The post ZachXBT traces $2M Canadian impersonator appeared on BitcoinEthereumNews.com. A new report on a complex fake Coinbase scam shows how a Canadian fraudsterThe post ZachXBT traces $2M Canadian impersonator appeared on BitcoinEthereumNews.com. A new report on a complex fake Coinbase scam shows how a Canadian fraudster

ZachXBT traces $2M Canadian impersonator

A new report on a complex fake Coinbase scam shows how a Canadian fraudster used support impersonation to steal millions in digital assets from platform users.

Canadian support impersonator steals over $2 million

A Canadian scammer posing as a support executive from crypto exchange Coinbase allegedly stole over $2 million in crypto from unsuspecting users through highly targeted social engineering schemes. Moreover, the individual repeatedly presented himself as a legitimate Coinbase support agent during calls and chats to win victims’ trust.

Independent on-chain analyst ZachXBT traced the scheme by cross-referencing wallet activity, Telegram accounts, and social media posts. According to his findings, the fraudster spent the proceeds on rare social media usernames, bottle service, and gambling, highlighting how quickly illicit crypto gains can be converted into a lavish lifestyle.

How the social engineering crypto scam operated

The investigation, detailed in a post on X dated Dec. 29, describes a sophisticated social engineering crypto scam in which the attacker convinced Coinbase users that he was a genuine support representative. However, behind the scenes, he was systematically guiding victims into making unauthorized transactions that funneled funds into wallets

he controlled.

For those unfamiliar with the tactic, social engineering, often called human hacking, relies on psychological manipulation rather than technical exploits. Attackers pressure or deceive individuals into revealing sensitive information or approving transfers, making it one of the most effective cryptocurrency wallet theft methods currently observed in retail-focused fraud.

In one leaked video shared by ZachXBT, the scammer can be seen pretending to be a Coinbase support agent while speaking with a user. During the call, he inadvertently reveals an email address and his Telegram handle, which investigators then used to tie his identity to various online profiles and crypto wallets.

Tracking the suspect behind the Coinbase support impersonation

Throughout the campaign, the fraudster, whom ZachXBT dubbed “Haby (Havard)”, allegedly accumulated more than $2 million over roughly a year. That said, his pattern of spending on premium Telegram identities became a key clue, as he continually purchased expensive Telegram usernames and deleted older accounts in an apparent attempt to erase his digital footprint.

However, this operational security mistake intersected with his public behavior. Haby reportedly posted openly on social media, flaunting luxury goods and nightlife expenses that appeared inconsistent with any legitimate income. These posts, combined with blockchain data and messaging records, ultimately enabled ZachXBT to piece together the scammer’s profile.

According to the investigation, the suspect’s activity and personal details aligned closely enough for the analyst to reportedly pinpoint his location in Abbotsford, British Columbia, turning what started as an online anonymity play into a traceable abbotsford crypto fraud case.

Broader pattern of Coinbase-focused attacks

The case fits into a wider trend in which Coinbase, due to its high profile and large user base, becomes a prime target for threat actors. Moreover, attackers deploy multiple vectors, including phishing campaigns, coinbase scam emails, live impersonation calls, and fake support chats, all aimed at bypassing user security rather than breaking platform infrastructure.

Once funds are stolen, they are often quickly moved through mixing services or converted into privacy coins, a process frequently described as privacy coins laundering. Because blockchain transactions are typically irreversible, recovery becomes extremely difficult unless law enforcement can rapidly identify and intercept the flows in cooperation with exchanges.

Previous large-scale losses linked to Coinbase users

Earlier this year, ZachXBT publicly urged Coinbase to take urgent action after uncovering that similar social engineering schemes resulted in at least $65 million stolen from Coinbase users between December 2024 and January 2025. However, he emphasized that these numbers likely understate the true scale, as many victims never report incidents.

In a separate case disclosed in June, the investigator exposed a New York-based scammer using the alias “Daytwo”. This individual allegedly stole over $4 million from Coinbase customers, including a single $240,000 theft from a senior citizen. The stolen funds in that operation were frequently diverted to online gambling platforms and converted into privacy-focused assets such as Monero.

Other leading exchanges, including Binance, have faced comparable attacks involving fraudulent support outreach and fake security alerts. That said, the level of detail in this latest zachxbt investigation details illustrates how open-source intelligence and on-chain forensics can still unmask individual perpetrators.

Recognizing and avoiding a coinbase scam

The term coinbase scam in this context generally refers to criminals misusing the brand to exploit users, rather than any wrongdoing by the exchange itself. Moreover, many incidents share recurring warning signs that retail investors can learn to spot early.

Legitimate support representatives from major exchanges will never ask for seed phrases, full login credentials, or two-factor authentication codes. They also will not redirect conversations to unverified third-party channels such as random WhatsApp numbers or personal Telegram accounts, which often feature prominently in coinbase scam calls and chat-based fraud.

Key safety practices for exchange users

To reduce risk, users should independently verify any unexpected outreach claiming to come from an exchange, especially if it references a supposed coinbase email scam or urgent account compromise. However, instead of engaging through links or numbers provided in the message, they should log in directly via the official website or app and contact support from there.

It is also critical to double-check URLs, avoid downloading remote-access software at a stranger’s request, and treat any demand for immediate large transfers as a red flag. By combining basic operational security habits with skepticism toward unsolicited assistance, users can significantly lower their exposure to evolving social engineering threats.

In summary, the case of Haby in Abbotsford, together with earlier multimillion-dollar thefts tied to Coinbase users, underscores how social engineering remains one of the most effective tools for crypto fraudsters. However, ongoing investigative work by analysts like ZachXBT, along with better user education and exchange security practices, can gradually narrow the window of opportunity for such schemes.

Source: https://en.cryptonomist.ch/2025/12/30/coinbase-scam-traced-zachxbt/

Market Opportunity
Scamcoin Logo
Scamcoin Price(SCAM)
$0.001045
$0.001045$0.001045
+3.46%
USD
Scamcoin (SCAM) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Exploring how biases in the peer-review system impact researchers' choices, showing how principles of fairness relate to the production of scientific knowledge based on topic importance and hardness.
Share
Hackernoon2025/09/17 23:15
MAXI DOGE Holders Diversify into $GGs for Fast-Growth 2025 Crypto Presale Opportunities

MAXI DOGE Holders Diversify into $GGs for Fast-Growth 2025 Crypto Presale Opportunities

Presale crypto tokens have become some of the most active areas in Web3, offering early access to projects that blend culture, finance, and technology. Investors are constantly searching for the best crypto presale to buy right now, comparing new token presales across different niches. MAXI DOGE has gained attention for its meme-driven energy, but early [...] The post MAXI DOGE Holders Diversify into $GGs for Fast-Growth 2025 Crypto Presale Opportunities appeared first on Blockonomi.
Share
Blockonomi2025/09/18 00:00