- Coinbase -Users Discovered an Error in their Account Activity Log Files
- The logs showed failed login attempts as failed 2FA codes
- The Bug was apparently used in social engineering but there is no evidence
The two-factor approval (2FA) error on Coinbase, one of the largest cryptocurrency-trading platforms in the world, was finally fixed.
In early April, Coinbase customers began to note that their account activity logs showed “2-step verification failed” items. These suggest that someone tried to log in using valid credentials but was only stopped after entering the wrong 2FA code.
Coinbase (and a few media, including Bleeping computer) Was soon notified of the messages and launched a study. Apparently, the log showed when someone tried to log in using the wrong credentials, but mistakenly stated it as “2-step verification failed”. In some cases, the log would also show the message “Second_Factor_Failure”, which basically meant the same thing.
Other increase
The platform has since addressed the problem and updated the log to show a “password attempt failed” message instead.
Although it may sound trivial, Bleeping computer Says that attaching errors like this is “essential”, not to cause unnecessary panic. Apparently, some users reached out to say that they reset their passwords and “spent hours” finding out if their accounts were hacked or not.
In addition, the publication claims that wrong labels could be abused in social technical attacks, with villains who convince victims that their stories were compromised and fool them into making wrong decisions.
As one of the biggest cryptocurrency -trading platforms out there, Coinbase is often the target of different scams. Crypto is a fireplace for cyber criminals as it still works mostly in the gray zone, and then means, once transferred, are impossible to pick up. In addition, some tokens, such as Monero, give their users high levels of anonymity and privacy, making it almost impossible to determine the identity of scammers and cyber criminals.
Via Bleeping computer