Coinbase (COIN) users lost over $65 million to social engineering attacks in the past two months with an estimated $300 million lost to such attacks annually, crypto sleuth ZachXBT said in an X post Monday.
The actual figure lost might be higher, because the amount doesn’t include unreported cases, ZachXBT said.
Coinbase has not publicly commented on the matter and did not respond to a CoinDesk request for comment before publication.
Scammers utilize stolen personal data to deceive users by sending fake emails that mimic Coinbase’s official communications, including false case IDs prompting users to transfer funds to scammer-controlled wallets, ZachXBT said.
“Scammers clone the Coinbase site nearly 1:1 and allow the scammers to send different prompts to the target via spoofed emails using panels,” he noted. “The two main groups conducting these scams are skids from the Com and threat actors located in India both primarily targeting US customers.”
“A Coinbase employee told people on X to stop using VPNs to avoid being flagged as suspicious. Meanwhile, threat actors will explicitly block VPNs from phishing sites,” ZachXBT wrote in the now-viral post. “This shows Coinbase’s failure to diagnose the actual problem.”
ZachXBT advised Coinbase to enhance security by making phone number inputs optional, creating a restricted account type for new users, and improving community education on scam prevention.
—
Blog powered by G6
Disclaimer! A guest author has made this post. G6 has not checked the post. its content and attachments and under no circumstances will G6 be held responsible or liable in any way for any claims, damages, losses, expenses, costs or liabilities whatsoever (including, without limitation, any direct or indirect damages for loss of profits, business interruption or loss of information) resulting or arising directly or indirectly from your use of or inability to use this website or any websites linked to it, or from your reliance on the information and material on this website, even if the G6 has been advised of the possibility of such damages in advance.
For any inquiries, please contact [email protected]