ZachXBT linked a fraudulent scheme posing as Coinbase support to the theft of $2 million
The suspect was tracked down through social media, Telegram, and on-chain data
30.12.2025 - 08:55
556
4 min
0
Key points
- ZachXBT reported that over the past year, the attacker posing as a Coinbase support employee stole approximately $2 million worth of cryptocurrency from users.
- The investigation is based on a comparison of on-chain transactions, social media posts, and screenshots from messengers.
- According to the analyst, the suspect is a Canadian citizen.
Blockchain analyst ZachXBT reported that he linked a series of cryptocurrency thefts to a fraudulent scheme in which the attacker posed as a Coinbase support employee. He estimates that the total damage to users over the past year amounted to about $2 million.
In his post on X, ZachXBT stated that he was able to identify the alleged fraudster by comparing messages in Telegram groups, social media posts, and blockchain transactions. According to him, the suspect repeatedly bragged about the thefts in private chats and publicly displayed his wallet balances.
Investigation details
ZachXBT claims that the suspect employed social engineering techniques to deceive Coinbase users into believing he represented the platform’s official support service. In one episode, the analyst published a video recording of a conversation in which the attacker communicates with the victim over the phone, offering fake support services.
According to ZachXBT, during the conversation, the scammer himself revealed his email address and Telegram account, along with a linked phone number. The analyst also stated that cryptocurrency addresses linked to the suspect appear in several other thefts of funds from Coinbase users.
The suspect’s behavior
ZachXBT’s publication notes that the suspect regularly showed off his lifestyle on social media, posting stories and selfies, and spending stolen funds on expensive Telegram usernames. According to the analyst, the attacker periodically deleted accounts, but previously disclosed pseudonyms and on-chain data allowed the chain of activity to be reconstructed.
ZachXBT also stated that he was able to establish the suspect’s presumed location, but did not disclose this information due to the rules of the X platform.
Christmas scam: how Trust Wallet users were robbed
A hacker attack on a popular crypto wallet affected 2596 addresses and resulted in $7 million in damages.
The incident with the fake Coinbase support service occurred against the backdrop of other major attacks on crypto wallet users. On December 26, Trust Wallet confirmed the theft of funds from users due to a critical vulnerability in version 2.68 of the browser extension, into which malicious code was embedded to steal seed phrases. According to the company, the attack affected 2596 wallets, with damages amounting to approximately $7 million, with funds being withdrawn through centralized exchanges and exchangers.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter