CoinBase Account Compromised jerecock
Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' section to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
Reddit user jerecock reports that their Coinbase account was compromised and all funds were withdrawn. From their description it appears that the attacker had remote access to their computer and waited until they logged into their account to initiate the withdrawals and drain the funds. $11k worth of funds were converted to Bitcoin Cash and then drained from the account. They did a lot of steps to contact authorities in an attempt to recover the money and it is unclear if any of those steps were successful.
This is a global/international case not involving a specific country.[1][2][3][4][5][6][7]
About CoinBase
"Yesterday morning I noticed several unusual things happening. My chase fraud alert went off and they canceled my credit card. My Facebook was logged into from an unknown location. My Gmail was hacked and I started to receive hundreds of spam emails... I logged into my Coinbase account to check on it, change passwords, etc. And immediately when logging in i saw my coins which at the time were primarily in MANA and LINK convert to Bitcoin Cash. When I went to click on the Bitcoin Cash wallet the funds were already sent to 2 separate outside wallets and my account was completely drained.
I have the transaction ID and the wallet IDs where it was initially sent. But I understand those coins are likely long gone to other wallets.
I contacted local police to file a theft report. I sent an urgent email to coinbase and suspended my Coinbase account temporarily. I contacted a lawyer specialized in Identity Theft, I contacted an organization called Coinfirm where I logged a detailed report, and I've contacted my local branch of the FBI to look into identity theft.
I'm so worried that I'll never recoup that money lost and I'm even more worried to touch anything that's connected to my Wi-Fi network or devices that are connected to anything financial.
Any advice on what else I can do would mean everything to me. Thank you."
"Thank you for the true advice. I did use SMS 2FA. I'm afraid that might have compromised me.
I also learned through this thread how much more risk is involved in holding my coins on Coinbase rather than in a wallet. I had no idea this was more dangerous, i was ignorant and paid a devastating price.
As someone said earlier, hopefully this serves as a reminder for everyone to keep an eye on their security measures."
"Thank you for all the replies. I realize I could have done much better with preventative measures. I appreciate all the advice and plan to action a lot of the ideas here in this thread.
To those saying I'm lying and I'm a complete idiot. I wish i was lying. And I am a complete idiot. This has been a terrible day and a huge set back for me financially I wouldn't wish this on my worst enemy. But I'm hopeful that other's will read this and it will help them not make the same mistakes I did."
"God i feel so stupid. I legit had no idea this is how coinbase vs wallets worked. Had i known I would've been safer.."
"The latter is exactly the steps I took. Coinbase sent the SMS 2FA and upon receiving and logging in my account was wiped in real time as I watched helplessly. It happened so fast I couldn't do anything. I should have taken more precautions as I've stated and read throughout these comments. Ignorance, being new and excited to crypto, and trying to get ahead blinded me from taking the proper security measures. I wish I could have a do over. But hopefully someone reading this will check themselves and protect their investments in ways i did not."
"Coinbase will not allow two logins with the same 2FA code. Try to log in twice with the same code, you will fail. That means that whoever hacked you had control over your computer (trojan horse virus or browser hijack). In theory, a cyber forensics firm may be able to trace back the connection, but in practice it's hopeless if the attackers were not complete idiots. Not worth the effort unless you lost millions."
This is a global/international case not involving a specific country.
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Include:
- Known history of when and how the service was started.
- What problems does the company or service claim to solve?
- What marketing materials were used by the firm or business?
- Audits performed, and excerpts that may have been included.
- Business registration documents shown (fake or legitimate).
- How were people recruited to participate?
- Public warnings and announcements prior to the event.
Don't Include:
- Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
- Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.
The Reality
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| March 14th, 2021 12:35:32 PM MDT | Reddit Post | Incident is posted on Reddit. |
Technical Details
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?
Total Amount Lost
The total amount lost has been estimated at $11,000 USD.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. : CryptoCurrency (Dec 21, 2022)
- ↑ My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. : CryptoCurrency (Oct 12, 2023)
- ↑ My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. : CryptoCurrency (Oct 12, 2023)
- ↑ My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. : CryptoCurrency (Oct 12, 2023)
- ↑ My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. : CryptoCurrency (Oct 12, 2023)
- ↑ SaneLad comments on My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. (Oct 12, 2023)
- ↑ My Coinbase was hacked and sent $11,000 of Bitcoin Cash to 2 separate unknown wallets. I desperately need help. : CryptoCurrency (Oct 12, 2023)