BPOI Banner
$65M Stolen, Actual Losses Likely Higher $65M Stolen, Actual Losses Likely Higher

$65M Stolen, Actual Losses Likely Higher

Over the past two months, Coinbase users have reported a surge in account restrictions, which appear linked to the company’s aggressive risk models and an ongoing wave of social engineering scams.

ZachXBT believes that the blame for the losses lies with Coinbase’s leadership, failing to report theft addresses, offer responsive support, and react swiftly to threats – issues rivals like Kraken and Binance manage far more effectively.

Coinbase’s Security Crisis

Popular pseudonymous on-chain investigator ZachXBT, alongside zeroShadow researcher ‘tanuki42,’ has uncovered that at least $65 million was stolen from Coinbase users through social engineering scams between December 2024 and January 2025.

Their findings, based on on-chain data analysis and victim reports received via direct messages, suggest the actual figure is likely much higher, as it does not account for cases reported directly to Coinbase or law enforcement.

The scams typically involve attackers posing as Coinbase support, using spoofed phone numbers and emails to gain victims’ trust, often leveraging personal data from private databases. Victims are tricked into transferring funds to compromised Coinbase Wallets and whitelisting fraudulent addresses.

One case involved a loss of $850,000, with the stolen funds consolidated alongside assets from over 25 other victims linked to the address ‘coinbase-hold.eth.’ ZachXBT attributed these scams to groups based in India and low-level cybercriminals from online communities like Com. He criticized Coinbase’s risk models and customer security measures, which he claims have failed to prevent over $300 million in annual losses to such fraud.

Leadership Inaction and Weak Support

In addition to rampant social engineering scams, ZachXBT claimed that Coinbase has quietly experienced several security incidents that were not publicly disclosed. These include breaches involving old API keys used for tax software, which were supposed to have read-only permissions but were compromised, and a recent bug that allowed verification codes to be sent to any email address, regardless of whether it was linked to an account.

In 2023, $15.9 million was stolen from Coinbase Commerce, and a threat actor laundered $38 million from the BTCTurk hack through Coinbase in just a few hours. The blame, according to the detective, largely falls on Coinbase’s leadership for systemic failures in security and customer response.

Theft-related addresses often go unreported in compliance tools for weeks, leaving gaps in fraud detection. Victims frequently encounter ineffective customer support, with little follow-up, and the company’s unavailability outside US hours is problematic for a global 24/7 market.

He further added that competitors such as Kraken, OKX, and Binance manage similar risks more effectively, Coinbase has failed to take decisive action against even low-level US-based threat actors with poor operational security. ZachXBT stated that the core issues stem from leadership decisions, not individual employees.

“Coinbase needs to urgently make changes as more and more users are being scammed for tens of millions every month. Other major exchanges do not have similar panels created by scammers for fraud. While the victims are partially responsible it’s unreasonable to expect elderly victims to understand the nuances of email/phone spoofing.”

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Source link

Chayanika Deka

https://cryptopotato.com/social-engineering-scams-hit-coinbase-users-hard-65m-stolen-actual-losses-likely-higher/

2025-02-05 12:15:53

bitcoin
Bitcoin (BTC) $ 87,197.36 1.18%
ethereum
Ethereum (ETH) $ 2,025.49 2.33%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.36 4.34%
bnb
BNB (BNB) $ 635.64 0.47%
solana
Solana (SOL) $ 138.11 4.84%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.195071 4.87%
cardano
Cardano (ADA) $ 0.736984 4.56%
tron
TRON (TRX) $ 0.233578 1.31%
staked-ether
Lido Staked Ether (STETH) $ 2,023.20 2.36%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,167.35 1.04%
chainlink
Chainlink (LINK) $ 15.63 2.16%
the-open-network
Toncoin (TON) $ 3.89 7.23%
avalanche-2
Avalanche (AVAX) $ 22.01 3.79%
leo-token
LEO Token (LEO) $ 9.76 0.13%
stellar
Stellar (XLM) $ 0.289625 2.74%
sui
Sui (SUI) $ 2.74 4.89%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,430.60 2.14%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 7.07%
usds
USDS (USDS) $ 1.00 0.01%
hedera-hashgraph
Hedera (HBAR) $ 0.191164 4.43%
litecoin
Litecoin (LTC) $ 94.37 2.01%
polkadot
Polkadot (DOT) $ 4.62 2.79%
bitcoin-cash
Bitcoin Cash (BCH) $ 332.88 1.61%
mantra-dao
MANTRA (OM) $ 6.61 3.27%
bitget-token
Bitget Token (BGB) $ 5.03 1.01%
weth
WETH (WETH) $ 2,024.98 2.35%
pi-network
Pi Network (PI) $ 0.840436 3.61%
ethena-usde
Ethena USDe (USDE) $ 0.999402 0.02%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.03%
hyperliquid
Hyperliquid (HYPE) $ 14.54 10.39%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,154.03 2.25%
whitebit
WhiteBIT Coin (WBT) $ 29.18 0.35%
monero
Monero (XMR) $ 223.40 1.47%
uniswap
Uniswap (UNI) $ 6.77 4.71%
near
NEAR Protocol (NEAR) $ 3.00 1.55%
pepe
Pepe (PEPE) $ 0.000009 6.72%
aptos
Aptos (APT) $ 5.92 1.66%
dai
Dai (DAI) $ 0.999898 0.05%
susds
sUSDS (SUSDS) $ 1.04 0.05%
okb
OKB (OKB) $ 49.97 1.22%
internet-computer
Internet Computer (ICP) $ 6.05 4.76%
ondo-finance
Ondo (ONDO) $ 0.912512 4.66%
gatechain-token
Gate (GT) $ 23.53 1.82%
tokenize-xchange
Tokenize Xchange (TKX) $ 36.02 0.57%
mantle
Mantle (MNT) $ 0.843876 0.75%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.16 0.01%
crypto-com-chain
Cronos (CRO) $ 0.101371 4.51%
aave
Aave (AAVE) $ 184.33 2.74%
bitcoin
Bitcoin (BTC) $ 87,197.36 1.18%
ethereum
Ethereum (ETH) $ 2,025.49 2.33%
tether
Tether (USDT) $ 1.00 0.01%
xrp
XRP (XRP) $ 2.36 4.34%
bnb
BNB (BNB) $ 635.64 0.47%
solana
Solana (SOL) $ 138.11 4.84%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.195071 4.87%
cardano
Cardano (ADA) $ 0.736984 4.56%
tron
TRON (TRX) $ 0.233578 1.31%
staked-ether
Lido Staked Ether (STETH) $ 2,023.20 2.36%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,167.35 1.04%
chainlink
Chainlink (LINK) $ 15.63 2.16%
the-open-network
Toncoin (TON) $ 3.89 7.23%
avalanche-2
Avalanche (AVAX) $ 22.01 3.79%
leo-token
LEO Token (LEO) $ 9.76 0.13%
stellar
Stellar (XLM) $ 0.289625 2.74%
sui
Sui (SUI) $ 2.74 4.89%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,430.60 2.14%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 7.07%
usds
USDS (USDS) $ 1.00 0.01%
hedera-hashgraph
Hedera (HBAR) $ 0.191164 4.43%
litecoin
Litecoin (LTC) $ 94.37 2.01%
polkadot
Polkadot (DOT) $ 4.62 2.79%
bitcoin-cash
Bitcoin Cash (BCH) $ 332.88 1.61%
mantra-dao
MANTRA (OM) $ 6.61 3.27%
bitget-token
Bitget Token (BGB) $ 5.03 1.01%
weth
WETH (WETH) $ 2,024.98 2.35%
pi-network
Pi Network (PI) $ 0.840436 3.61%
ethena-usde
Ethena USDe (USDE) $ 0.999402 0.02%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.03%
hyperliquid
Hyperliquid (HYPE) $ 14.54 10.39%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,154.03 2.25%
whitebit
WhiteBIT Coin (WBT) $ 29.18 0.35%
monero
Monero (XMR) $ 223.40 1.47%
uniswap
Uniswap (UNI) $ 6.77 4.71%
near
NEAR Protocol (NEAR) $ 3.00 1.55%
pepe
Pepe (PEPE) $ 0.000009 6.72%
aptos
Aptos (APT) $ 5.92 1.66%
dai
Dai (DAI) $ 0.999898 0.05%
susds
sUSDS (SUSDS) $ 1.04 0.05%
okb
OKB (OKB) $ 49.97 1.22%
internet-computer
Internet Computer (ICP) $ 6.05 4.76%
ondo-finance
Ondo (ONDO) $ 0.912512 4.66%
gatechain-token
Gate (GT) $ 23.53 1.82%
tokenize-xchange
Tokenize Xchange (TKX) $ 36.02 0.57%
mantle
Mantle (MNT) $ 0.843876 0.75%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.16 0.01%
crypto-com-chain
Cronos (CRO) $ 0.101371 4.51%
aave
Aave (AAVE) $ 184.33 2.74%