Highlights: Coinbase support impersonation scam drained over $2M from unsuspecting users. ZachXBT linked wallets chats and social posts to expose a Highlights: Coinbase support impersonation scam drained over $2M from unsuspecting users. ZachXBT linked wallets chats and social posts to expose a

ZachXBT Uncovers $2M Coinbase Support Impersonation Scam Linked to Canadian Suspect

Highlights:

  • Coinbase support impersonation scam drained over $2M from unsuspecting users.
  • ZachXBT linked wallets chats and social posts to expose a year-long fraud tied to a single Canadian operator.
  • Impersonation scams keep rising as attackers use urgency and human error instead of technical exploits.

ZachXBT, a blockchain researcher, has tracked a one-year-long scam focused on Coinbase users. The scammer pretended to be a Coinbase customer service representative and stole over two million dollars in crypto. The plan was based on plain lying rather than technical adventures. Public online activity and on-chain data contributed to the operation being exposed.

ZachXBT said he uncovered the Coinbase-related scam by linking wallet chat screenshots and social posts. He matched Telegram conversations with transaction timing on public blockchains. Moreover, repeated transfers followed direct contact with Coinbase users.

The investigator identified the suspect as a Canadian individual he called “Haby” or “Havard.” He said the suspect repeatedly bought expensive Telegram usernames. The suspect then deleted older accounts to reduce traceability. Nevertheless, the uniformity of wallet conduct produced new connections among identities.

Social media posts were also a factor. ZachXBT noted common instances of lavish spending with stolen crypto. These posts were consistent with wallet outflows of Coinbase user losses. Consequently, public behavior weakened efforts to remain hidden. The investigator noted repeated operational security failures.

ZachXBT also reviewed a leaked call tied to the scheme. The footage depicted a fake Coinbase support conversation with one of the victims. The impersonator provided a Telegram handle and an email address during the call. The details assisted in connecting multiple accounts. The next action was the movement of wallets after the call.

Open-source data narrowed the suspect location to Abbotsford, British Columbia. ZachXBT did not provide specific details because of platform regulations. Nonetheless, the activity left a track that could be tracked down. Cleanup attempts failed to erase that footprint.

Coinbase Support Impersonation Scam Relied on Social Engineering Tactics

The fraud depended on social engineering rather than malware or smart contract vulnerabilities. The attacker directly contacted Coinbase users and posed as an employee of the exchange. He framed discussions on pressing account issues. This pressure pushed victims to act quickly.

Coinbase attracts these attacks due to its size and visibility. The exchange has millions of retail users globally. The resulting reach provides ample opportunities for impersonation. Moreover, many users expect proactive contact during account alerts. ZachXBT has flagged similar Coinbase-focused scams before. Earlier findings linked social engineering attacks to at least $65 million in losses. Those losses occurred within a short time window. The cases followed the same contact-first pattern.

In June, ZachXBT exposed another scammer using the alias “Daytwo.” That case involved more than $4 million stolen from Coinbase users. One victim lost about $240,000. The money was spent swiftly following theft, restricting chances of recovery. Gambling platforms are frequently used by attackers to launder stolen crypto. They also use methods that slow tracing efforts. These actions reduce the chance of intervention.

Ongoing Impersonation Attacks Keep Exchange Users at Risk

Coinbase users are constantly exposed to impersonation scams. Assailants take advantage of the sense of urgency and trust in personal interaction. Hence, calls that purport to be Coinbase support are to be regarded as suspicious.

Authentic Coinbase customer service does not demand seed phrases or logins. They also never move conversations to Telegram or WhatsApp. Users should contact support only through the official app or website. These habits reduce exposure to manipulation. According to industry data, the risk is not confined to a single exchange. Hacken noted Web3 lost approximately $3.95 billion this year. Access control failures and unsound operational practices were the main causes of most losses.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9
Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Market Opportunity
Scamcoin Logo
Scamcoin Price(SCAM)
$0.000987
$0.000987$0.000987
+1.54%
USD
Scamcoin (SCAM) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump’s Tactics Reignite Crypto’s SEC Dialogue

Trump’s Tactics Reignite Crypto’s SEC Dialogue

Prior to Donald Trump’s influence, cryptocurrency companies primarily encountered the Securities and Exchange Commission (SEC) through legal battles. Under the leadership of former SEC Chair Gary Gensler, the lack of clear guidance from the commission bred a climate of apprehension, leaving businesses in a perplexed state.Continue Reading:Trump’s Tactics Reignite Crypto’s SEC Dialogue
Share
Coinstats2025/09/18 04:08
Ex-FTX Exec’s Plea Deal Still at the Center of Court Case

Ex-FTX Exec’s Plea Deal Still at the Center of Court Case

The post Ex-FTX Exec’s Plea Deal Still at the Center of Court Case appeared on BitcoinEthereumNews.com. Nearly three years after the collapse of crypto exchange FTX, courtroom battles tied to its executives and their associates are still unfolding. This week, Michelle Bond, spouse of former FTX Digital Markets co-CEO Ryan Salame, will return to court for an evidentiary hearing in her criminal case. In a Sunday filing in the US District Court for the Southern District of New York (SDNY), Bond’s legal team requested that a federal judge allow her to testify despite prosecutors’ objections. Prosecutors had argued Friday that it was unlikely Bond could offer testimony relevant to Salame’s plea agreement involving allegations of campaign finance fraud. He’s currently serving time in prison for charges related to his role in the company’s downfall. Salame’s plea deal sits at the heart of Bond’s case over alleged campaign finance violations. Prosecutors alleged that Salame ordered $400,000 in funds tied to FTX sent to her campaign. Bond was charged with conspiracy to cause unlawful campaign contributions, causing and accepting excessive campaign contributions, causing and receiving an unlawful corporate contribution, and causing and receiving a conduit contribution in August 2024. She pleaded not guilty to all charges. “The government has no grounds to pre-emptively bar Ms. Bond from testifying because her testimony is neither redundant nor irrelevant,” said her attorneys. “Ms. Bond’s and her husband’s state of mind in entering into the plea agreement are directly relevant to the issues before the Court […]” Sunday filing by Michelle Bond’s lawyers. Source: Courtlistener As one of five defendants included in the indictment of former FTX and Alameda Research executives, Salame pleaded guilty to conspiracy to make unlawful political contributions and defraud the Federal Election Commission and conspiracy to operate an unlicensed money transmitting business. He was sentenced to seven-and-a-half years in prison, where he reported in October 2024.  After Salame’s guilty plea,…
Share
BitcoinEthereumNews2025/09/23 22:07
SEC New Standards to Simplify Crypto ETF Listings

SEC New Standards to Simplify Crypto ETF Listings

The post SEC New Standards to Simplify Crypto ETF Listings appeared on BitcoinEthereumNews.com. The United States Securities and Exchange Commission (SEC) approved a new standard for crypto ETF listings on Wednesday. The standard is created to simplify the working of exchanges in terms of the process followed for crypto ETP listings. This makes it possible to to avoid the cumbersome route of case-by-case approval being followed so far. With this change, exchanges can bypass the 19(b) rule filing process. It is a review that can stretch up to 240 days and demands direct SEC approval before an ETF can launch. Instead of going through the tedious and lengthy review process, the SEC has set up a system that allows exchanges to act more quickly. Now, when an ETF issuer presents a product idea to exchanges like Nasdaq, NYSE, or CBOE, the exchange can move ahead as long as the proposal meets the generic listing standard. This means that strategies based on a single token or a basket of tokens can be listed without waiting for individual approval. New Standards Will Ease Crypto ETF Listings: SEC Chairman According to the Chairman of the SEC, Paul Atkins, this move is aimed at making it easier for investors to access digital asset products through regulated U.S. markets. He noted that by approving generic listing standards, the agency is helping U.S. capital markets remain a global leader in digital asset innovation. At the same time, the SEC approved the Grayscale Digital Large Cap Fund, a fund made up of Bitcoin, Ethereum, XRP, Cardano and Solana. Furthermore, the SEC also approved a new type of options linked to the Cboe Bitcoin U.S. ETF Index and its mini version. This step further expands the range of crypto-linked derivatives available in regulated U.S. markets. How Will SEC General Listing Standard Impact Altcoin Crypto ETF Market? The SEC’s updated listing standards could clear…
Share
BitcoinEthereumNews2025/09/18 21:38