An alleged scammer, posing as a Coinbase help desk employee, reportedly stole more than $2 million in cryptocurrency by using social engineering tactics to convinceAn alleged scammer, posing as a Coinbase help desk employee, reportedly stole more than $2 million in cryptocurrency by using social engineering tactics to convince

$2M Crypto Stolen in Fake Coinbase Support Social Engineering Scam

2025/12/30 17:46
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
  • The fake Coinbase support scammers managed to steal in excess of $2 million.
  • Investigators link the scam to fake support channels and on–chain asset space.

An alleged scammer, posing as a Coinbase help desk employee, reportedly stole more than $2 million in cryptocurrency by using social engineering tactics to convince victims they were receiving legitimate support. He contacted victims through apps like Telegram and fake support chats, often sharing convincing messages or calls that appeared authentic. By gaining their trust, he manipulated them into revealing sensitive account details or authorizing transactions that sent funds directly to wallets he controlled. 

Blockchain investigator ZachXBT identified the scammer by cross-referencing Telegram group screenshots, social media posts, and on-chain wallet transactions tied to the thefts. The fraudster, according to the report, used this tactic to convince them to send funds to wallets he controlled. 

The Smooth Execution Of The Scam

The scam didn’t involve hacking into the Coinbase systems directly, but rather leaned on social engineering, where the attackers try to befriend victims to get sensitive information from them or make them confirm or authorise some transfers. The scammer reportedly posed as an official support agent and directed victims to provide details or move assets to new locations under the guise of “protecting” their funds. Applications were supported by spoofed e-mail addresses and Telegram accounts, some of them connected to his online persona and boasting of making luxury purchases using the stolen funds. 

This kind of impersonation scam is not an isolated case, where extended trends show that quite often, scammers advertise fake support numbers or initiate unsolicited contact to deceive users. Official guidance by Coinbase stresses that legitimate support staff will never ask for passwords, two–factor authentication codes, private keys, or request that users send funds to external wallets, and that genuine communication only happens through verified channels listed on the company’s website or official app. 

The Breaches and Their Risks

Perhaps worse, previous events illustrate that bad actors have previously accessed user information via compromised or extorted support agents. More specifically, Coinbase announced at one point that international agents had been bribed to share customer data, like names, addresses, masked Social Security details, and other personal information, which ended up being used for scams and extortion. Coinbase reacted by firing those who had engaged in this behaviour, and also issued a $250,000 reward for any individual with information leading to the capture of its attackers.  These kinds of scams are the ones that recur, and the ones that are resolved are fewer. While blockchain networks stay secure themselves, on the other hand, there is an increase in the way that attackers manipulate people for their benefit. 

Therefore, it can be seen that investors must be more cautious regarding security measures, given the way scammers are evolving. This would include storing investments in hardware wallets, not disclosing personal information for authentication, and checking support conversations through legit channels. The crypto community, regulators, and users must be aware of the technical measures for them to effectively address any future attacks.

Highlighted Crypto News:

‌Whale Deposits ENA into Binance, Sparks Liquidation Concerns After Ethena Price Drops

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!