Blockchain investigator ZachXBT has exposed a Canada-based scammer who allegedly stole more than $2 million in cryptocurrency by impersonating Coinbase customerBlockchain investigator ZachXBT has exposed a Canada-based scammer who allegedly stole more than $2 million in cryptocurrency by impersonating Coinbase customer

ZachXBT Exposes “Canadian” Scammer Who Stole $2M Via Fake Coinbase Support

2025/12/30 18:17
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Blockchain investigator ZachXBT has exposed a Canada-based scammer who allegedly stole more than $2 million in cryptocurrency by impersonating Coinbase customer support, adding to a growing list of social engineering cases targeting users of major exchanges.

In a series of posts on X, ZachXBT said the alleged scammer, identified by the alias “Haby” or “Havard,” spent more than a year posing as a Coinbase help desk worker and tricking users into handing over funds.

ZachXBT Tracks Coinbase Scammer Through Screenshots and Wallet Data

According to the investigator, the suspect relied on classic social engineering tactics rather than technical exploits, manipulating victims into believing their accounts were under threat and needed immediate intervention.

ZachXBT said he was able to trace the activity by cross-referencing screenshots shared in Telegram group chats, social media posts, and on-chain transaction data.

In an instance, dated Dec. 30, 2024, the alleged scammer posted a screenshot boasting of a 21,000 XRP theft, worth about $44,000 at the time, taken from a Coinbase user.

Further analysis linked that XRP address to additional Coinbase-related thefts totaling roughly $500,000.

The investigator said the suspect routinely converted stolen XRP into bitcoin using instant exchange services, a move intended to obscure transaction trails.

Source: ZachXBT

By analyzing transaction timing and wallet balances, ZachXBT said he identified a bitcoin address that later displayed a balance of about $237,000 in February 2025, matching screenshots the suspect had shared while showing off his funds in private chats.

Tracing backward from that address revealed three more Coinbase impersonation thefts worth more than $560,000.

ZachXBT also shared a leaked screen recording that allegedly shows the suspect on a call with a victim, impersonating Coinbase support.

In the video, the caller is heard guiding the target through what appeared to be fake security steps while inadvertently revealing an email address and Telegram account tied to the operation.

The suspect reportedly bought expensive Telegram usernames and deleted older accounts in an attempt to evade detection, though repeated online bragging made attribution easier.

Crypto Users Face Rising Losses as Social Engineering Attacks Spread

The case surfaced as authorities in India recently arrested a former Coinbase customer support agent in Hyderabad over a separate data breach affecting nearly 70,000 users.

Coinbase CEO Brian Armstrong said the breach stemmed from a bribery scheme targeting offshore support staff and resulted in about $307 million in remediation and reimbursement costs.

Coinbase refused to pay a $20 million ransom linked to the incident and instead launched a bounty program to aid investigations.

Social engineering scams like the one described by ZachXBT typically begin with unsolicited calls, texts, or emails that appear to come from a legitimate company.

Scammers often create urgency by claiming there has been suspicious activity or an imminent account compromise, then pressure victims into revealing login credentials or two-factor authentication codes or transferring funds to wallets controlled by the attacker.

The exposure of the alleged Canadian scammer follows other recent enforcement actions. In the United States, prosecutors charged a 23-year-old Brooklyn resident with stealing about $16 million from roughly 100 Coinbase users through a similar impersonation scheme.

That investigation also relied on blockchain analysis and resulted in the seizure of cash and digital assets, with recovery efforts ongoing.

Source: Chainalysis

Industry data show crypto theft remains widespread, with more than $3.4 billion stolen across the sector between January and early December 2025.

Security experts continue to urge users to avoid responding to unsolicited messages, never share passwords or recovery phrases, and only contact support through official websites or apps.

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!