Coinbase Users Suffer $45 Million Losses in Social Engineering Scams

Coinbase Users Suffer $45 Million Losses in Social Engineering Scams

By: Eva Baxter

In a recent investigation, blockchain analyst ZachXBT revealed that Coinbase users have suffered substantial financial losses due to an ongoing wave of social engineering scams. Over the past week, victims reportedly lost a staggering $45 million, adding to the cumulative annual losses of over $300 million attributed to these sophisticated scams.Coinbase, a major cryptocurrency exchange, has been identified as a primary target for these attacks. ZachXBT and fellow researcher Tanuki42 meticulously traced these thefts, highlighting the exploitation of vulnerabilities in Coinbase's user verification and compliance mechanisms. Suspect addresses connected to the thefts were found on multiple blockchains, including Bitcoin and Ethereum, revealing the scammers' extensive reach.Ethereum

The modus operandi involves scammers impersonating Coinbase representatives, contacting victims through spoofed phone numbers, and orchestrating phishing operations via cloned Coinbase websites. These fraudulent activities are further facilitated by advanced phishing panels and malicious scripts tailored to deceive even vigilant users. Victims are convinced to transfer their assets into what they believe is a secure Coinbase Wallet, only to fall into the hands of orchestrated theft operations. Such deceit underscores the challenges faced by users in securing their funds against increasingly advanced threats.

ZachXBT's disclosures place a spotlight on recurring issues within Coinbase's security architecture, which have been exploited by organized groups such as "The Com" and a network operating from India. Despite prior reports and presented evidence, Coinbase has not effectively mitigated these risks, according to the investigator. ZachXBT emphasizes the exchange's sluggish responses to red flags, including freezing known fraudulent addresses long after they are reported. The ongoing scams have reignited calls for improved security measures, with recommended changes such as removing phone number requirements for enhanced user authentication and bolstering support for international users.

In response to these alarming findings, ZachXBT has proposed a suite of protective measures for Coinbase to consider. Among them are the introduction of optional "elder" account types with withdrawal restrictions, proactive community education initiatives, and regular updates on security incidents. While acknowledging Coinbase's contributions to the broader crypto ecosystem, including the development of tools to aid asset recovery, it's argued that user safety should not be compromised. With no other exchanges experiencing comparable breaches, this predicament underscores a critical need for Coinbase to revive trust through robust and responsive security protocols.

Get In Touch

[email protected]

Follow Us

© BlockBriefly. All Rights Reserved.