
In a developing legal showdown, leading crypto exchange Coinbase has filed a lawsuit against Tobias Honscha, a resident of Isernhagen, Germany, for allegedly misusing the domain name coinbase.de in a way that violates both trademark law and the company’s affiliate agreement.
According to a complaint filed in California federal court, Coinbase claims that Honscha deliberately purchased and used a domain that mirrors the company’s brand identity to exploit its decade-long reputation. The domain, rather than representing Coinbase or any official services, was reportedly being used to redirect visitors to a mobile app focused on trading physical coins, creating confusion for users and potentially eroding trust in the Coinbase brand.
But the issue goes far deeper than just redirection. Coinbase alleges that Honscha was monetizing traffic from the domain by embedding affiliate links. These links would earn commissions from Coinbase whenever someone registered using them — something the company says clearly violated their affiliate terms, which strictly prohibit domains from appearing to be officially associated with Coinbase or using its name directly.
Coinbase further revealed that Honscha allegedly pressured the exchange to purchase the domain from him at a high price. The complaint points to messages where Honscha warned about the dangers of phishing attacks, unsolicited user submissions of personal data, and potential misuse of @coinbase.de email addresses, should Coinbase refuse to buy the domain.
This, Coinbase argues, is nothing short of an extortion attempt. The lawsuit describes it as a calculated effort to either profit directly from Coinbase or sell the domain to a third party who could weaponize it for even more malicious cyber activities.
Coinbase also accuses Honscha of running an email service tied to the domain, further increasing the risk that unsuspecting users might be tricked into thinking they were interacting with official Coinbase representatives. The platform warns that such activities could lead to severe security breaches, with users potentially submitting ID documents, passwords, or under false pretenses.

