TLDR
A customer support impersonation scam targeted Coinbase (a major CEX), with a single actor posing as staff and stealing over $2 million from users via social engineering report.
- The attacker, known as Haby, convinced victims to authorize transfers under fake urgent security fixes summary.
- Funds were laundered across chains using instant exchanges after consolidation from multiple victims details.
- The scheme reflects a broader rise in brand impersonation and human?layer fraud hitting exchanges context.
Deep Dive
1. What Happened
An on?chain investigation linked a Canadian threat actor, Haby, to more than $2 million stolen by impersonating Coinbase support and manipulating users into risky actions coverage.
- The investigator cross?referenced Telegram screenshots, social posts, and wallet transactions, including a leaked video where the scammer posed as support and exposed contact details write?up.
- Screenshots linked thefts across assets such as XRP and traced conversions into bitcoin to obscure trails analysis.
Treat unsolicited support outreach as hostile by default. Initiate support only via the official site or app.
2. How It Worked
The attack used low?tech social engineering. The impostor claimed to fix urgent account issues, then guided victims to authorize transfers or share access, bypassing strong platform security by exploiting trust report.
- After access, stolen funds were consolidated and swapped across chains with instant exchange services to hinder tracing details.
- This pattern aligns with recent prosecutions that described Coinbase representative impersonation and laundering through mixers and gambling venues context.
Security posture must include human?layer defenses. Verify identity out?of?band and never act on urgent demands from unsolicited contacts.
3. Why It Matters
As exchanges harden infrastructure, attackers shift to brand abuse and impersonation. Typosquatted domains, cloned interfaces, and AI?assisted outreach multiply the reach of social engineering against CEX user bases overview.
- Coinbase users were specifically warned that real support will not request seed phrases, login credentials, or move chats to WhatsApp or Telegram advisory.
- Sector data shows losses skew toward impersonation and access?control failures rather than novel code exploits, reinforcing the human attack surface risk summary.
Adopt simple rules. Only contact support through official channels, never share sensitive info, and consider hardware wallets and 2FA with separate recovery paths.
Conclusion
The impersonation scheme that hit CEX users leveraged fake Coinbase support and social engineering, not a code exploit, to drain funds. The core risk is human trust and brand mimicry. Users who verify support through official portals and refuse unsolicited urgent fixes sharply reduce exposure to this type of fraud.
