From December 2024 to January 2025, Coinbase users lost over $65 million due to social engineering scams. This was reported by on-chain detective ZachXBT.
1/ Over the past few months I imagine you have seen many Coinbase users complain on X about their accounts suddenly being restricted.
— ZachXBT (@zachxbt) February 3, 2025
This is the result of aggressive risk models and Coinbase’s failure to stop its users losing $300M+ per year to social engineering scams. pic.twitter.com/PjtX7vmjqc
One victim reported a loss of around $850,000. An analysis of fund movements revealed an address where the stolen funds from over 25 thefts on the Coinbase platform were consolidated.
ZachXBT explained that the scammer used personal information stolen from private databases to convince the victim of unauthorized login attempts to their account. The scammer then sent a fake email from the exchange, instructing the victim to whitelist a specific address and transfer funds there. The email contained a link to a counterfeit site that closely resembled the original Coinbase platform.
According to ZachXBT, the reported losses of $65 million over two months and $300 million annually are likely much lower than the actual figures, as they do not account for claims filed with customer support and the police.
The expert criticized Coinbase’s leadership for failing to properly address such attacks, noting that the exchange rarely reveals scammer addresses, even when the thefts continue for weeks.
“Last month, clients were advised not to use VPNs to avoid raising suspicions with the platform, while at the same time, scammers intentionally block access to VPNs on phishing sites and do not use them. This shows Coinbase’s inability to diagnose the real problem,” said ZachXBT.
The detective recommended that the exchange strengthen its anti-fraud measures, including making phone number entry optional for users who have passed the KYC check, restricting fund withdrawals, and improving community interaction.
Earlier, ZachXBT reported that in December 2024, one Coinbase user lost $11.5 million through a social engineering scam.