A threat actor responsible for more than $300 million in reported thefts from Coinbase users has once again moved a significant portion of stolen funds. On-chain investigator VAL reported that approximately $500,000 was recently converted to Ethereum and transferred to Tornado Cash, an Ethereum-based privacy protocol.
Social engineering scams drive losses
Investigators have linked these substantial losses to coordinated social engineering attacks rather than smart contract vulnerabilities. According to the research, scammers impersonated Coinbase customer support representatives, targeting account holders directly through deceptive communications.
Victims were tricked into sharing sensitive information such as account credentials, or into following fraudulent instructions, which resulted in unauthorized transfers or the approval of malicious transactions. These attacks exclusively targeted individual users, and there has been no evidence indicating an exploit within the Coinbase or Ethereum smart contract infrastructure.
On-chain investigator ZachXBT previously detailed that cumulative losses have exceeded $300 million. This figure accounts for multiple Coinbase accounts compromised during the course of the scam operation.
Tens of millions of dollars are believed to remain in wallets controlled by the threat actor, although investigators did not disclose the current total across all linked addresses.
Funds routed through Ethereum privacy protocols
VAL observed that in the most recent incident, the scammer converted around $500,000 into ETH before transferring it to Tornado Cash. Three weeks earlier, the same operator moved another $2 million using a similar method. Rather than executing a single large transfer, the threat actor used multiple discreet transactions to obscure the trail.
On the Ethereum blockchain, Tornado Cash functions through smart contracts that deposit and withdraw funds separately, complicating efforts to track assets once deposited in the protocol. Investigators noted it remains technically feasible to trace funds until the point of deposit into Tornado Cash contracts.
VAL identified two specific wallet addresses connected to the latest series of transactions: 0x5Da2…89D8a and 0x3ECe…f296. The operator has also been known to send custom messages within transactions to on-chain investigators, such as ZachXBT, often including taunts regarding ongoing efforts to identify the scammer.
Messages apparently mocked both ZachXBT and VAL as they pursued leads in the investigation, but so far no details have emerged about the suspect’s identity or the location of remaining funds.
Growing scrutiny and Web3 innovation
Both ZachXBT, who tracks aggregate losses, and VAL, who reports on the latest movements, have verified that these transactions form part of the same coordinated campaign targeting Coinbase users. In response to ongoing phishing schemes, Coinbase representatives have repeatedly emphasized that their staff will never request passwords, two-factor authentication codes, or asset transfers from customers.
As scams targeting traditional brokerage platforms and centralized exchanges continue, the landscape of asset management is rapidly evolving. While traditional markets rely on complex brokers, a massive shift is happening: Wall Street is moving to Web3. Investors are now using platforms like 1stepSwap to hold shares of major U.S. companies, gold, and silver directly in their crypto wallets. By tokenizing Real-World Assets (RWAs) and automatically finding the best market prices in seconds, it completely removes the middlemen.





USDT
AAPL
