Posted an overview about all of the recent account restrictions for Coinbase users and how it relates to $300M+ stolen via social engineering scams.
ZachXBT
@zachxbt
11mo
1/ Over the past few months I imagine you have seen many Coinbase users complain on X about their accounts suddenly being restricted.
This is the result of aggressive risk models and Coinbase’s failure to stop its users losing $300M+ per year to social engineering scams. https://t.co/PjtX7vmjqc


18
36
158
A Coinbase user was likely social engineered and scammed for 110 cbBTC ($11.5M) on Base last month by a threat actor.
The stolen funds were immediately swapped, bridged, and laundered through multiple instant exchanges and funds consolidated with other Coinbase victims on Ethereum.
Theft transaction hash
0x8639f4b44...
11
46
154
Someone was likely hacked for $29M (6.27M SUI) on Sui last month on December 12th, 2024.
The stolen funds were bridged from Sui to Ethereum via Bridgers and then deposited to Tornado Cash in batches.
Primary theft address
0x731c2cd8f060428e7bb520899c855b48bf4b22d9
81f07a69ce3d0a258f3e589a
Theft transaction hash
4xo... 11
61
208
The P2P marketplace Noones was likely exploited for ~$7.9M on Ethereum, Tron, Solana, & BSC on January 1-2, 2025 as its hot wallets saw hundreds of suspicous outflows for <$7K per txn.
Shortly after the platform made an announcement about maintenance although no official statement was made about any security incident...
0
30
112
Here’s a 31 minute video of the phishing scammer ‘Vkevin’ secretly being recorded draining victims while running a fake Safeguard verification bot scam on Telegram.
12
40
162
A few hours ago wallets tied to crypto influencer JRNY saw ~$4M worth of crypto assets suspiciously transferred out and sold indicating a potential private key compromise.
Theft address
0xc467150582cfc8eec4132a483c76101d3636f598
0x6fd6c8fd64c7efdb8eec902161d3bbc035430456
0xa2dd5e2ab84240cbecc7beaca9946afef97ae74a
10
15
80
Multisig exploiter just transferred 9980 ETH ($31.4M) to the crypto exchange exchange eXch, swapping from Ethereum to Bitcoin in 7 orders.
Source address
0x2d146Aa23645950FDefBb23f636A5d1674FE1047
Destination address
bc1qffvx38hplm6ym5el5yakxmntezv7tg6yurghnq
bc1qut035lpe0k6yklcrkaquhvg4x65lkg5n3uvnel
bc1qe6yk9rnae0l... 136
30
135
Looks like the crypto casino Metawin was exploited for $4M+ on Ethereum and Solana earlier today.
See 115+ theft addresses tied to the exploiter below.
So far stolen funds have been transferred to Kucoin and a HitBTC nested service.
166
24
108
I recently spoke with Andy Greenberg from WIRED, who did a profile that dives into my journey over the past few years. It was a great experience to reflect on the evolution of my investigations.
15
50
252
My new research detailing a Chinese OTC trader named Yicong Wang who Lazarus Group has used since 2022 to off-ramp tens of millions from crypto hacks.
10
30
126


