
Key takeaways
- São Paulo's court reportedly orders Coinbase to repay roughly R$507,000 after alleged unauthorized Coinbase Wallet transactions
- Brazil's Consumer Protection Code reportedly puts the evidentiary burden on Coinbase despite the wallet's self-custody design
- Attorney Raphael Souza says unexplained technical records cannot shield wallet developers from claims about product security in Brazilian courts
A repayment order with wider implications
On July 12, TFTC reported that the São Paulo State Court ordered Coinbase to repay roughly R$507,000, about $99,000, after a user alleged unauthorized transactions drained a Coinbase Wallet. The court reportedly rejected Coinbase's argument that the product's self-custody architecture ended its responsibility for the disputed transfers.
The account traces to reporting in Portuguese from Livecoins; no public court docket has surfaced. The reporting says Brazil's Consumer Protection Code placed the evidentiary burden on Coinbase as the service provider. Coinbase did not prove that the user authorized the transfers or demonstrate that adequate security protections existed, according to the reports.
"Coinbase had every opportunity to prove that the investor authorized the transaction, explain the technical records, and inform where the funds went. It chose not to do any of that."
That assessment came from Raphael Souza, an attorney specializing in digital law, quoted by Livecoins and TFTC. The reported order required repayment of the full amount plus legal interest (Cryptopolitan put court costs at 10% of the claim). Coinbase has not publicly confirmed whether it will appeal, and the reporting does not explain how the funds were moved.
Self-custody meets consumer law
Coinbase Wallet is designed so the user, rather than Coinbase, controls the private keys. That technical separation normally distinguishes wallet software from a custodian holding customer funds. The reported decision focused elsewhere: whether the company had met its evidentiary obligations under consumer law after placing a product on the Brazilian market.
Souza argued that the ruling weakens two common defenses. A software provider cannot rely solely on the fact that it never held the keys, he said, and raw technical records carry little weight when the court is not given a clear explanation. His view points toward broader exposure for wallet developers, though that remains a possible implication rather than a settled nationwide rule.
"Anyone who develops and puts a product on the market is responsible for its security, regardless of how the technical architecture works behind it."
The distinction matters for open source projects. A court can demand evidence that a developer may never possess by design. Yet this case could also turn on Coinbase's specific presentation, corporate presence, or security claims. Without the judgment or an appellate ruling, it is too early to say that every self-custody wallet serving Brazil inherits the same duty.
Why It Matters
Bitcoin self-custody removes a custodian from control of the keys, but it does not automatically remove software companies from every claim under consumer law. If courts require wallet developers to prove what users authorized on systems the developers cannot control, they risk converting a sovereignty tool into a regulated service relationship. That could favor large companies with legal teams while raising the cost of shipping open source wallets. The sound response is precise law that distinguishes custody, software, and fraud. It should not quietly make permissionless tools liable for evidence they were built never to hold.




















