Spoofed Calls, Cloned Logins: The $65 Million Social-Engineering Wave Hitting Coinbase Users
Coinbase customers lost a combined $65 million to phishing and impersonation scams over a two-month period, according to an investigation by on-chain researcher ZachXBT. The losses came while the exchange's public attention was largely directed toward its regulatory advocacy efforts.

The scams follow a repeatable, multi-stage script rather than relying on any smart-contract exploit. It starts with a call that displays as Coinbase's own support line, placed using personal data — name, recent trading activity, even specific deposits — obtained from prior leaks, lending the call false credibility. A follow-up phishing email then arrives carrying a fabricated case ID designed to resemble genuine Coinbase correspondence. Victims are steered toward a cloned version of Coinbase's login page, closely matching the platform's current interface, which harvests their credentials. The scheme closes with victims being told to "verify" their account by moving funds to a wallet described as secure — one that in fact belongs to the attackers.
On-chain tracing tied more than 25 separate victims to a single address labeled coinbase-hold.eth (0x53F9a859eff25D845D0a6e02bc0f9Ba3e2760fE6), indicating a coordinated operation rather than scattered, independent incidents. Stolen assets were then routed through swaps, bridges, and mixers to obscure their trail. ZachXBT's findings point to two groups behind much of the activity: "The Com," a set of Telegram-based crypto-theft and redistribution networks, and separate fraud rings operating out of India.
The investigation also flagged weaknesses in how Coinbase responded to reports of fraud. Addresses already known to belong to scammers reportedly kept operating for weeks, continuing to process stolen funds while flagged support tickets sat unresolved. Additional problems cited included API keys labeled "read-only" that in practice allowed write access, and a verification-code bug that let attackers redirect two-factor codes to email addresses of their choosing. The same reporting noted that a $15.9 million Coinbase Commerce exploit went unresolved for an extended stretch even as roughly $38 million connected to the BTCTurk exchange hack passed through Coinbase's platform.
ZachXBT's research estimates that users lose about $300 million annually to this category of scam across the industry — a figure that stands in contrast to Coinbase's simultaneous push for U.S. regulators to let banks outsource crypto custody to exchanges like itself. The report also noted that competing exchanges, including Binance, Kraken, and OKX, have not shown comparable losses tied to this particular scam pattern.
Among the remedies ZachXBT proposed: letting verified users who rely on hardware security keys drop phone numbers as an authentication factor, blocking withdrawals to newly added addresses for beginner accounts, staffing fraud response with human reviewers rather than automated systems alone, and pursuing legal action against scammers based in the United States. None of these changes had been adopted at the time of reporting.
Victims of these scams were directed to reach out to zeroShadow or SEAL911 for assistance. Credit for uncovering the scope of the operation goes to ZachXBT, alongside reporting from Crypto.News and Cointelegraph, and on-chain data from Arkham Intelligence and MetaSleuth.

Get new scam files the moment we publish them — usually 2–3 emails a week.