Coinbase Users' $300M+ Stolen Funds Moved Again via Tornado Cash

iconCoinpedia
Share
AI summary iconSummary
ETH news: A threat actor tied to over $300 million in stolen Coinbase funds is moving assets again. Onchain investigator VAL reported that $500K was converted to ETH and sent to Tornado Cash. This follows a $2 million ETH update via the same mixer three weeks ago. The funds came from a social engineering scam targeting users. Tens of millions remain in the attacker’s wallets.

The Coinbase users previous theft story once again came to limelight today. As the scam actor linked to more than $300 million in stolen funds is moving money again, with onchain investigator VAL reporting that around some quantity was converted to ETH and sent to Tornado cash yesterday. This transaction comes after another big stash reportedly took the same route three weeks ago.

Coinbase Users Theft Came Through Social ENgineering

This wasn’t a smart-contract exploit. In fact the stolen funds came from an extensive social engineering campaign targeting individual Coinbase users, with scammers allegedly impersonating as customer support to trick victims into revealing credentials, transferring assets or approving malicious transactions.

Onchain investigators, including ZachXBT, previously tracked the cumulative losses at more than $300 million. And despite the scale of the theft, tens of million of dollars reportedly remain sitting in wallets associated with the threat actor. That said, there is a lot of ammunition there is that is still sitting onchain.

The Threat Actor Is Moving Ethereum Again

As per VAL’s latest update, around $500K was converted into ETH before being sent to Tornado Cash yesterday. A separate $2 million transaction of conversion happened to ETH which was carried out three weeks earlier as well and sent through the same route, which is via the Tornado Cash.

The movement are notable because the funds stolen from users weren’t simply sitting untouched. In fact the threat actor appears to be actively moving portions of the stolen funds, while sustained balances remain in associated wallets.

The Same Actor Once Mocked ZackXBT Investigator

The case also has an unusually brazen history. The threat actor previously embedded custom messages directly into transactions sent toward ZachXBT’s wallet effectively trolling the analyst while tracking efforts were underway at the time.

The wallet identified in the latest update include ‘0x5Da2….89D8a’ and ‘0x3ECe….f296’. For Coinbase users, the episode is another reminder that social engineering can be just as damaging as technical exploit. The Coinbase users theft now has a fresh development, and with tens od million still reportedly parked in wallets, the story clearly isn’t finished.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.