😎 Summer Sale Exclusive - Up to 50% off AI-powered stock picks by InvestingProCLAIM SALE

Crypto Scam: Sophisticated Social Engineering Attack Targets Coinbase Users

Published 2023-06-14, 11:55 a/m
© Reuters Crypto Scam: Sophisticated Social Engineering Attack Targets Coinbase Users
COIN
-

U.Today - Seasoned trader Jacob Canfield shared his story of almost being scammed by malefactors. The next day, an anonymous whitehat hacker approached him and gave him a few security tips: the trader was contacted by email and phone number that he never shared with the hacker.

Beware: All Coinbase (NASDAQ:COIN) users should change passwords and 2FA credentials

A series of social engineering attacks targets all users of Coinbase, the largest U.S. cryptocurrency exchange ecosystem. Malefactors contact traders and inform them that their password and 2FA settings are allededly changed. Professional trader and investor Jacob Canfield was among those reached by scammers.

First, such information was sent via SMS, but then the scammers started calling Canfield from a San Francisco-registered phone number.

The trader stressed that he never used SMS as an instrument for 2FA. That is, the entire process of "verification" looked strange to him from the very beginning. However, he then received an email from real Coinbase server that included his 2FA code from an active account.

He called this social engineering attack one of the most sophisticated of all time as it includes interaction with a legit Coinbase support unit.

As it stands, it looks like the email from Coinbase is legit and is automatically sent when you request a support ticket to verify your account.

Canfield added that he has information about 30+ users of Coinbase who were targeted by the same scam campaign.

Gemini 2022 data breach might be to blame, white hat hacker says

However, the spiciest thing is the fact that Canfield was contacted by a whitehat hacker who allegedly knows the design of the attack.

He reached the trader by phone and an email that he never shared. The whitehat hacker opined that the Coinbase attacker might use dumps of personal data obtained in previous large-scale attacks:

Canfield is going to create his own guide to cyber security considering the experience of a failed hack attempt and a conversation with a hacker.

This article was originally published on U.Today

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.