Coinbase (Coin) users lost over $ 65 million to social engineering attacks in the last two months of estimated $ 300 million lost to such attacks annually, Crypto Sleuth Zachxbt said in an X post Monday.
The actual lost figure may be higher because the amount does not include -reported cases, Zachxbt said.
Coinbase has not publicly commented on the case and did not respond to a Coindesk request for comment before publication.
Scammers use stolen personal data to deceive users by sending false emails that mimic Coinbas’s official communication, including false case IDs asking users to transfer funds to fraudulent wallets, Zachxbt said.
“Scammers clones the coin base venue almost 1: 1 and allow the scammers to send different prompts to the target via spoofed E emails using panels,” he noted. “The two main groups that perform these scams are sliding from com and threat actors located in India, both primarily aimed at American customers.”
“A coinbase employee told People on X about stopping using VPNs to avoid being marked as suspicious. Meanwhile, threat actors will explicitly block VPNs from phishing sites, ”Zachxbt wrote in the now-viral post. “This shows Coinbas’s failure to diagnose the actual problem.”
Zachxbt advised Coinbase to improve security by making phone number inputs optional, creating a limited account type for new users and improving society’s education in fraud prevention.