Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

Coinbase-posing scammers steal $1.7M from a user amid a string of attacks

CointelegraphCointelegraph2024/07/08 06:22
By:Jesse Coghlan

At least three Coinbase users and one crypto user have reported being targeted by Coinbase-impersonating scammers in the past week, with one victim claiming to have been swindled out of $1.7 million.

Edge & Node co-founder Tegan Kline shared to X on July 7 an explainer from a “good friend” who had their self-custody wallet drained of $1.7 million a day prior after a scammer tricked them into sharing part of their seed phrase .

The victim said the scammer called claiming they were from Coinbase’s security team and sent the victim an email that appeared to be from Coinbase that verified the victim was “speaking to an official representative at Coinbase.”

The scammer claimed the victim’s wallet was “connecting directly with the blockchain” causing transactions to come out of the wallet. The scammer then sent another email appearing to be from Coinbase showing an outgoing transaction.

Part of the victim’s explainer of the scam. Source: Tegan Kline

The scammer directed the victim to a website to enter their seed phrase to stop the transactions, which the victim knew was “not safe” but entered “a portion” of their phrase anyway, without submitting it.

Hours later, $1.7 million was drained from their wallet, they claimed.

Hiro Systems CEO Alex Miller wrote that such websites “are capturing data as you enter it” even without submitting and the victim’s partial reveal of their seed phrase was likely enough for “the bad guys [to] brute force the rest.”

Miller shared that he was also recently contacted by a scammer pretending to be from Coinbase using a similar scam. He believes his information may have been leaked in 2022 from CoinTracker’s email service provider database.

“Specifically, they were using the Coinbase API key connecting to CoinTracker to verify that they were me (in addition to other info),” he said. “At the very least cycle your API keys if you have been using CoinTracker,” Miller advised.

Related: Karma served — Pink Drainer gets hit with address poisoning scam

Last week, X user “TraderPaul04” on July 3 shared what they called a “pretty sophisticated” similar social engineering attempt by a fake Coinbase rep who called them claiming there was a login attempt on their account from a different city.

TraderPaul said “an American male claiming to be a Coinbase employee” said their full name and confirmed their email before claiming to have temporarily locked their Coinbase account, sending a fake password reset link with the aim of nabbing their account password.

Source: TraderPaul04

TraderPaul wasn’t convinced and insisted on calling Coinbase customer service directly, adding the scammer “hung up” after failing to convince him not to.

X user “beanx” on July 7 posted they also had a similar scam call with a fake Coinbase rep claiming “someone attempted to login to my Coinbase.”

Around $1.19 billion was lost to crypto security incidents in the first half of 2024, with over $900 million stolen through phishing and seed phrase compromise attacks.

AI Eye: $1M bet ChatGPT won’t lead to AGI, Apple’s intelligent AI use, AI millionaires surge

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

You may also like

North Korean hackers likely behind $235 million WazirX exploit: Elliptic

Elliptic said its on-chain analysis suggests hackers affiliated with North Korea conducted today’s high-profile exploit of WazirX.About $235 million in crypto was stolen from the Indian exchange, followed by the hackers starting to launder the funds.

The Block2024/07/18 11:13

What’s Next for Solana’s Price Amid Strong Bullish Momentum?

Cryptodnes2024/07/18 11:01

Solana’s on-chain DEX transaction volume exceeded US$1.8 billion yesterday, surpassing Ethereum to rank first

Cointime2024/07/18 10:58

WazirX hacker address transferred 801 billion SHIB in the past two hours

Cointime2024/07/18 10:58

‌Spot copy trading

More
AIOnline
AIOnline
insight1000/1000
10206.96%
ROI
Total profit $52055.52
HappyPlanets
HappyPlanets
insight500/500
14617.21%
ROI
Total profit $29234.4

Bot copy trading

More
SeiSixSechs
SeiSixSechs
insight98/150
$813.32
Total profit
Total subscriber profits $-62.73
BGUSER-FFF8CNJ4
BGUSER-FFF8CNJ4
insight9/150
$1475.38
Total profit
Total subscriber profits $-129.69