecured creditors. This may result in customers finding our custodial services more risky and less attractive and any failure to increase our customer base, discontinuation or reduction in use of our platform and products by existing customers as a result could adversely affect our business, operating results, and financial condition. Additionally, following the acquisition of CBAM, some of our asset management products hold customer assets at third-party custodians with their own bankruptcy protection procedures. We place great importance on securely storing crypto assets we custody and keeping them bankruptcy remote from our general creditors, and in June 2022 we updated our Retail User Agreement to clarify the applicability of Uniform Commercial Code (“UCC”) Article 8 to custodied crypto assets – the same legal protection that our institutional custody and prime broker clients also rely upon. UCC Article 8 provides that financial assets held by Coinbase are not property of Coinbase and not subject to the claims of its general creditors. In light of UCC Article 8, we believe that a court would not treat custodied crypto assets as part of our general estate; however, due to the novelty of crypto assets, courts have not yet considered this type of treatment for custodied crypto assets. Our MiCA-authorized entity in the E.U. securely stores client assets in dedicated, segregated custody vaults with separate books-and-records 42 Table of Contents from Coinbase’s own and other client funds, and uses tightly controlled settlement flows to preserve access to global liquidity and fast execution. We deposit, transfer, and custody customer cash and crypto assets in multiple jurisdictions. In each instance, we require bank-level security encryption to store customers’ assets for our wallet and storage systems, as well as our financial management systems related to such custodial functions. Our security technology is designed to prevent, detect, and mitigate inappropriate access to our systems, by internal or external threats. We believe we have developed and maintained administrative, technical, and physical measures designed to comply with applicable legal requirements and industry standards. However, it is nevertheless possible that hackers, employees or service providers acting contrary to our policies, or others could circumvent these measures to improperly access our systems or documents, or the systems or documents of our business partners, agents, or service providers, and improperly access, obtain, or misuse customer crypto assets and funds. The methods used to obtain unauthorized access, disable, or degrade service or sabotage systems are also constantly changing and evolving and may be difficult to anticipate or detect for long periods of time. Certain of our customer contracts do not limit our liability with respect to security breaches and other security-related matters and our insurance coverage for such impropriety is limited and may not cover the extent of loss nor the nature of such loss, in which case we may be liable for the full amount of losses suffered, which could be greater than all of our assets. Our ability to maintain insurance is also subject to the insurance carriers’ ongoing underwriting criteria. Any loss of customer cash or crypto assets could result in a subsequent lapse in insurance coverage, which could cause a substantial business disruption, adverse reputational impact, inability to compete with our competitors, and regulatory investigations, inquiries, or actions. Additionally, transactions undertaken through our websites or other electronic channels may create risks of fraud, hacking, unauthorized access or acquisition, and other deceptive practices. Any security incident resulting in a compromise of customer assets could result in substantial costs to us and require us to notify impacted individuals, and in some cases regulators, of a possible or actual incident, expose us to regulatory enforcement actions, including substantial fines, limit our ability to provide services, subject us to litigation, significant financial losses, damage our reputation, and adversely affect our business, operating results, financial condition, and cash flows. The theft, loss, or destruction of private keys required to access any crypto assets held in custody for our own account or for our customers may be irreversible. If we are unable to access our private keys or if we experience a hack or other data loss relating to our ability to access any crypto assets, it could cause regulatory scrutiny, reputational harm, and other losses. Crypto assets are generally controllable only by the possessor of the unique private key relating to the digital wallet in which the crypto assets are held. While blockchain protocols typically require public addresses to be published when used in a transaction, private keys must be secured and kept private in order to prevent a third party from accessing the crypto assets held in such a wallet. To the extent that any of the private keys relating to our wallets containing crypto assets held for our own account or for our customers is lost, destroyed, or otherwise compromised or unavailable, and no backup of the private key is accessible, we will be unable to access the crypto assets held in the related wallet. Further, we cannot provide assurance that our wallets will not be hacked or compromised. Crypto assets and blockchain technologies have been, and may in the future be, subject to security breaches, hacking, or other malicious activities. Any loss of private keys relating to, or hack or other compromise of, digital wallets used to store our customers’ crypto assets could adversely affect our customers’ ability to access or sell their crypto assets, require us to reimburse our customers for their losses, and subject us to significant financial losses in addition to losing customer trust in us and our products. As such, any loss of private keys due to a hack, employee or service provider misconduct or error, or other compromise by third parties could hurt our brand and reputation, result in significant losses, and adversely affect our business, operating results, and financial condition. To mitigate the risks associated with the loss or theft of keys, we utilize both hot wallets and cold wallets in our custodial solutions. We actively manage wallet balances and generally seek to hold no more than 2% of custodied assets in hot wallets at any given time. Cold wallet private key materials are 43 Table of Contents stored and secured at facilities within the United States and internationally. We store the substantial majority of our own crypto asset holdings utilizing the same storage solutions that we provide to our customers. In limited cases, we use storage solutions not offered to our customers to store immaterial amounts of crypto held for corporate purposes outside of our core custodial product offerings. Additionally, both Deribit and our CBAM offering utilize both Coinbase custody services and third parties as custodians. At all times, we hold corporate assets in excess of the total amount of assets held in our hot wallets. Similar to most financial institutions, the total customer assets on our platform, such as those assets held in cold storage, are substantially more than our corporate assets and available insurance. While we have for years maintained, and continue to maintain, a commercial crime insurance policy, which has a one-year term without automatic renewals, in the event of a loss from our cold wallets, our assets may be insufficient to cover amounts that exceed our insurance coverage. We may be liable for such uninsured losses where we are required to reimburse customers, and such liability could adversely affect our business, operating results, and financial condition. Other Risks Related to Our Business and Financial Position If we fail to retain existing customers or add new customers, or if our customers decrease their level of engagement with our products, services and platform, our business, operating results, and financial condition may be significantly harmed. Our success depends on our ability to retain existing customers and attract new customers, including developers, to increase engagement with our products, services, and platform. To do so, we must continue to offer leading technologies and ensure that our products and services are secure, reliable, and engaging. We must also expand our products and services, and offer competitive prices in an increasingly crowded and price-sensitive market. There is no assurance that we will be able to continue to do so, that we will be able to retain our current customers or attract new customers, or keep our customers engaged. Any number of factors can negatively affect customer retention, growth, and engagement, including if: • customers increasingly engage with competing products and services, including products and services that we are unable to offer due to regulatory reasons; • we fail to introduce new and improved products and services, or if we introduce new products or services that are not favorably received; • we fail to support new and in-demand crypto assets or if we elect to support crypto assets with negative reputations; • there are changes in sentiment about the quality or usefulness of our products and services or concerns related to privacy, security, fiat pegging or other factors; • there are adverse changes in our products and services that are mandated by legislation, regulatory authorities, or litigation; • customers perceive the crypto assets on our platform to be bad investments, or experience significant losses in investments made on our platform; • technical or other problems prevent us from delivering our products and services with the speed, functionality, security, and reliability that our customers expect; • cybersecurity incidents, employee or service provider misconduct, or other unforeseen activities cause losses to us or our customers, including losses to assets held by us on behalf of our customers; • modifications to our pricing model or modifications by competitors to their pricing models; • we fail to provide adequate customer service; 44 Table of Contents • regulatory and governmental bodies in countries that we target for expansion express negative views towards crypto asset trading platforms and, more broadly, our industry; or • we or other companies or high-profile figures in our industry are the subject of adverse media reports or other negative publicity. From time to time, certain of these factors have negatively affected customer retention, growth, and engagement to varying degrees. If we are unable to maintain or increase our customer base and customer engagement, our revenue and financial results may be adversely affected. Any decrease in user retention, growth, or engagement could render our products and services less attractive to customers and lead to a decrease in revenue, and our business, operating results, and financial condition could be adversely affected. If our customer growth rate slows or declines, we will become increasingly dependent on our ability to maintain or increase levels of user engagement and monetization in order to drive growth of revenue. Our operating expenses may increase in the future and we may not be successful in increasing our revenue to sufficiently offset these higher expenses, which could impact our ability to achieve profitability or positive cash flow from operations on a consistent basis and cause our business, operating results, and financial condition to be adversely affected. Our operating expenses may increase in the future as we continue to grow our business. While we consistently evaluate opportunities to drive efficiency, we cannot guarantee that these efforts will be successful or that we will not need to increase operating expenditures in the future. Our operations may prove more expensive than we currently anticipate, and we may not succeed in increasing our net revenue sufficiently to offset these higher expenses. Additionally, our revenue growth may be negatively impacted by, among other things, reduced demand for our offerings, increased competition, adverse macroeconomic conditions, any decrease in the growth or size of our industry, regulatory uncertainty or scrutiny, changes that impact our ability to offer certain products or services, or failure of new products and services to gain market adoption. As a result, we cannot be certain that we will be able to achieve profitability or achieve positive operating cash flow on any quarterly or annual basis. If we are unable to effectively manage these risks and difficulties as we encounter them, our business, operating results, and financial condition may suffer. If we do not effectively manage our growth, including through acquisitions and by maintaining and improving our systems and processes, our business, operating results, and financial condition could be adversely affected. We have experienced, and may experience in the future, periods of significant growth. To effectively manage and capitalize on our growth periods, we will need to manage headcount, capital, and processes efficiently while making investments such as expanding our information technology and financial, operating, and administrative systems and controls, and such initiatives could strain our resources. We could experience operating difficulties in managing our business as it expands across numerous jurisdictions, including difficulties in hiring, training, managing and retaining a remote and evolving employee base, as well as challenges integrating acquired businesses, technologies, and personnel. If we do not adapt or scale to meet these evolving challenges, or if we fail to successfully integrate acquisitions, we may experience erosion to our brand, the quality of our products and services may suffer, and our company culture may be harmed. Moreover, the failure of our systems and processes could undermine our ability to provide accurate, timely, and reliable reports on our financial and operating results, including the financial statements provided herein, and could impact the effectiveness of our internal controls over financial reporting. In addition, our systems and processes may not prevent or detect all errors, omissions, or fraud. Any of the foregoing operational failures could lead to noncompliance with laws and regulations, loss of operating licenses or other authorizations, or loss of financial institution relationships that could substantially impair or even suspend company operations. Successful implementation of our growth strategy will also require significant expenditures before any substantial associated revenue is generated and we cannot guarantee that these increased investments 45 Table of Contents will result in corresponding and offsetting revenue growth. For example, we may pay substantial premiums for acquired businesses and there can be no assurance that anticipated synergies or benefits will be realized on the timeline expected, or at all. Because we have a limited history operating our business at its current scale, it is difficult to evaluate our current business and future prospects, including our ability to plan for and model future growth. Our limited operating experience at this scale, combined with the rapidly evolving and volatile nature of the crypto asset market in which we operate, and other economic factors beyond our control, reduces our ability to accurately forecast quarterly or annual revenue. Additionally, from time to time, we have realigned our resources and talent to meet evolving business needs. This has previously included layoffs and workforce reductions aimed at cutting costs, improving efficiency, and responding to economic shifts. If there are unforeseen expenses associated with such realignments in our business strategies, and we incur unanticipated charges or liabilities, then we may not be able to effectively realize the expected cost savings or other benefits of such actions. Failure to manage any growth or any scaling back of our operations could have an adverse effect on our business, operating results, and financial condition. Our strategy and focus on delivering high-quality, compliant, easy-to-use, and secure crypto-related financial services may not maximize short-term or medium-term financial results. We have taken, and expect to continue to take, actions that we believe are in the best interests of our customers and the long-term interests of our business, even if those actions do not necessarily maximize short-term or medium-term results. These include expending significant managerial, technical, and legal efforts on complying with laws and regulations that are applicable to our products and services and ensuring that our products are secure. We also focus on driving long-term engagement with our customers through innovation and developing new industry-leading products and technologies. These decisions may not be consistent with the short-term and medium-term expectations of our shareholders and may not produce the long-term benefits that we expect, which could have an adverse effect on our business, operating results, and financial condition. Laws and regulations regarding conflicts of interest associated with the use of predictive data analytics, digital engagement practices, and similar technologies, if adopted and found to be applicable to our business, may require us to modify, limit, or discontinue our use of certain technologies and features contained within our products and services and may impact the way that we interact with existing and prospective customers, which could adversely affect our business, operating results, and financial condition. Our products, services and educational offerings incorporate a holistic, customer-centric set of digital engagement practices, including educational content and notifications, which are designed, in part, to promote financial literacy and awareness and to provide customers with guidance and information to help them make better informed decisions about their crypto activity. Certain jurisdictions have proposed or are considering laws and regulations regarding conflicts of interest associated with the use of predictive data analytics, digital engagement practices, and similar technologies by broker-dealers, investment advisers and/or other securities market participants. If adopted and found to apply to our business, such laws or regulations may impose obligations on us that may require us to modify, limit, or discontinue our use of certain technologies and features used in connection with our products and services and/or to change the way that we interact with existing and prospective customers, which could adversely affect our business, operating results, and financial condition. Because our long-term success depends, in part, on our ability to expand our sales to customers outside the United States, our business is susceptible to risks associated with international operations. We currently have subsidiaries in the United States and abroad. We plan to enter into or increase our presence in additional markets around the world. We have a limited operating history outside the United 46 Table of Contents States, and our ability to manage our business and conduct our operations internationally requires considerable management attention and resources and is subject to particular challenges of supporting a growing business in an environment of diverse cultures, languages, customs, tax laws, legal systems, alternate dispute systems, and regulatory systems. As we continue to expand our business and customer base outside the United States, we will be increasingly susceptible to risks associated with international operations. These risks and challenges include: • difficulty establishing and managing international operations and the increased operations, travel, infrastructure, including establishment of local customer service operations, local infrastructure to manage supported cryptocurrency or other financial instruments and corresponding books and records, and legal and regulatory compliance costs associated with different jurisdictions; • the need to vary pricing and margins to effectively compete in international markets; • the need to adapt and localize our products and services for specific countries, including offering services and support in local languages; • compliance with multiple, potentially conflicting and changing governmental laws and regulations across different jurisdictions; • compliance with U.S. and foreign laws designed to combat money laundering and the financing of terrorist activities, as well as economic and trade sanctions; • the need to comply with a greater set of law enforcement inquiries including those subject to mutual legal assistance treaties; • compliance with the extraterritorial reach of any U.S. regulatory rules, including those imposed by the CFTC, SEC, FinCEN or other U.S. based regulators; • difficulties obtaining and maintaining required licensing from regulators in foreign jurisdictions; • competition with companies that have greater experience in the local markets, pre-existing relationships with customers in these markets or are subject to less regulatory requirements in local jurisdictions; • varying levels of payments and blockchain technology adoption and infrastructure, and increased network, payment processing, banking, and other costs; • compliance with anti-bribery laws, including compliance with the Foreign Corrupt Practices Act, the U.K. Bribery Act 2010, and other local anticorruption laws; • difficulties collecting in foreign currencies and associated foreign currency exposure; • difficulties holding, repatriating, and transferring funds held in offshore bank accounts; • difficulties adapting to foreign customary commercial practices, enforcing contracts and collecting accounts receivable, longer payment cycles and other collection difficulties; • restrictions on crypto asset trading; • stringent local labor laws and regulations; • potentially adverse tax developments and consequences; • antitrust and competition regulations; and • regional economic and political conditions. We may not be able to penetrate or successfully operate in the markets we choose to enter. In addition, we may incur significant expenses as a result of our international expansion, and we may not be successful. We may face limited brand recognition in certain parts of the world that could lead to non-acceptance or delayed acceptance of our products and services by customers in new markets. We may also face challenges in complying with local laws and regulations. For example, we may be subject to 47 Table of Contents regulatory frameworks that are evolving, have not undergone extensive rulemaking, and could result in uncertain outcomes for our customers and/or our ability to offer competitive products in the broader onchain economy. Our failure to successfully manage these risks could harm our international operations and have an adverse effect on our business, operating results, and financial condition. Disputes with our customers could adversely affect our brand, reputation, business, operating results, and financial condition. From time to time we have been, and may in the future be, subject to claims and disputes with our customers with respect to our products and services, such as regarding the execution and settlement of crypto asset trades, fraudulent or unauthorized transactions, account takeovers, deposits and withdrawals of crypto assets, failures or malfunctions of our systems and services, or other issues relating to our products and services. For example, during periods of heavy Trading Volumes, we have received increased customer complaints. Additionally, the ingenuity of criminal fraudsters, combined with many consumer users’ susceptibility to fraud, may cause our customers to be subject to ongoing account takeovers and identity fraud issues. While we have taken measures to detect and reduce the risk of fraud, there is no guarantee that they will be successful and, in any case, require continuous improvement and optimization for continually evolving forms of fraud to be effective. There can be no guarantee that we will be successful in detecting and resolving these disputes or defending ourselves in any of these matters, and any failure may result in impaired relationships with our customers, damage to our brand and reputation, and substantial fines and damages. In some cases, the measures we have implemented to detect and deter fraud have led to poor customer experiences, including indefinite account inaccessibility for some of our customers, which increases our customer support costs and can compound damages. We could incur significant costs in compensating our customers, such as if a transaction was unauthorized, erroneous, or fraudulent. We could also incur significant legal expenses resolving and defending claims, even those without merit. To the extent we are found to have failed to fulfill our regulatory obligations, we could also lose our authorizations or licenses or become subject to conditions that could make future operations more costly, impair our ability to grow, and adversely affect our business, operating results, and financial condition. We currently are, or may in the future become, subject to investigation and enforcement action by state, federal, and international consumer protection agencies, including the Consumer Financial Protection Bureau, the Federal Trade Commission (the “FTC”), state agencies and attorneys general in the United States, the U.K. Financial Conduct Authority, the U.K. Financial Ombudsman Service, and the U.K. Office of Fair Trading, each of which monitors customer complaints against us and, from time to time, escalates matters for investigation and potential enforcement against us. While certain of our customer agreements contain arbitration provisions with class action waiver provisions that may limit our exposure to consumer class action litigation, some federal, state, and foreign courts have refused or may refuse to enforce one or more of these provisions, and there can be no assurance that we will be successful in enforcing these arbitration provisions, including the class action waiver provisions, in the future or in any given case. Legislative, administrative, or regulatory developments may directly or indirectly prohibit or limit the use of pre-dispute arbitration clauses and class action waiver provisions. Any such prohibitions or limitations on or discontinuation of the use of such arbitration or class action waiver provisions could subject us to additional lawsuits, including additional consumer class action litigation, and significantly limit our ability to avoid exposure from consumer class action litigation. We may suffer losses due to staking, delegating, and other related services we provide to our customers. Certain supported crypto assets enable holders to earn rewards by participating in decentralized governance, bookkeeping and transaction confirmation activities on their underlying blockchain networks, such as through staking activities, including staking through validation, delegating, and baking. We currently provide and expect to continue to provide such services for certain supported crypto assets to our customers in order to enable them to earn rewards based on crypto assets that we hold on their 48 Table of Contents behalf. For instance, as a service to customers and at their instruction, we operate staking nodes on certain blockchain networks utilizing customers’ crypto assets and pass through the rewards received to those customers, less a service fee. In other cases, upon customers’ instructions, we may delegate our customers’ assets to third-party service providers that are unaffiliated with us. Some networks may further require customer assets to be transferred into smart contracts on the underlying blockchain networks not under our or anyone’s control. If our validator, any third-party service providers, or smart contracts fail to behave as expected, suffer cybersecurity attacks, experience security issues, or encounter other problems, our customers’ assets may be irretrievably lost. In addition, certain blockchain networks dictate requirements for participation in the relevant decentralized governance activity, and may impose penalties, or “slashing,” if the relevant activities are not performed correctly, such as if the staker, delegator, or baker acts maliciously on the network, “double signs” any transactions, or experience extended downtimes. If we or any of our service providers are slashed by the underlying blockchain network, our customers’ assets may be confiscated, withdrawn, or burnt by the network, resulting in losses for which we may be responsible. Furthermore, certain types of staking require the payment of transaction fees on the underlying blockchain network and such fees can become significant as the amount and complexity of the transaction grows, depending on the degree of network congestion and the price of the network token. If we experience a high volume of such staking requests from our customers on an ongoing basis, we could incur significant costs. Any penalties or slashing events could damage our brand and reputation, cause us to suffer financial losses, discourage existing and future customers from utilizing our products and services, and adversely affect our business, operating results, and financial condition. We may not be able to generate sufficient cash to service our debt and other obligations, including our obligations under the 2026 Convertible Notes, 2029 Convertible Notes, 2030 Convertible Notes, 2032 Convertible Notes, and Senior Notes. Our ability to make payments on our indebtedness, including the 2026 Convertible Notes, 2029 Convertible Notes, 2030 Convertible Notes, 2032 Convertible Notes, and Senior Notes, and our other obligations will depend on our financial and operating performance, which is subject to prevailing economic and competitive conditions and to certain financial, business and other factors beyond our control. We may be unable to attain a level of cash flows from operating activities sufficient to permit us to pay the principal, premium, if any, and interest on our indebtedness, including each series of the 2026 Convertible Notes, 2029 Convertible Notes, 2030 Convertible Notes, 2032 Convertible Notes, and Senior Notes, and other obligations. If we are unable to service our debt and other obligations from cash flows, we may need to refinance or restructure all or a portion of our debt obligations prior to maturity. Our ability to refinance or restructure our debt and other obligations will depend upon the condition of the capital markets and our financial condition at such time. Any refinancing or restructuring could be at higher interest rates and may require us to comply with more onerous covenants, which could further restrict our business operations. Statutory, contractual or other restrictions may also limit our subsidiaries’ ability to pay dividends or make distributions, loans or advances to us. For these reasons, we may not have access to any assets or cash flows of our subsidiaries to make interest and principal payments on each series of the 2026 Convertible Notes, 2029 Convertible Notes, 2030 Convertible Notes, 2032 Convertible Notes, and Senior Notes. If our cash flows are insufficient to fund our debt and other obligations and we are unable to refinance or restructure these obligations on commercially reasonable terms or at all, we could face substantial liquidity problems and may be forced to reduce or delay investments and capital expenditures, or to sell material assets or operations to meet our debt and other obligations. We cannot assure you that we would be able to implement any of these alternative measures on satisfactory terms or at all or that the proceeds from such alternatives would be adequate to meet any debt or other obligations when due. If it becomes necessary to implement any of these alternative measures, our business, operating results, and financial condition could be adversely affected. 49 Table of Contents We have a substantial amount of indebtedness and other obligations, which could adversely affect our financial position and prevent us from fulfilling our obligations under the 2026 Convertible Notes, 2029 Convertible Notes, 2030 Convertible Notes, 2032 Convertible Notes, and Senior Notes. We have a substantial amount of indebtedness and other obligations. As of December 31, 2025, we had approximately $7.28 billion in aggregate principal amount of outstanding long-term indebtedness (excluding crypto asset borrowings), which includes $1.74 billion of our Senior Notes, $1.27 billion of our 2026 Convertible Notes, $1.50 billion of our 2029 Convertible Notes, $1.27 billion of our 2030 Convertible Notes, and $1.50 billion of our 2032 Convertible Notes. Our substantial indebtedness and other obligations may: • make it difficult for us to satisfy our financial obligations, including making scheduled principal and interest payments on our 2026 Convertible Notes, 2029 Convertible Notes, 2030 Convertible Notes, 2032, Convertible Notes, Senior Notes, and our other obligations; • limit our ability to use our cash flow for working capital, capital expenditures, acquisitions, or other general business purposes; • increase our cost of borrowing; • require us to use a substantial portion of our cash flow from operations to make debt service payments and pay our other obligations when due; • limit our flexibility to plan for, or react to, changes in our business and industry; • place us at a competitive disadvantage compared to our less leveraged competitors; and • increase our vulnerability to the impact of adverse economic and industry conditions, including changes in interest rates and foreign exchange rates. We provide secured loans to our customers, which exposes us to credit risks and may cause us to incur financial or reputational harm. We provide commercial loans to qualified customers secured by their fiat or crypto asset holdings, including USDC, on our platform, which exposes us to the risk of our borrowers’ inability to repay such loans. In addition, such activity results in us being subject to certain lending laws and regulations in the applicable jurisdiction and as a result we may be subject to additional regulatory scrutiny. In the future we may enter into credit arrangements with financial institutions to obtain more capital. Any termination or interruption in the financial institutions’ ability to lend to us could interrupt our ability to provide capital to qualified customers to the extent we rely on such credit lines to continue to offer or to grow such products. Further, our credit approval process, pricing, loss forecasting, and scoring models may contain errors or may not adequately assess creditworthiness of our borrowers, or may be otherwise ineffective, resulting in incorrect approvals or denials of loans. It is also possible that loan applicants could provide false or incorrect information. While we have procedures in place to manage our credit risk, such as conducting due diligence on our customers and running stress test simulations to monitor and manage exposures, including any exposures resulting from loans collateralized with crypto assets, we remain subject to risks associated with our borrowers’ creditworthiness and our approval process. Borrower loan loss rates may be significantly affected by economic downturns or general economic conditions beyond our control and beyond the control of individual borrowers. In particular, loss rates on loans may increase due to factors such as prevailing market conditions in our industry, the price of Bitcoin and other crypto assets, which have experienced significant fluctuations, the amount of liquidity in the markets, and other factors. Borrowers may seek protection under federal bankruptcy law or similar laws. If a borrower of a loan files for bankruptcy (or becomes the subject of an involuntary petition), a stay may go into effect that will automatically put any pending collection actions on the loan on hold and prevent further collection action absent bankruptcy court approval. The efficacy of our security interest in customer 50 Table of Contents collateral is not guaranteed under applicable state law or the Uniform Commercial Code and therefore we may be exposed to loss in the event of a customer default, even if we appear to be secured against such default. While we have not incurred any material losses to date, if any of the foregoing events were to occur, our reputation and relationships with borrowers, and our financial results, could be harmed. We intend to continue to explore other products, models, and structures for offering commercial financing, and other forms of credit and loan products. Some of those models or structures may require, or be deemed to require, additional data, procedures, partnerships, licenses, regulatory approvals, or capabilities that we have not yet obtained or developed. We are exposed to transaction losses due to chargebacks, refunds, or returns as a result of fraud or uncollectability that could adversely affect our business, operating results, and financial condition. Certain of our products and services are paid for by electronic transfers from bank accounts, which exposes us to risks associated with returns and insufficient funds. Furthermore, some of our products and services are paid for by credit and debit cards through payment processors, which exposes us to risks associated with chargebacks and refunds. These risks could arise from fraud, misuse, unintentional use, settlement delay, insufficiency of funds, or other activities. Also, criminals are using increasingly sophisticated methods to engage in illegal activities, such as counterfeiting and fraud. If we are unable to collect such amounts from the customer, or if the customer refuses or is unable, due to bankruptcy or other reasons, to reimburse us, we bear the loss for the amount of the chargeback, refund, or return. While we have policies and procedures to manage and mitigate these risks, we cannot be certain that such processes will be effective. Our failure to limit chargebacks and fraudulent transactions could increase the number of returns, refunds, and chargebacks that we have to process. In addition, if the number of returns, refunds, and chargebacks increases, card networks or our financial institution partners could require us to increase reserves, impose penalties on us, charge additional or higher fees, or terminate their relationships with us. Failure to effectively manage risk and prevent fraud could increase our chargeback, refund, and return losses or cause us to incur other liabilities. Increases in chargebacks, refunds, returns, or other liabilities could have an adverse effect on our operating results, financial condition, and cash flows. We route orders through third-party trading venues in connection with our Coinbase Prime trading service. The loss or failure of any such trading venues could adversely affect our business, operating results, and financial condition. In connection with our Prime trading service, we routinely route customer orders to third-party exchanges or other trading venues. In connection with these activities, we generally hold cash and other crypto assets with such third-party exchanges or other trading venues in order to effect customer orders. If we were to experience a disruption in our access to these third-party exchanges and trading venues, our Prime trading service could be adversely affected to the extent that we are limited in our ability to execute order flow for our Prime customers. In addition, while we have policies and procedures to help mitigate our risks related to routing orders through third-party trading venues, if any of these third-party trading venues experience any technical, legal, regulatory, or other adverse events, such as shutdowns, delays, system failures, suspension of withdrawals, illiquidity, insolvency, or loss of customer assets, we might not be able to fully recover the cash and other crypto assets that we have deposited with these third parties. As a result, our business, operating results, and financial condition could be adversely affected. Any acquisitions and investments that we make could require significant management attention, disrupt our business, result in dilution to our shareholders, and could adversely affect our business, operating results, and financial condition. As part of our business strategy, we routinely conduct discussions and evaluate opportunities for possible acquisitions, strategic investments, entries into new businesses, joint ventures, and other transactions. We have made, and may continue to make, acquisitions of and investments in, among other 51 Table of Contents things, specialized employees and complementary companies, products, services, licenses, or technologies. For example, as a result of our acquisition of Deribit in August 2025, we now provide additional cryptocurrency products and services internationally, including options and perpetual swaps. If we are unable to successfully integrate Deribit or comply with evolving U.S. and international crypto and derivatives regulations applicable to our expanded operations and products, we could be required to modify or discontinue certain offerings, face limitations on our ability to onboard or serve customers in key markets, incur substantial compliance and remediation costs, or be subject to penalties and other enforcement actions, any of which could adversely affect our business, operating results, and financial condition. In the future, the pace and scale of our acquisitions may increase and may include larger acquisitions than we have done historically. We also invest in companies and technologies, many of which are private companies and technologies that are highly speculative in nature. In the future, we may not be able to find other suitable acquisition and investment candidates, and we may not be able to complete acquisitions or make investments on favorable terms, if at all. In some cases, the costs of such acquisitions and investments may be substantial, and there is no assurance that we will receive a favorable return on investment for our acquisitions and investments. We have and may in the future be required to write off acquisitions or investments. Moreover, our previous and future acquisitions and investments may not achieve our goals, and any future acquisitions and investments we complete could be viewed negatively by customers, developers, advertisers, or investors. In addition, if we fail to successfully close or integrate any acquisitions, or integrate the products or technologies associated with such acquisitions into our company, our business, operating results, and financial condition could be adversely affected. Our ability to acquire and integrate companies, products, services, licenses, employees, or technologies in a successful manner is unproven. Any integration process may require significant time and resources, and we may not be able to manage the process successfully, including successfully securing regulatory approvals which may be required to close the transaction and to continue to operate the target firm’s business or products in a manner that is useful to us. We may not successfully evaluate or utilize the acquired products, services, technology, or personnel, or accurately forecast the financial impact of an acquisition transaction, including accounting charges. We may have to pay cash, incur debt, or issue equity securities to pay for any such acquisition, which could adversely affect our business, operating results, and financial condition. The sale of equity or issuance of debt to finance any such acquisitions could result in dilution to our shareholders, which, depending on the size of the acquisition, may be significant. The incurrence of indebtedness would result in increased fixed obligations and could also include covenants or other restrictions that would impede our ability to manage our operations. If we fail to develop, maintain, and enhance our brand and reputation, our business, operating results, and financial condition could be adversely affected. Our brand and reputation are key assets and a competitive advantage. Maintaining, protecting, and enhancing our brand depends largely on the success of our marketing efforts, ability to provide consistent, high-quality, and secure products, services, features, and support, and our ability to successfully secure, maintain, and defend our rights to use the “Coinbase” mark and other trademarks important to our brand. We believe that the importance of our brand will increase as competition further intensifies. Our brand and reputation could be harmed if we fail to achieve these objectives or if our public image were to be tarnished by negative publicity, unexpected events, or actions by third parties. Unfavorable publicity regarding, for example, our product changes, product quality, litigation or regulatory activity, privacy and data security practices, terms of service, employment matters, the use of our products, services, or supported crypto assets for illicit or objectionable ends, the actions of our customers, or the actions of other companies that provide similar services to ours, has in the past, and could in the future, adversely affect our reputation. Moreover, to the extent that we acquire a company and maintain that acquired company’s separate brand, we could experience brand dilution or fail to retain positive impressions of our own brand to the extent such impressions are instead attributed to the acquired company’s brand. In addition, because we are a founder-led company, actions by, or 52 Table of Contents unfavorable publicity about, Brian Armstrong, our co-founder and Chief Executive Officer, may adversely impact our brand and reputation. Such negative publicity also could have an adverse effect on the size and engagement of our customers and could result in decreased revenue, which could adversely affect our business, operating results, and financial condition. Key business metrics and other estimates are subject to inherent challenges in measurement and change as our business evolves, and our business, operating results, and financial condition could be adversely affected by real or perceived inaccuracies in those metrics or any changes in metrics we disclose. We regularly review our key business metrics to evaluate our business, measure our performance, identify trends affecting our business, and make strategic decisions. These key business metrics are calculated using internal company data and have not been validated by an independent third-party. While these numbers are based on what we believe to be reasonable estimates for the applicable period of measurement at the time of reporting, there are inherent challenges in such measurements. If we fail to maintain an effective analytics platform, our key business metrics calculations may be inaccurate, and we may not be able to identify those inaccuracies. Additionally, we may in the future calculate certain key business metrics using third-party data. While we believe the third-party data we have used in the past or may use in the future is reliable, we have not independently verified and may not in the future independently verify the accuracy or completeness of the data contained in such sources and there can be no assurance that such data is free of error. Any inaccuracy in the third-party data we use could cause us to overstate or understate our key business metrics. We regularly review our processes for calculating these metrics, and from time to time we make adjustments to improve their accuracy. Additionally, our MTUs metric is measured at a point in time and as our products and internal processes for calculating these metrics evolve over time, a previously reported number could fluctuate. We generally will not update previously disclosed key business metrics for any such inaccuracies or adjustments that are immaterial. Our key business metrics may also be impacted by compliance or fraud-related bans, technical incidents, or false or spam accounts in existence on our platform. We regularly deactivate fraudulent and spam accounts that violate our terms of service, and exclude these users from the calculation of our key business metrics; however, we may not succeed in identifying and removing all such accounts from our platform. Additionally, users are not prohibited from having more than one account and our MTUs metric may overstate the number of unique customers who have registered an account on our platform as one customer may register for, and use, multiple accounts with different email addresses, phone numbers, or usernames. Furthermore, MTUs may overstate the number of unique consumers due to differences in product architecture or user behavior, which may cause MTUs to fluctuate. For example, a user may currently have an account on the Base App (formerly Coinbase Wallet) that is unlinked to their registered account on our platform, but then choose to link these accounts in the future as our product offerings evolve. To the extent that the user had activity in both their Wallet and their registered account in the measurement period, what was previously captured as two unique MTUs would now be counted as a single MTU. If MTUs or our other key business metrics provide us with incorrect or incomplete information about users and their behavior, we may make inaccurate conclusions about our business. We may change our key business metrics from time to time, which may be perceived negatively. Given the rapid evolution of the crypto markets and our revenue sources, we regularly evaluate whether our key business metrics remain meaningful indicators of the performance of our business. As a result of these evaluations, in the past we have decided to make changes, and in the future may make additional changes, to our key business metrics, including adding, eliminating, or replacing existing metrics. Further, if investors or the media perceive any changes to our key business metrics disclosures negatively, our business, operating results, and financial condition could be adversely affected. 53 Table of Contents Our platform may be exploited to facilitate illegal activity such as fraud, money laundering, gambling, tax evasion, and scams. If our platform is used to further such illegal activities, our business, operating results, and financial condition could be adversely affected. Our platform may be exploited to facilitate illegal activity such as fraud, money laundering, gambling, tax evasion, sanctions evasion, and scams. We or our partners may be specifically targeted by individuals seeking to conduct fraudulent or otherwise illicit transfers, and it may be difficult or impossible for us to detect and avoid such transactions in certain circumstances. The use of our platform for illegal or improper purposes could subject us to claims, individual and class action lawsuits, and government and regulatory investigations, prosecutions, enforcement actions, inquiries, or requests that could result in liability and reputational harm for us. Moreover, certain activities that may be legal in one jurisdiction may be illegal in another jurisdiction, and certain activities that are at one time legal may in the future be deemed illegal in the same jurisdiction. As a result, there is significant uncertainty and cost associated with detecting and monitoring transactions for compliance with local laws. In the event that a customer is found responsible for intentionally or inadvertently violating the laws in any jurisdiction, we may be subject to governmental inquiries, enforcement actions, prosecuted, or otherwise held secondarily liable for aiding or facilitating such activities. Changes in law have also increased the penalties for money transmitters for certain illegal activities, and government authorities may consider increased or additional penalties from time to time. Owners of intellectual property rights or government authorities may seek to bring legal action against money transmitters, including us, for involvement in the sale of infringing or allegedly infringing items. Any threatened or resulting claims could result in reputational harm, and any resulting liabilities, loss of transaction volume, or increased costs could harm our business. Moreover, while fiat currencies can be used to facilitate illegal activities, crypto assets are relatively new and, in many jurisdictions, may be lightly regulated or largely unregulated. Many types of crypto assets have characteristics, such as the speed with which digital currency transactions can be conducted, the ability to conduct transactions without the involvement of regulated intermediaries, the ability to engage in transactions across multiple jurisdictions, the irreversible nature of certain crypto asset transactions, and encryption technology that anonymizes these transactions, that make crypto assets susceptible to use in illegal activity. U.S. federal regulatory authorities and law enforcement agencies, such as the Department of Justice, the Department of the Treasury, SEC, CFTC, FTC, FinCEN or the Internal Revenue Service (“IRS”), various state securities and financial regulators, such as the NYDFS, and similar foreign regulatory authorities, have taken and continue to take legal actions against persons and entities alleged to be engaged in fraudulent schemes or other illicit activity involving crypto assets. We also support crypto assets that incorporate privacy-enhancing features, and may from time to time support additional crypto assets with similar functionalities. These privacy-enhancing crypto assets obscure the identities of sender and receiver, and may prevent law enforcement officials from tracing the source of funds on the blockchain. Facilitating transactions in these crypto assets may cause us to be at increased risk of liability arising out of anti-money laundering and economic sanctions laws and regulations. While we believe that our risk management and compliance framework is designed to detect significant illicit activities conducted by our potential or existing customers, we cannot ensure that we will be able to detect all illegal activity on our platform. Base Chain (formerly Base), an open source permissionless L2 protocol built on the Ethereum blockchain developed by us, has been in the past, and may in the future, be a target for scam tokens or other illegal activity. For example, in August 2023, a number of fraudulent tokens were identified and traded on Base Chain blockchain. As we continue to develop Base Chain, and in light of this fraudulent activity, we continue to invest in improving our security processes, including through our in-house blockchain monitoring capabilities, third-party tools for identifying malicious and out of pattern events, and the monitoring of contract source code and bytecode on Base Chain against a database of known scam code patterns. While to date, such illegal or fraudulent activity on Base Chain has not had a material impact on our business, operating results, financial condition, or cash flows, future illegal activity could adversely affect our business, operating results, financial condition or cash flows and our efforts to identify and remedy such illegal or fraudulent activity 54 Table of Contents may not be successful. If our platform is used to further such illegal activities, our business, operating results, and financial condition could be adversely affected. Our compliance and risk management methods might not be effective and may result in outcomes that could adversely affect our reputation, operating results, and financial condition. Our ability to comply with applicable complex and evolving laws, regulations, and rules is largely dependent on the establishment, maintenance, and scaling of our compliance, internal audit, and reporting systems to continuously keep pace with our customer activity and transaction volume, as well as our ability to attract and retain qualified compliance and other risk management personnel. While we have devoted significant resources to develop policies and procedures to identify, monitor, and manage our risks, and expect to continue to do so in the future, we cannot assure you that our policies and procedures are and will always be effective or that we have been and will always be successful in monitoring or evaluating the risks to which we are or may be exposed in all market environments or against all types of risks, including unidentified or unanticipated risks. Our risk management policies and procedures rely on a combination of technical and human controls and supervision that are subject to error and failure. Some of our methods for managing risk are discretionary by nature and are based on internally developed controls and observed historical market behavior, and also involve reliance on standard industry practices. These methods may not adequately prevent losses, particularly as they relate to extreme market movements, which may be significantly greater than historical fluctuations in the market. Further, market disruptions in the future may cause us to reevaluate our risk management policies and procedures. Accordingly, in the future, we may identify gaps in such policies and procedures or existing gaps may become higher risk, and may require significant resources and management attention. Our risk management policies and procedures also may not adequately prevent losses due to technical errors if our testing and quality control practices are not effective in preventing failures. In addition, we may elect to adjust our risk management policies and procedures to allow for an increase in risk tolerance, which could expose us to the risk of greater losses. Regulators periodically review our compliance with our own policies and procedures and with a variety of laws and regulations. We have received in the past and may from time to time receive additional examination reports citing violations of rules and regulations and inadequacies in existing compliance programs, and requiring us to enhance certain practices with respect to our compliance program, including due diligence, training, monitoring, reporting, and recordkeeping. If we fail to comply with these, or do not adequately remediate certain findings, regulators could take a variety of actions that could impair our ability to conduct our business, including, but not limited to, delaying, denying, withdrawing, or conditioning approval of certain products and services. In addition, regulators have broad enforcement powers to censure, fine, issue cease and desist orders, prohibit us from engaging in some of our business activities, or revoke our licenses. We face significant intervention by regulatory authorities, including extensive examination and surveillance activities, and will continue to face the risk of significant intervention by regulatory authorities in the future. In the case of non-compliance or alleged non-compliance, we could be subject to investigations and proceedings that may result in substantial penalties or civil lawsuits, including by customers, for damages which can be significant. Any of these outcomes would adversely affect our reputation and brand and our business, operating results, and financial condition. Some of these outcomes could adversely affect our ability to conduct our business. We hold certain investments in DeFi protocols and may suffer losses if they do not function as expected. We hold investments in various DeFi protocols. These protocols achieve their investment purposes through self-executing smart contracts that allow users to invest crypto assets in a pool from which other users can borrow without requiring an intermediate party to facilitate these transactions. These investments earn interest to the investor based on the rates at which borrowers repay the loan, and can generally be withdrawn with no restrictions. However, these DeFi protocols are subject to various risks, including uncertain regulatory and compliance conditions in large markets such as the United States, the risk that the underlying smart contract is insecure, the risk that borrowers may default and the investor will 55 Table of Contents not be able to recover its investment, the risk that any underlying collateral may experience significant volatility, and the risk of certain core developers with protocol administration rights can make unauthorized or harmful changes to the underlying smart contract. If any of these risks materialize, our investments in these DeFi protocols may be adversely impacted. We may suffer losses due to abrupt and erratic market movements. The crypto asset market has been characterized by significant volatility and unexpected price movements, and has experienced significant declines in the past. Certain crypto assets may become more volatile and less liquid in a very short period of time, resulting in market prices being subject to erratic and abrupt market movement, which could harm our business. For instance, abrupt changes in volatility or market movement can lead to extreme pressures on our platform and infrastructure that can lead to inadvertent suspension of services across parts of the platform or the entire platform. As a result, from time to time we experience outages. For example, in 2025, we experienced approximately 10 outages, with an average outage duration of 74.2 minutes. Outages can lead to increased customer service expense, can cause customer loss and reputational damage, result in inquiries and actions by regulators, and can lead to other damages for which we may be responsible. Risks Related to Crypto Assets Due to unfamiliarity and some negative publicity associated with crypto asset platforms, confidence or interest in crypto asset platforms may decline. Crypto asset platforms are relatively new. Many of our competitors are unlicensed, unregulated, operate without supervision by any governmental authorities, and do not provide the public with significant information regarding their ownership structure, management team, corporate practices, cybersecurity, and regulatory compliance. As a result, customers and the general public may lose confidence or interest in crypto asset platforms, including regulated platforms like ours. Since the inception of our industry, numerous crypto asset platforms have been sued, investigated, or shut down due to fraud, manipulative practices, business failure, and security breaches. In many of these instances, customers of these platforms were not compensated or made whole for their losses. Larger platforms like us are more appealing targets for hackers and malware, and may also be more likely to be targets of regulatory enforcement actions. For example, in February 2014, Mt. Gox, the then largest crypto asset platform worldwide, filed for bankruptcy protection in Japan after an estimated 700,000 Bitcoins were stolen from its wallets. In May 2019, Binance, one of the world’s largest platforms, was hacked, resulting in losses of approximately $40 million, and in February 2021, Bitfinex settled a long-running legal dispute with the State of New York related to Bitfinex’s alleged misuse of over $800 million of customer assets. The failure of several prominent crypto trading venues and lending platforms in 2022 resulted in a loss of confidence in the broader industry, adverse reputational impact to crypto asset platforms, increased negative publicity surrounding crypto more broadly, heightened scrutiny by regulators and lawmakers and a call for increased regulations of crypto assets and crypto asset platforms. In addition, there have been reports that a significant amount of crypto asset trading volume on crypto asset platforms is fabricated and false in nature, with a specific focus on unregulated platforms located outside the United States. Such reports may indicate that the market for crypto asset platform activities is significantly smaller than otherwise understood. Negative perception, a lack of stability and standardized regulation in our industry, and the closure or temporary shutdown of crypto asset platforms due to fraud, business failure, hackers or malware, or government mandated regulation, and associated losses suffered by customers may continue to reduce confidence or interest in our industry and result in greater volatility of the prices of assets, including significant depreciation in value. Any of these events could have an adverse impact on our business and our customers’ perception of us, including decreased use of our platform and loss of customer demand for our products and services. 56 Table of Contents Depositing and withdrawing crypto assets into and from our platforms involve risks, which could result in loss of customer assets, customer disputes and other liabilities, which could adversely affect our business, operating results, and financial condition. In order to own, transfer and use a crypto asset on its underlying blockchain network, a person must have a private and public key pair associated with a network address, commonly referred to as a “wallet.” Each wallet is associated with a unique “public key” and “private key” pair, each of which is a string of alphanumerical characters. To deposit crypto assets held by a customer onto our platforms, a customer must “sign” a transaction that consists of the private key of the wallet from where the customer is transferring crypto assets, the public key of a wallet that we control which we provide to the customer, and broadcast the deposit transaction onto the underlying blockchain network. Similarly, to withdraw crypto assets from our platforms, the customer must provide us with the public key of the wallet that the crypto assets are to be transferred to, and we would be required to “sign” a transaction authorizing the transfer. In addition, some crypto networks require additional information to be provided in connection with any transfer of crypto assets to or from our platforms. A number of errors can occur in the process of depositing or withdrawing crypto assets into or from our platforms, such as typos, mistakes, or the failure to include the information required by the blockchain network. For instance, a user may incorrectly enter our wallet’s public key or the desired recipient’s public key when depositing and withdrawing from our platforms, respectively. Alternatively, a user may transfer crypto assets to a wallet address that the user does not own, control or hold the private keys to. In addition, each wallet address is only compatible with the underlying blockchain network on which it is created. For instance, a Bitcoin wallet address can only be used to send and receive Bitcoins. If any Ethereum or other crypto assets are sent to a Bitcoin wallet address, or if any of the foregoing errors occur, all of the customer’s sent crypto assets will be permanently and irretrievably lost with no means of recovery. We have encountered and expect to continue to encounter similar incidents with our customers. Such incidents could result in customer disputes, damage to our brand and reputation, legal claims against us, and financial liabilities, any of which could adversely affect our business, operating results, and financial condition. Moreover, we hold customer assets one-to-one at all times and we have procedures to process redemptions and withdrawals expeditiously, following the terms of the applicable user agreements. We have not experienced excessive redemptions or withdrawals, or prolonged suspended redemptions or withdrawals, of crypto assets to date. However, similar to traditional financial institutions, we may experience temporary process-related withdrawal delays. For example, we, and traditional financial institutions, may experience such delays if there is a significant volume of withdrawal requests that is vastly beyond anticipated levels. This does not mean we cannot or will not satisfy withdrawals, but this may mean a temporary delay in satisfying withdrawal requests, which we still expect to be satisfied within the withdrawal timelines set forth in the applicable user agreements or otherwise communicated by us. To the extent we have process-related delays, even if brief or due to blockchain network congestion or heightened redemption activity, and within the terms of an applicable user agreement or otherwise communicated by us, we may experience increased customer complaints and damage to our brand and reputation and face additional regulatory scrutiny, any of which could adversely affect our business, operating results, and financial condition. A temporary or permanent blockchain “fork” to any supported crypto asset could adversely affect our business, operating results, and financial condition. Blockchain protocols, including Bitcoin and Ethereum, are open source. Any user can download the software, modify it, and then propose that Bitcoin, Ethereum, or other blockchain protocols users and miners adopt the modification. When a modification is introduced and a substantial majority of users and miners consent to the modification, the change is implemented and the Bitcoin, Ethereum or other blockchain protocol networks, as applicable, remain uninterrupted. However, if less than a substantial majority of users and miners consent to the proposed modification, and the modification is not compatible with the software prior to its modification, the consequence would be what is known as a “fork” (i.e., “split”) of the impacted blockchain protocol network and respective blockchain, with one prong running the pre-modified software and the other running the modified software. The effect of such a fork would be the 57 Table of Contents existence of two parallel versions of the Bitcoin, Ethereum, or other blockchain protocol network, as applicable, running simultaneously, but with each split network’s crypto asset lacking interchangeability. Both Bitcoin and Ethereum protocols have been subject to “forks” that resulted in the creation of new networks, including Bitcoin Cash ABC, Bitcoin Cash SV, Bitcoin Diamond, Bitcoin Gold, Ethereum Classic, EthereumPOW, and others. Some of these forks have caused fragmentation among platforms as to the correct naming convention for forked crypto assets. Due to the lack of a central registry or rulemaking body, no single entity has the ability to dictate the nomenclature of forked crypto assets, causing disagreements and a lack of uniformity among platforms on the nomenclature of forked crypto assets, and which results in further confusion to customers as to the nature of assets they hold on platforms. In addition, several of these forks were contentious and as a result, participants in certain communities may harbor ill will towards other communities. As a result, certain community members may take actions that adversely impact the use, adoption, and price of Bitcoin, Ethereum, or any of their forked alternatives. Furthermore, hard forks can lead to new security concerns. For instance, when the Ethereum and Ethereum Classic networks split in July 2016, replay attacks, in which transactions from one network were rebroadcast on the other network to achieve “double-spending,” plagued platforms that traded Ethereum through at least October 2016, resulting in significant losses to some crypto asset platforms. Similar replay attacks occurred in connection with the Bitcoin Cash and Bitcoin Cash SV network split in November 2018. Another possible result of a hard fork is an inherent decrease in the level of security due to the splitting of some mining power across networks, making it easier for a malicious actor to exceed 50% of the mining power of that network, thereby making crypto assets that rely on proof-of-work more susceptible to attack, as has occurred with Ethereum Classic. We do not believe that we are required to support any fork or airdrop or provide the benefit of any forked or airdropped crypto asset to our customers. However, we have in the past and may in the future continue to be subject to claims by customers arguing that they are entitled to receive certain forked or airdropped crypto assets by virtue of crypto assets that they hold with us. If any customers succeed on a claim that they are entitled to receive the benefits of a forked or airdropped crypto asset that we do not or are unable to support, we may be required to pay significant damages, fines or other fees to compensate customers for their losses. Future forks may occur at any time. A fork can lead to a disruption of networks and our information technology systems, cybersecurity attacks, replay attacks, or security weaknesses, any of which can further lead to temporary or even permanent loss of our and our customers’ assets. Such disruption and loss could cause us to be exposed to liability, even in circumstances where we have no intention of supporting an asset compromised by a fork. We currently support, and expect to continue to support, certain smart contract-based crypto assets. If the underlying smart contracts for these crypto assets do not operate as expected, they could lose value and our business, operating results, and financial condition could be adversely affected. We currently support, and expect to continue to support, various crypto assets that represent units of value on smart contracts deployed on a third-party blockchain. Smart contracts are programs that store and transfer value and execute automatically when certain conditions are met. Since smart contracts typically cannot be stopped or reversed, vulnerabilities in their programming and design can have damaging effects. For instance, in April 2018, a batch overflow bug was found in many Ethereum-based ERC20-compatible smart contract tokens that allowed hackers to create a large number of smart contract tokens, causing multiple crypto asset platforms worldwide to shut down ERC20-compatible token trading. Similarly, in March 2020, a design flaw in the MakerDAO smart contract caused forced liquidations of crypto assets at significantly discounted prices, resulting in millions of dollars of losses to users who had deposited crypto assets into the smart contract. If any such vulnerabilities or flaws come to fruition, smart contract-based crypto assets, including those held by our customers on our platforms, may suffer 58 Table of Contents negative publicity, be exposed to security vulnerabilities, decline significantly in value, and lose liquidity over a short period of time. In some cases, smart contracts can be controlled by one or more “admin keys” or users with special privileges, or “super users.” These users have the ability to unilaterally make changes to the smart contract, enable or disable features on the smart contract, change how the smart contract receives external inputs and data, and make other changes to the smart contract. For smart contracts that hold a pool of reserves, these users may also be able to extract funds from the pool, liquidate assets held in the pool, or take other actions that decrease the value of the assets held by the smart contract in reserves. Even for crypto assets that have adopted a decentralized governance mechanism, such as smart contracts that are governed by the holders of a governance token, such governance tokens can be concentrated in the hands of a small group of core community members, who would be able to make similar changes unilaterally to the smart contract. If any such super user or group of core members unilaterally make adverse changes to a smart contract, the design, functionality, features and value of the smart contract, its related crypto assets may be harmed. In addition, assets held by the smart contract in reserves may be stolen, misused, burnt, locked up or otherwise become unusable and irrecoverable. These super users can also become targets of hackers and malicious attackers. If an attacker is able to access or obtain the super user privileges of a smart contract, or if a smart contract’s super users or core community members take actions that adversely affect the smart contract, our customers who hold and transact in the affected crypto assets may experience decreased functionality and value of the applicable crypto assets, up to and including a total loss of the value of such crypto assets. Although we do not control these smart contracts, any such events could cause customers to seek damages against us for their losses, result in reputational damage to us, or in other ways adversely affect our business, operating results, and financial condition. From time to time, we may encounter technical issues in connection with the integration of supported crypto assets and changes and upgrades to their underlying networks, which could adversely affect our business, operating results, and financial condition. In order to support any supported crypto asset, a variety of front and back-end technical and development work is required to implement our wallet, custody, trading, staking and other solutions for our customers, and to integrate such supported crypto asset with our existing technical infrastructure. For certain crypto assets, a significant amount of development work is required and there is no guarantee that we will be able to integrate successfully with any existing or future crypto asset, or that such integration will be secure against blockchain-level exploits or vulnerabilities. In addition, such integration may introduce software errors or weaknesses into our platform, including our existing infrastructure. Even if such integration is initially successful, any number of technical changes, software upgrades, soft or hard forks, cybersecurity incidents, or other changes to the underlying blockchain network may occur from time to time, causing incompatibility, technical issues, disruptions, or security weaknesses to our platform. If we are unable to identify, troubleshoot and resolve any such issues successfully, we may no longer be able to support such crypto asset, our customers’ assets may be frozen or lost, the security of our hot, warm, or cold wallets may be compromised, and our platform and technical infrastructure may be affected, all of which could adversely affect our business, operating results, and financial condition. If miners or validators of any supported crypto asset demand high transaction fees, our business, operating results, and financial condition could be adversely affected. We charge blockchain transaction fees when a customer sends certain crypto assets from their Coinbase account to a non-Coinbase account. We estimate the blockchain transaction fee based on the cost that we will incur to process the withdrawal transaction on the underlying blockchain network. In addition, we also pay blockchain transaction fees when we move crypto assets for various operational purposes, such as when we transfer crypto assets between our hot and cold wallets, for which we do not charge our customers. However, blockchain transaction fees have been and may continue to be unpredictable. If the block rewards for miners on any blockchain network are not sufficiently high to incentivize miners, miners may demand higher transaction fees, or collude to reject low transaction fees 59 Table of Contents and force users to pay higher fees. Although we generally attempt to pass blockchain transaction fees relating to customer withdrawals through to our customers, we have in the past incurred, and expect to incur from time to time, losses associated with the payment of blockchain transaction fees in excess of what we charge our customers, which could adversely affect our business, operating results, and financial condition. Future developments regarding the treatment of crypto assets for U.S. and foreign tax purposes could adversely affect our business, operating results, and financial condition. Due to the nature of crypto assets and the absence of comprehensive legal and tax guidance with respect to crypto asset products and transactions, many significant aspects of the U.S. and foreign tax treatment of transactions involving crypto assets, such as the purchase and sale of crypto assets on our platform, as well as the provision of blockchain rewards and other crypto asset incentives and rewards products, are uncertain, and it is unclear whether, when and what guidance may be issued in the future on the treatment of crypto asset transactions for U.S. and foreign tax purposes. In 2014, the IRS released Notice 2014-21, discussing certain aspects of “virtual currency” for U.S. federal income tax purposes and, in particular, stating that such virtual currency (i) is “property,” (ii) is not “currency” for purposes of the rules relating to foreign currency gain or loss, and (iii) may be held as a capital asset. From time to time, the IRS has released other guidance relating to the tax treatment of virtual currency or crypto assets reflecting the IRS’s position on certain issues. The IRS has not addressed many other significant aspects of the U.S. federal income tax treatment of crypto assets and related transactions. There continues to be uncertainty with respect to the timing, character, and amount of income inclusions for various crypto asset transactions including, but not limited to lending and borrowing crypto assets, staking, and other crypto asset incentives and products that we offer. Although we believe our treatment of crypto asset transactions for federal income tax purposes is consistent with existing positions from the IRS and/or existing U.S. federal income tax principles, because of the advances in crypto asset innovations and the increasing variety and complexity of crypto asset transactions and products, it is possible the IRS and various U.S. states may disagree with our treatment of certain crypto asset offerings for U.S. tax purposes, which could adversely affect our customers and the vitality of our business. Similar uncertainties exist in the foreign markets in which we operate with respect to direct and indirect taxes, and these uncertainties and potential adverse interpretations of tax law could impact the amount of tax we and our non-U.S. customers are required to pay, and the vitality of our platforms outside of the United States. There can be no assurance that the IRS, U.S. state revenue agencies, or other foreign tax authorities, will not alter their respective positions with respect to crypto assets in the future or that a court would uphold the treatment set forth in existing positions. It also is unclear what additional tax authority positions, regulations, or legislation may be issued in the future on the treatment of existing crypto asset transactions and future crypto asset innovations under U.S. federal, U.S. state, or foreign tax law. Any such developments could result in adverse tax consequences for holders of crypto assets and could have an adverse effect on the value of crypto assets and the broader crypto assets markets. Future technological and operational developments that may arise with respect to crypto assets may increase the uncertainty with respect to the treatment of crypto assets for U.S. and foreign tax purposes. The uncertainty regarding tax treatment of crypto asset transactions impacts our customers, and could impact our business, both domestically and abroad. Our tax information reporting obligations with respect to crypto transactions may be subject to further scrutiny in light of the implementation of the U.S. and global broker reporting regime for tax reporting. In 2021, the U.S. Congress passed the Infrastructure Investment and Jobs Act (the “IIJA”), providing that brokers would be responsible for reporting to the IRS the transactions of their customers in digital assets, including transfers to other exchanges or to digital asset wallets not connected to any exchange. 60 Table of Contents In 2024, the U.S. Treasury Department and the IRS released final regulations and issued other administrative guidance on tax information reporting for digital assets (collectively, the “Final Regulations”) that are applicable, in certain cases as of January 1, 2025. Although we believe we are compliant with U.S. tax reporting and withholding requirements, our compliance with the Final Regulations, including but not limited to U.S. onboarding requirements through Forms W-9 and W-8, backup withholding, non-resident alien withholding, and Form 1099 and Form 1042-S reporting obligations, may be subject to scrutiny and may be challenged. There is a risk that we may not properly implement processes and procedures necessary to comply with the Final Regulations, may misinterpret the IIJA, the Final Regulations, or the administrative guidance, or may experience disruptions in the systems recently built. If the IRS determines that we are not in compliance with our tax reporting or withholding obligations, significant taxes and penalties may be imposed, which could adversely affect our financial position. The Final Regulations require us to invest substantially in new compliance processes and procedures, which also could adversely affect our financial position. Further, the IRS may issue additional guidance with respect to tax reporting and withholding obligations, which could impose additional burdens on us and result in significant taxes and penalties that could adversely affect our financial position. Similarly, new rules for reporting crypto assets under the global “common reporting standard” (CRS) and the “crypto-asset reporting framework” (CARF) have been implemented on our operations, creating new obligations and a need to continue investing in new onboarding and reporting infrastructure. Such rules have been adopted by numerous member and observer states of the “Organization for Economic Cooperation and Development” and by the European Commission on behalf of the member states of the European Union. These new rules may give rise to potential liabilities or disclosure requirements for prior customer arrangements and operational challenges that affect how we onboard our customers and report their transactions to taxing authorities. Additionally, the European Union has implemented a directive, commonly referred to as “CESOP” (the Central Electronic System of Payment information), which requires payment service providers in the European Union to report cross-border fiat transactions to taxing authorities on a quarterly basis. Any actual or perceived failure by us to comply with the above or any other tax and financial regulations that apply to our operations could harm our business, lead to customer attrition, and adversely affect our financial position. The nature of our business requires the application of complex financial accounting rules, and there is limited guidance from accounting standard setting bodies on certain topics. If financial accounting standards undergo significant changes, our operating results could fluctuate. The accounting rules and regulations that we must comply with are complex and subject to interpretation by the Financial Accounting Standards Board (the “FASB”), the SEC, and various other bodies formed to promulgate and interpret appropriate accounting principles. Recent actions and public comments from the FASB and the SEC have focused on the integrity of financial reporting and internal controls and many companies’ accounting policies are being subjected to heightened scrutiny by regulators and the public. Further, there remains relatively limited precedent for the financial accounting of crypto assets and related valuation and revenue recognition, even while the crypto ecosystem continues to evolve rapidly, leading in some cases to related accounting standards becoming quickly outdated. Moreover, a change in these principles or interpretations could have a significant effect on our reported financial results, and may even affect the reporting of transactions completed before the announcement or effectiveness of a change. For example, on March 31, 2022, the staff of the SEC issued Staff Accounting Bulletin (“SAB”) No. 121 (“SAB 121”), which represented a significant change regarding how a company safeguarding crypto assets held for its platform users reports such crypto assets on its balance sheet and required retrospective application as of January 1, 2022. In January 2025, the staff of the SEC issued SAB No. 122 (“SAB 122”), which rescinds the previously-issued interpretive guidance included within SAB 121. We adopted SAB 122 as of December 31, 2024 on a retrospective basis. Uncertainties in or changes to regulatory or financial accounting standards could result in the need to change our accounting methods and may retroactively affect previously reported results and impair our 61 Table of Contents ability to provide timely and accurate financial information, which could adversely affect our financial statements, result in a loss of investor confidence, and our business, operating results, and financial condition. Risks Related to Government Regulation and Privacy Matters The onchain economy is novel. As a result, policymakers are considering what a regulatory regime for crypto would look like and the elements that would serve as the foundation for such a regime. This less developed consideration of crypto may harm our ability to effectively react to proposed legislation and regulation of crypto assets or crypto asset platforms adverse to our business. As crypto assets have grown in both popularity and market size, various U.S. federal, state, and local and foreign governmental organizations, consumer agencies and public advocacy groups have been examining the operations of crypto networks, users and platforms, with a focus on how crypto assets can be used to launder the proceeds of illegal activities, fund criminal or terrorist enterprises, and simultaneously how to ensure the safety and soundness of platforms and other service providers that hold crypto assets for users. Many of these entities have called for heightened regulatory oversight, and have issued consumer advisories describing the risks posed by crypto assets to users and investors. Competitors, including traditional financial services, have spent years cultivating professional relationships with relevant policymakers on behalf of their industry so that those policymakers may understand that industry, the current legal landscape affecting that industry, and the specific policy proposals that could be implemented in order to responsibly develop that industry. The lobbyists working for these competitors have similarly spent years developing and working to implement strategies to advance these industries. Members of the onchain economy have started to engage policymakers directly and with the help of external advisors and lobbyists. For example, in order to advance our mission, in February 2022 we launched our Coinbase Innovation Political Action Committee to support crypto-forward political candidates and initiatives. Further, in December 2023, we together with a number of other crypto and blockchain market participants supported the launch of the Fairshake Political Action Committee, which supports political candidates who support crypto and blockchain innovation or against political candidates who do not support crypto and blockchain innovation. However, these efforts to educate policymakers and advocate for sensible crypto regulation are nascent compared to more established industries, and may be perceived unfavorably by investors and the public and have an adverse impact on our brand and reputation. As a result, new laws and regulations may be proposed and adopted in the United States and internationally, or existing laws and regulations may be interpreted in new ways, that harm the onchain economy or crypto asset platforms, which could adversely affect our business, operating results, and financial condition. Our Consolidated Balance Sheets may not contain sufficient amounts or types of regulatory capital to meet the changing requirements of our various regulators worldwide, which could adversely affect our business, operating results, and financial condition. We are required to possess sufficient financial soundness and strength to adequately support our regulated subsidiaries. We may from time to time incur indebtedness and other obligations which could make it more difficult to meet these capitalization requirements or any additional regulatory requirements. In addition, although we are not a bank holding company for purposes of United States law or the law of any other jurisdiction, as a global provider of financial services and in light of the changing regulatory environment in various jurisdictions, we could become subject to new capital requirements introduced or imposed by the United States and international regulators. Any change or increase in these regulatory requirements could adversely affect our business, operating results, and financial condition. As a financial institution licensed to, among other things, engage in money transmission in the United States, to conduct virtual currency business activity in New York, Dubai and Bermuda, and issue electronic money in the United Kingdom and the European Union, we are subject to strict rules governing 62 Table of Contents how we manage and hold customer fiat currency, stablecoins, and crypto assets. We maintain complex treasury operations to manage and move customer fiat currency, stablecoins, and crypto assets across our platforms and to comply with regulatory requirements. However, it is possible we may experience errors in fiat currency, stablecoin, and crypto asset handling, accounting, and regulatory reporting that lead us to be out of compliance with these requirements. In addition, regulators may increase the amount of capital reserves that we are required to maintain for our operations, as has happened in the past, which may lead to sanctions, penalties, changes to our business operations, or the revocation of licenses. Frequent launch of new products and services, margin trading, lending functions, and the addition of new payment rails increase these risks. Many of the crypto assets and other products, such as event contracts, in which we facilitate trading are subject to regulatory authority by the CFTC. Any fraudulent or manipulative activity in a crypto asset or other regulated product, including event contracts, occurring on our platform could subject us to increased regulatory scrutiny, regulatory enforcement, and litigation. The CFTC has stated and judicial decisions involving CFTC enforcement actions have confirmed that at least some crypto assets, including Bitcoin, ether, litecoin, and stablecoins, such as USDC, USDT and BUSD, fall within the definition of a “commodity” under the U.S. Commodities Exchange Act of 1936 (the “CEA”). As a result, the CFTC has general enforcement authority to police against manipulation and fraud in at least some spot crypto asset markets. From time to time, manipulation, fraud, and other forms of improper trading by market participants have resulted in, and may in the future result in, CFTC investigations, inquiries, enforcement action, and similar actions by other regulators, government agencies, and civil litigation. Such investigations, inquiries, enforcement actions, and litigation may cause us to incur substantial costs and could result in negative publicity. Furthermore, the CTFC has regulatory authority over certain product offerings, including event contracts, which are regulated as “swaps” under the CEA. This classification subjects us to the CFTC’s supervisory and enforcement oversight, including supervisory requirements to prevent manipulation, fraud and other forms of improper trading in these markets. As a result, the offering and facilitation of these contracts on our platform could result in increased regulatory scrutiny, investigations, and enforcement actions, which may cause us to incur substantial costs and expose us to civil liability, fines, and reputational harm. Some states have taken the position that the states and not the CFTC should be the appropriate regulator for sports-related event contracts and that question is the subject of ongoing litigation. See the Risk Factor titled “ We are subject to an extensive, highly-evolving and uncertain regulatory landscape and any adverse changes to, or our failure to comply with, any laws and regulations could adversely affect our brand, reputation, business, operating results, and financial condition. ” for additional information. Certain transactions in crypto assets may constitute “retail commodity transactions” subject to regulation by the CFTC as futures contracts. If crypto asset transactions we facilitate are deemed to be such retail commodity transactions, we would be subject to additional regulatory requirements, licenses and approvals, and potentially face regulatory enforcement, civil liability, and significant increased compliance and operational costs. Any transaction in a commodity, including a crypto asset, entered into with or offered to retail investors using leverage, margin, or other financing arrangements (a “retail commodity transaction”) is subject to CFTC regulation as a futures contract unless such transaction results in actual delivery within 28 days. The meaning of “actual delivery” has been the subject of commentary and debate. To the extent that crypto asset transactions that we facilitate or facilitated are deemed retail commodity transactions, including pursuant to current or subsequent rulemaking or guidance by the CFTC, we may be subject to additional regulatory requirements and oversight, and we could be subject to judicial or administrative sanctions if we do not or did not at a relevant time possess appropriate registrations. The CFTC has previously brought enforcement actions against entities engaged in retail commodity transactions without appropriate registrations, as well as recent enforcement settled orders against developers of decentralized platforms. 63 Table of Contents Particular crypto assets or transactions therein, or other contracts or products we offer, could be deemed “commodity interests” (e.g., futures, options, swaps) or security-based swaps subject to regulation by the CFTC or SEC, respectively. If a crypto asset that we facilitate trading in is deemed a commodity interest or a security-based swap, we would be subject to additional regulatory requirements, registrations and approvals, and potentially face regulatory enforcement, civil liability, and significant increased compliance and operational costs. Commodity interests, as such term is defined by the CEA and CFTC rules and regulations, are subject to more extensive supervisory oversight by the CFTC, including registrations of entities engaged in, and platforms offering, commodity interest transactions. This CFTC authority extends to crypto asset futures contracts and swaps, including transactions that are based on current and future prices of crypto assets and indices of crypto assets. To the extent that a crypto asset in which we facilitate or facilitated trading or transactions in a crypto asset which we facilitate or facilitated are deemed to fall within the definition of a commodity interest, including pursuant to subsequent rulemaking or guidance by the CFTC, we may be subject to additional regulatory requirements and oversight and could be subject to judicial or administrative sanctions if we do not or did not at a relevant time possess appropriate registrations as an exchange (for example, as a designated contract market for trading futures or options on futures, or as a swaps execution facility for trading swaps) or as a registered intermediary (for example, as a futures commission merchant or introducing broker). Such actions could result in injunctions, cease and desist orders, as well as civil monetary penalties, fines, and disgorgement, as well as reputational harm. The CFTC has previously brought enforcement actions against entities engaged in crypto asset activities for failure to obtain appropriate exchange, execution facility and intermediary registrations. Furthermore, the CFTC and the SEC have jointly adopted regulations defining “security-based swaps,” which include swaps based on single securities and narrow-based indices of securities. If a crypto asset is deemed to be a security, certain transactions referencing that crypto asset could constitute a security-based swap. A crypto asset or transaction therein that is based on or references a security or index of securities, whether or not such securities are themselves crypto assets, could also constitute a security-based swap. To the extent that a crypto asset in which we facilitate or have facilitated trading or transactions in a crypto asset which we facilitate or have facilitated are deemed to fall within the definition of a security-based swap, including pursuant to subsequent rulemaking or guidance by the CFTC or SEC, we may be subject to additional regulatory requirements and oversight by the SEC and could be subject to judicial or administrative sanctions if we do not or did not a relevant time possess appropriate registrations as an exchange (for example, as a security-based swaps execution facility) or as a registered intermediary (for example, as a security-based swap dealer or broker-dealer). This could result in injunctions, cease and desist orders, as well as civil monetary penalties, fines, and disgorgement, as well as reputational harm. We collect and process a large amount of sensitive customer data. Any real or perceived improper use of, disclosure of, or access to such data could harm our reputation, as well as adversely affect our business, operating results, and financial condition. We collect and process large amounts of sensitive data, including personal data related to our customers and their transactions, such as their names, addresses, social security numbers, visa information, copies of government-issued identification, biometric facial recognition data (from scanning of photographs for identity verification and fraud prevention purposes), trading data, tax identification, and bank account information. We face risks, including to our reputation, in the processing and protection of this data, and these risks will increase as our business continues to expand, including through our acquisition of, and investment in, other companies and technologies. Federal, state, and international laws and regulations governing privacy, data protection, and e-commerce transactions require us to safeguard our customers’, employees’, and service providers’ personal data. We have administrative, technical, and physical security measures and controls in place and maintain a robust information security program. However, our security measures, those of our vendors or service providers, or the security measures of companies we acquire, may be inadequate or breached as a result 64 Table of Contents of third-party action, employee or service provider error, malfeasance, malware, phishing, hacking attacks, system error, trickery, advances in computer capabilities, new discoveries in the field of cryptography, inadequate facility security or otherwise, and, as a result, someone may be able to obtain unauthorized access to sensitive information, including personal data, on our systems. We could be the target of a cybersecurity incident, which could result in harm to our reputation and financial losses. Additionally, our customers have been and could be targeted in cybersecurity incidents like an account takeover, which could result in harm to our reputation and financial losses. For example, as previously disclosed on a Current Report on Form 8-K filed with the SEC on May 15, 2025, a threat actor improperly obtained information about certain customer accounts and internal documentation, and used that information for social-engineering attempts. No passwords or private keys were compromised as a result of this incident. We continue to face risks related to this incident, including harm to our reputation, governmental investigations and regulatory scrutiny, and ongoing litigation. Our future success depends on the reliability and security of our platform. To the extent that the measures we, any companies we acquire, or our third-party service providers, vendors, or business partners have taken prove to be insufficient or inadequate, or to the extent we discover a security breach suffered by a company we acquire following the closing of such acquisition, we may become subject to litigation, breach notification obligations, or regulatory or administrative sanctions, which could result in significant fines, penalties, damages, harm to our reputation, or loss of customers. If our own confidential business information or sensitive customer information were improperly disclosed, our business, operating results, and financial condition could be adversely affected. Additionally, a party who circumvents our security measures could, among other effects, appropriate customer information or other proprietary data, cause interruptions in our operations, or expose customers to hacks, viruses, and other disruptions. The increasing sophistication of AI poses a greater risk of identity fraud, as malicious actors may exploit various AI technologies to create increasingly convincing false identities, transaction records, or attempt to manipulate our verification processes. This necessitates ongoing enhancements to our verification systems and security protocols to prevent unauthorized access and protect sensitive information. Failure to manage these risks or to implement effective countermeasures could lead to unauthorized transactions, financial losses, reputational damage and increased regulatory scrutiny. Depending on the nature of the information compromised, in the event of a data breach or other unauthorized access to our customer data, we may also have obligations to notify customers and regulators about the incident, and we may need to provide some form of remedy, such as a subscription to credit monitoring services, pay significant fines to one or more regulators, or pay compensation in connection with a class-action settlement. Breach notification laws continue to evolve and may be inconsistent from one jurisdiction to another. In the United States, the SEC has adopted rules for mandatory disclosure of material cybersecurity incidents suffered by public companies, as well as cybersecurity governance and risk management. Complying with these obligations could cause us to incur substantial costs and could increase negative publicity surrounding any incident that compromises customer data. Any failure or perceived failure by us to comply with these laws may also subject us to enforcement action or litigation, any of which could harm our business. Additionally, the financial exposure from the events referenced above could either not be insured against or not be fully covered through any insurance that we may maintain, and there can be no assurance that the limitations of liability in any of our contracts would be enforceable or adequate or would otherwise protect us from liabilities or damages as a result of the events referenced above. Any of the foregoing could adversely affect our business, reputation, operating results, and financial condition. Furthermore, we may be required to disclose personal data pursuant to demands from individuals, regulators, government agencies, and law enforcement agencies in various jurisdictions with conflicting privacy and security laws, which could result in a breach of privacy and data protection policies, notices, laws, rules, court orders, and regulations. Additionally, changes in the laws and regulations that govern our collection, use, and disclosure of customer data could impose additional requirements with respect to 65 Table of Contents the retention and security of customer data, could limit our marketing activities, and adversely affect our business, operating results, and financial condition. We are subject to laws, regulations, and industry requirements related to data privacy, data protection and information security, and user protection across different markets where we conduct our business, including in the United States, European Economic Area (the “EEA”), and Asia-Pacific region, and such laws, regulations, and industry requirements are constantly evolving and changing. Any actual or perceived failure to comply with such laws, regulations, and industry requirements, or our privacy policies, could harm our business. Various local, state, federal, and international laws, directives, and regulations apply to our collection, use, retention, protection, disclosure, transfer, and processing of personal data. These data protection and privacy laws and regulations are subject to uncertainty and continue to evolve in ways that could adversely affect our business, operating results, and financial condition. These laws have a substantial impact on our operations both outside and in the United States, either directly or as a data processor and handler for various offshore entities. In the United States, state and federal lawmakers and regulatory authorities have increased their attention on the collection and use of user data and various laws and regulations apply to the collection, processing, disclosure, and security of certain types of data, including the Gramm Leach Bliley Act (“GLBA”) and state laws relating to privacy and data security. GLBA requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. Additionally, the Federal Trade Commission and many state attorneys general are interpreting federal and state consumer protection laws as imposing standards for the online collection, use, dissemination, and security of data. For example, California has enacted the California Consumer Privacy Act (the “CCPA”). The CCPA requires covered companies to, among other things, provide disclosures to individuals in California, and affords such individuals privacy rights such as the ability to opt-out of certain sales of personal information and expanded rights to access and require deletion of their personal information, opt out of certain personal information sharing, and receive detailed information about how their personal information is collected, used, and shared. The CCPA provides for civil penalties for violations, as well as a private right of action for security breaches that may increase security breach litigation. In addition, other U.S. states have proposed or enacted laws that contain obligations similar to the CCPA that have taken effect or will take effect in coming years. We cannot fully predict the impact of recently proposed or enacted laws or regulations on our business or operations, but compliance may require us to modify our data processing practices and policies incurring costs and expense. Further, to the extent multiple state-level laws are introduced with inconsistent or conflicting standards, it may require costly and difficult efforts to achieve compliance with such laws. Our failure or perceived failure to comply with state privacy laws or regulations passed in the future could adversely affect our business, including how we use personal information, operating results, and financial condition. Additionally, many foreign countries and governmental bodies, including Australia, Brazil, Kenya, the European Union, India, Japan, Philippines, Indonesia, Singapore, United Kingdom, Switzerland, and numerous other jurisdictions in which we may operate or conduct our business, have laws and regulations concerning the collection, use, processing, storage, and deletion of personal data obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States. Such laws and regulations may require companies to implement new privacy and security policies, permit individuals to access, correct, and delete personal data stored or maintained by such companies, inform individuals of security breaches that affect their personal data, require that certain types of data be retained on local servers within these jurisdictions, and, in some cases, obtain individuals’ affirmative opt-in consent to collect and use personal data for certain purposes. 66 Table of Contents We are subject to, or may become subject to, the E.U.’s and the U.K.’s General Data Protection Regulation (collectively, the “GDPR”), the E.U. ePrivacy Directive (including its national implementations), the E.U. Data Act, the E.U. Digital Operational Resilience Act and other E.U. and U.K. laws that regulate personal data, non-personal data, and cybersecurity operations. The most well-known of such laws, the GDPR, imposes stringent privacy and personal data protection requirements and could increase the risk of non-compliance and the costs of providing our products and services in a compliant manner. A breach of the GDPR could result in regulatory investigations, reputational damage, fines and sanctions, orders to cease or change our processing of our data, enforcement notices, or assessment notices (for a compulsory audit). For example, if regulators assert that we have failed to comply with the GDPR, we may be subject to fines of up to €20 million in the E.U. (£17.5 million in the U.K.) or 4% of our worldwide annual revenue, whichever is greater. We may also face civil claims including representative actions and other class action type litigation (where individuals have suffered harm), potentially amounting to significant compensation or damages liabilities, as well as associated costs, diversion of internal resources, and reputational harm. The GDPR and Swiss data protection laws impose strict rules on the transfer of personal data out of the E.U., U.K., or Switzerland to a “third country,” including the United States, unless particular compliance mechanisms are implemented. The mechanisms that we and many other companies rely upon for such data transfers (for example, standard contractual clauses or the E.U.-U.S. and Swiss-U.S. Data Privacy Framework (“DPF”) and the U.K. extension to the DPF) are the subject of legal challenge, regulatory interpretation, and judicial decisions. In the E.U. and other markets, potential new rules and restrictions on the flow of data across borders could increase the cost and complexity of doing business in those regions. While we maintain E.U.-U.S., Swiss-U.S. and U.K.-U.S. DPF certification, we still rely on the standard contractual clauses for intercompany data transfers from the European Union, Switzerland, and the U.K. to the United States. As supervisory authorities continue to issue further guidance on personal data, we could suffer additional costs, complaints, or regulatory investigations or fines, and if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations and could adversely affect our financial results. We are also subject to evolving privacy laws on cookies and e-marketing and online behavioral advertising. As regulators become increasingly focused on compliance, this could lead to substantial costs, require significant systems changes, limit the effectiveness of our marketing activities, divert the attention of our technology personnel, negatively impact our efforts to understand users, adversely affect our margins, increase costs, and subject us to additional liabilities. There is a risk that as we expand, we may assume liabilities for breaches experienced by the companies we acquire. Additionally, there are potentially inconsistent world-wide government regulations pertaining to data protection and privacy. Despite our efforts to comply with applicable laws, regulations and other obligations relating to privacy, data protection, and information security, it is possible that our practices, offerings, or platform could fail, or be alleged to fail to meet applicable requirements. For instance, the overall regulatory framework governing the application of privacy laws to blockchain technology is still highly undeveloped and likely to evolve. Further there are also changes in the regulatory landscape relating to new and evolving technologies. Our failure, or the failure by our third-party providers or partners, to comply with applicable laws or regulations and to prevent unauthorized access to, or use or release of personal data, or the perception that any of the foregoing types of failure has occurred, even if unfounded, could subject us to audits, inquiries, whistleblower complaints, adverse media coverage, investigations, severe criminal, or civil sanctions, damage our reputation, or result in fines or proceedings by governmental agencies and private claims and litigation, any of which could adversely affect our business, operating results, and financial condition. 67 Table of Contents Issues relating to the development and use of AI in our business could result in reputational harm, competitive harm, and legal liability, and could adversely affect our business, operating results, and financial condition. We currently leverage internally developed and third-party developed AI into certain aspects of our business and we anticipate that AI will become increasingly important to our operations in the future. Our competitors and other third parties may incorporate AI into their businesses or offerings more quickly or more successfully than us, which could impair our ability to compete effectively and adversely affect our business, operating results, and financial condition. Our use of AI may result in new or expanded risks and liabilities, including due to enhanced governmental or regulatory regulation and scrutiny, litigation, compliance issues, ethical concerns, confidentiality or security risks, as well as other factors that could adversely affect our reputation, business, operating results, and financial condition. Evolving legal frameworks and guidance, such as the E.U. AI Act, other international regimes, and emerging developments with respect to U.S. federal and state regulations, rules, and industry standards governing AI may require us and our third-party developers to incur significant costs to modify, maintain, or align our business practices, services, and solutions to comply with rules and regulations, the nature of which cannot be determined at this time and may be inconsistent from jurisdiction to jurisdiction. There can be no assurance that the use of AI and machine learning solutions and features will enhance our products or services, produce the intended results, or be beneficial to our business, including our efficiency. Consumer and societal attitudes toward AI are evolving and there is a risk that customers, regulators or the public may perceive AI technologies negatively. Concerns about automation, automated decision making, privacy, security, transparency, or other ethical considerations could reduce trust in our products and services or deter customer adoption of AI-enabled features in our products or services. AI machine learning systems are complex and may be flawed, insufficient, reflect unwanted forms of bias, or contain errors or inadequacies that are not easily detectable, or may cause unintentional or unexpected outputs that are incorrect, including with respect to financial data, do not match our business goals, do not comply with our policies or those of our regulators, or are otherwise are inconsistent with our brand. If the output that the AI applications we use to produce such output is, or is alleged to be, inaccurate, deficient, or biased, our reputation, business, operating results, and financial condition could be adversely affected. Risks Related to Third Parties Our current and future services are dependent on payment networks and acquiring processors, and any changes to their rules or practices could adversely affect our business, operating results, and financial condition. We rely on financial institutions and other payment processors to process customers’ payments in connection with the purchase of crypto assets on our platform and we pay these providers fees for their services. From time to time, payment networks have increased, and may increase in the future, the interchange fees and assessments that they charge for transactions that use their networks. Payment networks have imposed, and may impose in the future, special fees on the purchase of crypto assets, including on our platform, which could negatively impact us and significantly increase our costs. Our payment card processors may have the right to pass any increases in interchange fees and assessments on to us, and may impose additional use charges which would increase our operating costs and reduce our operating income. We could attempt to pass these increases along to our customers, but this strategy might result in the loss of customers to our competitors that may not pass along the increases, thereby reducing our revenue and earnings. If competitive practices prevent us from passing along the higher fees to our customers in the future, we may have to absorb all or a portion of such increases, thereby increasing our operating costs and reducing our earnings. 68 Table of Contents We may also be directly or indirectly liable to the payment networks for rule violations. Payment networks set and interpret their network operating rules and have alleged from time to time that various aspects of our business model violate these operating rules. If such allegations are not resolved favorably, they may result in significant fines and penalties, require changes in our business practices, or result in the loss of their services for parts of our business, any of which may be costly and adversely affect our business. The payment networks could adopt new operating rules or interpret or reinterpret existing rules that we or our processors might find difficult or even impossible to follow, or costly to implement. As a result, we could lose our ability to give customers the option of using cards to fund their purchases or the choice of currency in which they would like their card to be charged. If we are unable to accept cards or are limited in our ability to do so, our business, operating results, and financial condition could be adversely affected. We depend on major mobile operating systems and third-party platforms for the distribution of certain products. If Google Play, the Apple App Store, or other platforms prevent customers from downloading our apps, our ability to grow may be hindered and our business, operating results, and financial condition could be adversely affected. We rely upon third-party platforms for the distribution of certain products and services. Our Coinbase and the Base App (formerly Coinbase Wallet) apps are provided as free applications through both the Apple App Store and the Google Play Store, and are also accessible via mobile and traditional websites. The Google Play Store and Apple App Store are global application distribution platforms and the main distribution channels for our apps. As such, the promotion, distribution, and operation of our apps are subject to the respective platforms’ terms and policies for application developers, which are very broad and subject to frequent changes and re-interpretation. Further, these distribution platforms often contain restrictions related to crypto assets that are uncertain, broadly construed, and can limit the nature and scope of services that can be offered. For example, Apple App Store’s restrictions related to crypto assets have disrupted the proposed launch of many features within the Coinbase and the Base App apps, including NFT transfer services and access to decentralized applications. If our products are found to be in violation of any such terms and conditions, we may no longer be able to offer our products through such third-party platforms. There can be no guarantee that third-party platforms will continue to support our product offerings, or that customers will be able to continue to use our products. For example, in December 2019, we were instructed by Apple to remove certain features relating to decentralized applications from our application to comply with the Apple App Store’s policies. Any changes, bugs, technical or regulatory issues with third-party platforms, our relationships with mobile manufacturers and carriers, or changes to their terms of service or policies could degrade our products’ functionalities, reduce or eliminate our ability to distribute our products, give preferential treatment to competitive products, limit our ability to deliver high quality offerings, or impose fees or other charges, any of which could affect our product usage and adversely affect our business, operating results, and financial condition. Risks Related to Intellectual Property Our intellectual property rights are valuable, and any inability to protect them could adversely affect our business, operating results, and financial condition. Our business depends in large part on our proprietary technology and our brand. We rely on, and expect to continue to rely on, a combination of trademark, trade dress, patents, domain name, copyright, and trade secrets, as well as confidentiality and license agreements with our employees, contractors, consultants, and third parties with whom we have relationships, to establish and protect our brand and other intellectual property rights. However, our efforts to protect our intellectual property rights may not be sufficient or effective. Our proprietary technology and trade secrets could be lost through misappropriation or breach of our confidentiality and license agreements, and any of our intellectual property rights may be challenged, which could result in them being narrowed in scope or declared invalid or unenforceable. There can be no assurance that our intellectual property rights will be sufficient to protect against others 69 Table of Contents offering products, services, or technologies that are substantially similar to ours and that compete with our business. We do not intend to monetize our patents or attempt to block third parties from competing with us by asserting our patents offensively, but our ability to successfully defend intellectual property challenges from competitors and other parties may depend, in part and where permissible, on our ability to counter-assert our patents defensively. Effective protection of our intellectual property may be expensive and difficult to maintain, both in terms of application and registration costs as well as the costs of defending and enforcing those rights. As we have grown, we have sought to obtain and protect our intellectual property rights in an increasing number of countries, a process that can be expensive and may not always be successful. In some instances, patent applications or patents may be abandoned or allowed to lapse, resulting in partial or complete loss of patent rights in a relevant jurisdiction. Further, intellectual property protection may not be available to us in every country in which our products and services are available, and the regulatory landscape in such jurisdictions may evolve rapidly, leading to an unanticipated change in the ability to obtain and enforce intellectual property rights in these jurisdictions. For example, some foreign countries have compulsory licensing laws under which a patent owner must grant licenses to third parties. In addition, many countries limit the enforceability of patents against certain third parties, including government agencies or government contractors. In these countries, patents may provide limited or no benefit. We may also agree to license our patents to third parties as part of various patent pools and open patent projects. Those licenses may diminish our ability, though, to counter-assert our patents against certain parties that may bring claims against us. We have been, and in the future may be, sued by third parties for alleged infringement of their proprietary rights. In recent years, there has been considerable patent, copyright, trademark, domain name, trade secret, and other intellectual property development activity in the onchain economy, as well as litigation, based on allegations of infringement or other violations of intellectual property, including by large financial institutions. The evolving climate and new policy initiatives at the U.S. Patent and Trademark Office (“USPTO”) related to the Patent Trial and Appeal Board are creating a more challenging environment to invalidate patents that are or can be asserted against us. Furthermore, individuals and groups can purchase patents and other intellectual property assets for the purpose of making claims of infringement to extract settlements from companies like ours. Finally, the USPTO has recently implemented and may continue to implement changes that expand the subject matter considered eligible for patent protection, which may make it easier for competitors and other adverse parties to obtain patents related to our platform and technology. Our use of third-party intellectual property rights also may be subject to claims of infringement or misappropriation. We cannot guarantee that our internally developed or acquired technologies and content do not or will not infringe the intellectual property rights of others. From time to time, our competitors or other third parties may claim that we are infringing upon or misappropriating their intellectual property rights, and we may be found to be infringing upon such rights. Any claims or litigation could cause us to incur significant expenses and, if successfully asserted against us, could require that we pay substantial damages or ongoing royalty payments, prevent us from offering our products or services or using certain technologies, force us to implement expensive or less effective work-arounds, or impose other unfavorable terms. We expect that the occurrence of infringement claims is likely to grow as the crypto assets market grows and matures. Accordingly, our exposure to damages resulting from infringement claims could increase and this could further exhaust our financial and management resources. Further, during the course of any litigation, we may make announcements regarding the results of hearings and motions, and other interim developments. If securities analysts and investors regard these announcements as negative, the market price of our Class A common stock may decline. Even if intellectual property claims do not result in litigation or are resolved in our favor, these claims, and the time and resources necessary to resolve them, could divert the resources of our management and require significant expenditures. Any of the foregoing could prevent us from competing effectively and could adversely affect our business, operating results, and financial condition. 70 Table of Contents Our platform contains third-party open source software components, and failure to comply with the terms of the underlying open source software licenses could harm our business. Our platform contains software modules licensed to us by third-party authors under “open source” licenses. We also make certain of our own software available to users for free under various open source licenses. Use and distribution of open source software may entail greater risks than use of third-party commercial software, as open source licensors generally do not provide support, warranties, indemnification or other contractual protections regarding infringement claims or the quality of the code. In addition, the public availability of such software may make it easier for others to compromise our platform. Some open source licenses contain requirements that we make available source code for modifications or derivative works we create based upon the type of open source software we use, or grant other licenses to our intellectual property. If we combine our proprietary software with open source software in a certain manner, we could, under certain open source licenses, be required to release the source code of our proprietary software to the public. This would allow our competitors to create similar offerings with lower development effort and time and ultimately could result in a loss of our competitive advantages. Alternatively, to avoid the public release of the affected portions of our source code, we could be required to expend substantial time and resources to re-engineer some or all of our software. We have not recently conducted an extensive audit of our use of open source software and, as a result, we cannot assure you that our processes for controlling our use of open source software in our platform are, or will be, effective. If we are held to have breached or failed to fully comply with all the terms and conditions of an open source software license, we could face litigation, infringement claims, or other liabilities. Likewise, we may be required to seek costly licenses from third parties to continue providing our offerings on terms that are not economically feasible, to re-engineer our platform, to discontinue or delay the provision of our offerings if re-engineering cannot be accomplished on a timely basis or to make generally available, in source code form, our proprietary code, any of which could adversely affect our business, operating results, and financial condition. Moreover, the terms of many open source licenses have not been interpreted by U.S. or foreign courts. As a result, there is a risk that these licenses could be construed in a way that could impose unanticipated conditions or restrictions on our ability to provide or distribute our platform. From time to time, there have been claims challenging the ownership of open source software against companies that incorporate open source software into their solutions. As a result, we could be subject to lawsuits by parties claiming ownership of what we believe to be open source software. Risks Related to Our Employees and Other Service Providers The loss of one or more of our key personnel, or our failure to attract and retain other highly qualified personnel in the future, could adversely affect our business, operating results, and financial condition. We operate in a relatively new industry that is not widely understood and requires highly skilled and technical personnel. We believe that our future success is highly dependent on the talents and contributions of our senior management team, including Mr. Armstrong, our co-founder and Chief Executive Officer, members of our executive team, and other key employees across product, engineering, risk management, finance, compliance and legal, and marketing. Our future success depends on our ability to attract, develop, motivate, and retain highly qualified and skilled employees. The pool of qualified talent in our industry is extremely limited, particularly with respect to executive talent, engineering, risk management, and financial regulatory expertise. We face intense competition for qualified individuals from numerous software and other technology companies. To attract and retain key personnel, we incur significant costs, including salaries and benefits and equity incentives. Even so, these measures may not be enough to attract and retain the personnel we require to operate our business effectively. The loss of even a few key employees or senior leaders, or an inability to attract, retain and motivate additional highly skilled employees required for the planned expansion of our business could adversely affect our business, operating results, and financial condition and impair our ability to grow. 71 Table of Contents Our culture emphasizes innovation, and if we cannot maintain this culture, our business, operating results, and financial condition could be adversely affected. We believe that our entrepreneurial and innovative corporate culture has been a key contributor to our success. We encourage and empower our employees to develop and launch new and innovative products and services, which we believe is essential to attracting high quality talent, partners, and developers, as well as serving the best, long-term interests of our company. If we cannot maintain this culture, we could lose the innovation, creativity and teamwork that has been integral to our business. Additionally, from time to time, we realign our resources and talent to implement stage-appropriate business strategies, including furloughs, layoffs, or reductions in force. In such cases, we may find it difficult to prevent a negative effect on employee morale or attrition beyond our planned reduction, in which case our products and services may suffer and our business, operating results, and financial condition could be adversely affected. In the event of employee or service provider misconduct or error, our business, operating results, and financial condition could be adversely affected. We have and may in the future experience employee or service provider misconduct. Employee or service provider misconduct or error could subject us to legal liability, financial losses, and regulatory sanctions and could seriously harm our reputation and negatively affect our business. Such misconduct could include engaging in improper or unauthorized transactions or activities, misappropriation of customer funds, insider trading and misappropriation of information, failing to supervise other employees or service providers, improperly using confidential information, as well as improper trading activity such as spoofing, layering, wash trading, manipulation and front-running. Employee or service provider errors, including mistakes in executing, recording, or processing transactions for customers, could expose us to the risk of material losses even if the errors are detected. Although we have implemented processes and procedures and provide trainings to our employees and service providers to reduce the likelihood of misconduct and error, these efforts may not be successful. Moreover, the risk of employee or service provider error or misconduct may be even greater for novel products and services and is compounded by the fact that many of our employees and service providers are accustomed to working at tech companies which generally do not maintain the same compliance customs and rules as financial services firms. This can lead to high risk of confusion among employees and service providers with respect to compliance obligations, particularly including confidentiality, data access, trading, and conflicts. It is not always possible to deter misconduct, and the precautions we take to prevent and detect this activity may not be effective in all cases. If we were found to have not met our regulatory oversight and compliance and other obligations, we could be subject to regulatory sanctions, financial penalties, restrictions on our activities for failure to properly identify, monitor and respond to potentially problematic activity and seriously damage our reputation. Our employees, contractors, and agents could also commit errors that subject us to financial claims for negligence, as well as regulatory actions, or result in financial liability. Further, allegations by regulatory or criminal authorities of improper trading activities could affect our brand and reputation. Our officers, directors, employees, and large shareholders may encounter potential conflicts of interests with respect to their positions or interests in certain crypto assets, entities, and other initiatives, which could adversely affect our business and reputation. We frequently engage in a wide variety of transactions and maintain relationships with a significant number of crypto projects, their developers, members of their ecosystem, and investors. These transactions and relationships could create potential conflicts of interests in management decisions that we make. For instance, certain of our officers, directors, and employees are active investors in crypto projects themselves, and may make investment decisions that favor projects that they have personally invested in. Many of our large shareholders also make investments in these crypto projects. In addition, our co-founder and Chief Executive Officer, Mr. Armstrong, is involved in a number of initiatives related to the onchain economy and more broadly. For example, Mr. Armstrong currently serves as the chief executive officer of ResearchHub Technologies, Inc., a scientific research development platform. This and 72 Table of Contents other initiatives he is involved in could divert Mr. Armstrong’s time and attention from overseeing our business operations which could have a negative impact on our business. Moreover, we may in the future be subject to litigation as a result of his involvement with these other initiatives. Similarly, certain of our directors, officers, employees, and large shareholders may hold crypto assets that we are considering supporting for trading on our platform, and may be more supportive of such listing notwithstanding legal, regulatory, and other issues associated with such crypto assets. While we have instituted policies and procedures to limit and mitigate such risks, there is no assurance that such policies and procedures will be effective, or that we will be able to manage such conflicts of interests adequately. If we fail to manage these conflicts of interests, or we receive unfavorable media coverage with respect to actual or perceived conflicts of interest, our business could be harmed and the brand, reputation and credibility of our company could be adversely affected. General Risk Factors Adverse economic conditions could adversely affect our business. Our performance is subject to general economic conditions, and their impact on the crypto asset markets and our customers. The United States and other key international economies have experienced cyclical downturns from time to time in which economic activity declined resulting in lower consumption rates, restricted credit, reduced profitability, weaknesses in financial markets, bankruptcies, and overall uncertainty with respect to the economy. Adverse general economic conditions have impacted in the past, and may impact in the future, the onchain economy, although the extent of such impacts remains uncertain and dependent on a variety of factors, including market adoption of crypto assets, global trends in the onchain economy, central bank monetary policies, instability in the global banking system, volatility and disruptions in the capital and credit markets, and other events beyond our control. Geopolitical developments, such as trade wars and foreign exchange limitations can also increase the severity and levels of unpredictability globally and increase the volatility of global financial and crypto asset markets. For example, in the past the capital and credit markets have experienced extreme volatility and disruptions, resulting in steep declines in the value of crypto assets. To the extent general economic conditions and crypto assets markets materially deteriorate or decline for a prolonged period, our ability to generate revenue and to attract and retain customers could suffer and our business, operating results and financial condition could be adversely affected. Moreover, even if general economic conditions were to improve following any such deterioration, there is no guarantee that the onchain economy would similarly improve. Further, in 2022, a number of blockchain protocols and crypto financial firms, and in particular protocols and firms involving high levels of financial leverage such as high-yield lending products or derivatives trading, suffered from insolvency and liquidity crises leading to the failure of several prominent crypto trading venues and lending platforms. Some of which are alleged or have been held to be the result of fraudulent activity by insiders, including misappropriation of customer funds and other illicit activity and internal controls failures. In connection with these failures, concerns were raised about the potential for a market condition where the failure of one company leads to the financial distress of other companies, which has the potential to depress the prices of assets used as collateral by other firms. If such a market condition were to become widespread in the onchain economy, we could suffer from increased counterparty risk, including defaults or bankruptcies of major customers or counterparties, which could lead to significantly reduced activity on our platform and fewer available crypto market opportunities in general. Further, forced selling of crypto assets by distressed companies could lead to lower crypto asset prices and may lead to a reduction in our revenue. To the extent that conditions in the general economic and crypto asset markets were to materially deteriorate, our ability to attract and retain customers may suffer. Actual events involving limited liquidity, defaults, non-performance or other adverse developments that affect financial institutions, transactional counterparties or other companies in the financial services industry, or the financial services industry generally, or concerns or rumors about any such events or other 73 Table of Contents similar risks, have in the past and may in the future lead to market-wide liquidity problems. For example, in March 2023, Silvergate Capital Corp. announced it would wind down operations and liquidate Silvergate Bank. Soon after, the FDIC was appointed receiver of Silicon Valley Bank and Signature Bank. In connection with these issues and issues with other financial institutions, the prices of fiat-backed stablecoins, including USDC, were temporarily impacted and may be similarly impacted again in the future. Further, if the instability in the global banking system continues or worsens, there could be additional negative ramifications, such as additional all market-wide liquidity problems or impacted access to deposits and investments for customers of affected financial institutions and certain partners, and our business, operating results and financial condition could be adversely affected. We are a remote-first company which subjects us to heightened operational risks. Our employees and service providers work from home and we are a remote-first company. This subjects us to heightened operational risks. For example, technologies in our employees’ and service providers’ homes may not be as robust as in our offices and could cause the networks, information systems, applications, and other tools available to employees and service providers to be more limited or less reliable than in our offices. Further, the security systems in place at our employees’ and service providers’ homes may be less secure than those used in our offices, and while we have implemented technical and administrative safeguards to help protect our systems as our employees and service providers work from home, we may be subject to increased cybersecurity risk, which could expose us to risks of data or financial loss, and could disrupt our business operations. There is no guarantee that the data security and privacy safeguards we have put in place will be completely effective or that we will not encounter risks associated with employees and service providers accessing company data and systems remotely. We also face challenges due to the need to operate with the remote workforce and are addressing those challenges to minimize the impact on our ability to operate. Environmental, social, and governance factors may impose additional costs and expose us to new risks. There is focus from certain investors, regulators, employees, users and other stakeholders concerning corporate responsibility, specifically related to environmental, social, and governance matters (“ESG”) and related assurances and disclosures. Compliance with recently adopted and future ESG requirements, including the E.U.’s Corporate Sustainability Reporting Directive and Corporate Sustainability Due Diligence Directive and California’s climate-related bills, may require the dedication of significant time and resources. If we are unable to comply with new laws and regulations or changes to existing legal or regulatory requirements concerning ESG matters, or if we fail to meet investor, industry, or stakeholder expectations and standards relating to ESG matters, our reputation may be harmed, customers may choose to refrain from using our products and services, we may be subject to fines, penalties, regulatory or other enforcement actions, and our business, operating results, and financial condition could be adversely affected. Changes in U.S. and foreign tax laws, as well as the application of such laws, could adversely affect our business, operating results, and financial condition. We are subject to complex tax laws and regulations in the United States and a variety of foreign jurisdictions. All of these jurisdictions have in the past and may in the future make changes to their corporate income tax rates and other income tax laws which could increase our future income tax provision. For example, our future income tax obligations could be adversely affected by earnings that are lower than anticipated in jurisdictions where we have lower statutory rates and by earnings that are higher than anticipated in jurisdictions where we have higher statutory rates, by changes in the valuation of our deferred tax assets and liabilities, by changes in the amount of unrecognized tax benefits, or by changes in tax laws, regulations, accounting principles, or interpretations thereof, including changes with possible retroactive application or effect. 74 Table of Contents