TLDR
A So Paulo State Court has treated a self-custody crypto wallet provider as liable for user losses in a landmark case against Coinbase in Brazil.
- The court ordered Coinbase to return about 100,000 dollars to a user whose Coinbase Wallet was allegedly hacked, despite Coinbase not controlling the wallet.
- Judges applied Brazils Consumer Protection Code, effectively saying companies that build self-custody wallet software are responsible for product security and technical explanations.
- This ruling could influence future cases and regulation in Brazil and beyond, increasing legal and security expectations for wallet developers and exchanges.
Deep Dive
1. What The Court Actually Decided
On July 12 2026, the So Paulo State Court ruled against Coinbase in a case involving unauthorized transactions from a users Coinbase self-custody wallet and ordered the company to repay nearly 100,000 dollars plus interest.
Coinbase argued it was not liable because the wallet was under the users full control, but the court found Coinbase failed to prove the user authorized the transfer or that adequate wallet security mechanisms were in place.
The decision relied on Brazils Consumer Protection Code, which puts the burden of proof on the service provider and treats Coinbase, registered in Brazil, as responsible for the security of the wallet product it offers to consumers.
Confidence: high, based on detailed reporting from the So Paulo ruling.
2. How It Changes Liability For Self-Custody
Legal experts quoted in the rulings coverage argue this dismantles a common industry defense that self-custody architecture removes liability from wallet providers, stating that anyone who develops and markets a product is responsible for its security regardless of technical design.
The magistrate also criticized Coinbase for failing to clearly explain technical records or trace where funds went, signaling that technical documentation alone is not enough without understandable evidence presented to the court.
In practice, this leans toward a form of strict product liability for self-custody software in Brazil, at least where a provider is a registered company serving local consumers and cannot show robust security and clear transaction authorization.
wallet and exchange brands that ship self-custody tools may face legal risk if they cannot demonstrate strong security and clear, user-understandable audit trails.
3. Implications For Users And The Wider Market
For Brazilian users, the ruling suggests courts may be willing to protect consumers even when they use non-custodial wallets, potentially making it easier to claim damages after hacks or unauthorized transfers tied to wallet design or security gaps.
For wallet developers and exchanges, it raises the bar on threat modeling, logging, and user education, and may push them to invest more in security features, forensic capabilities, and local legal compliance if they are active in Brazil.
Globally, this single case is not binding outside Brazil, but it adds to a growing trend of regulators and courts scrutinizing non-custodial services and could inform similar arguments in other consumer protection regimes.
if you rely on self-custody wallets, it is increasingly important to choose providers with strong security practices and clear incident-response processes, as legal standards are catching up.
Conclusion
Brazils So Paulo ruling against Coinbase shows that courts can treat self-custody wallet providers as responsible for customer losses when security and evidentiary standards are not convincingly met.
For crypto users and builders, the key shift is not that self-custody is unsafe, but that we just provide the software is no longer a reliable legal shield, especially under consumer protection laws.
Watching how Brazilian regulators and higher courts respond next will be important for understanding whether this becomes a broader precedent for wallet liability worldwide.
