ZachXBT Tracked Part of $6.5 Million Stolen from Coinbase Client

coinbasehackerss

In October, a client of the cryptocurrency exchange Coinbase in the US fell victim to a hacker who used social engineering to steal $6.5 million. On-chain detective ZachXBT helped the victim track part of the stolen funds.

The hacker, known by the username Ronaldd (or Ronald Spektor), impersonated Coinbase’s customer support team over the phone and tricked the user into visiting a phishing website.

After gaining access to the victim’s assets, the hacker exchanged them for Bitcoin and Ethereum. He then converted all the assets into Litecoin and distributed them across various platforms.

“Just a few days after the theft, Ronaldd began showing his Ledger Live via Discord, revealing that on October 8, 2024, he had received $3.1 million,” said ZachXBT.

During the investigation, the detective discovered the now-deleted hacker’s Telegram channel, which contained screenshots of the wallet used in the chain of stolen funds.

The wallet linked to the account TON was funded by several exchanges.

“This address is linked to several other withdrawals from Coinbase, suggesting more potential phishing victims,” added the researcher.

Thanks to numerous data leaks, ZachXBT was able to identify the hacker’s email, IP address from New York, and his alleged name.

However, the investigation has not progressed as the victim deleted the X account they were communicating with the detective from. It was also unclear if Ronaldd had accomplices or where the remaining $3.4 million of the stolen funds had gone.

As a reminder, according to ZachXBT, over the past year, Coinbase users have lost between $100 million and $150 million due to phishing and social engineering scams.