The post Coinbase Breach Actor Behind the $300M Heist Shifts $5M in Fresh Moves appeared on BitcoinEthereumNews.com. The threat actor behind the Coinbase customer breach resurfaced on October 2, moving fresh capital across stablecoin rails before bridging funds away within minutes, according to blockchain investigator ZachXBT. He reported that roughly 5 million DAI was swapped into an equivalent amount of USDC and sat for only about 35 minutes before being bridged, with a portion routed through Circle’s Cross-Chain Transfer Protocol (CCTP). This was not the first time the actor signaled activity on-chain. On May 21, the same wallet complex transferred more than $42.5 million from Bitcoin to Ethereum through THORChain. On the occasion, the hack left a message trolling ZachXBT. Latest movement by Coinbase’s threat actor | Source: DeBank A $300 Million Breach Coinbase disclosed on May 15 that a data breach had occurred, affecting less than 1% of its monthly active users, according to the exchange. A group of overseas support agents with privileged access was bribed and recruited by outside actors. Those insiders exposed names, contact details, identity documents, and partially masked financial data, which was enough to supercharge impersonation campaigns. Coinbase emphasized that core infrastructure, including authentication secrets, private keys, and Prime wallets, remained uncompromised, and it pledged to compensate affected users. CEO Brian Armstrong stated that the attackers attempted to extort $20 million in Bitcoin. However, the company refused the ransom and instead announced a $20 million reward fund for information leading to arrests and convictions. Coinbase response to the data breach and thefts | Source: X The US Department of Justice initiated an investigation immediately afterward, and Coinbase’s preliminary estimate for remediation and reimbursements ranges from $180 million to $400 million. That insider-enabled data trove became the raw material for industrial-grade social engineering. Alliance DAO’s Qiao Wang described a highly scripted playbook. Impostors posing as Coinbase staff flagged “compromised” accounts, steering targets… The post Coinbase Breach Actor Behind the $300M Heist Shifts $5M in Fresh Moves appeared on BitcoinEthereumNews.com. The threat actor behind the Coinbase customer breach resurfaced on October 2, moving fresh capital across stablecoin rails before bridging funds away within minutes, according to blockchain investigator ZachXBT. He reported that roughly 5 million DAI was swapped into an equivalent amount of USDC and sat for only about 35 minutes before being bridged, with a portion routed through Circle’s Cross-Chain Transfer Protocol (CCTP). This was not the first time the actor signaled activity on-chain. On May 21, the same wallet complex transferred more than $42.5 million from Bitcoin to Ethereum through THORChain. On the occasion, the hack left a message trolling ZachXBT. Latest movement by Coinbase’s threat actor | Source: DeBank A $300 Million Breach Coinbase disclosed on May 15 that a data breach had occurred, affecting less than 1% of its monthly active users, according to the exchange. A group of overseas support agents with privileged access was bribed and recruited by outside actors. Those insiders exposed names, contact details, identity documents, and partially masked financial data, which was enough to supercharge impersonation campaigns. Coinbase emphasized that core infrastructure, including authentication secrets, private keys, and Prime wallets, remained uncompromised, and it pledged to compensate affected users. CEO Brian Armstrong stated that the attackers attempted to extort $20 million in Bitcoin. However, the company refused the ransom and instead announced a $20 million reward fund for information leading to arrests and convictions. Coinbase response to the data breach and thefts | Source: X The US Department of Justice initiated an investigation immediately afterward, and Coinbase’s preliminary estimate for remediation and reimbursements ranges from $180 million to $400 million. That insider-enabled data trove became the raw material for industrial-grade social engineering. Alliance DAO’s Qiao Wang described a highly scripted playbook. Impostors posing as Coinbase staff flagged “compromised” accounts, steering targets…

Coinbase Breach Actor Behind the $300M Heist Shifts $5M in Fresh Moves

2025/10/03 02:42

The threat actor behind the Coinbase customer breach resurfaced on October 2, moving fresh capital across stablecoin rails before bridging funds away within minutes, according to blockchain investigator ZachXBT.

He reported that roughly 5 million DAI was swapped into an equivalent amount of USDC and sat for only about 35 minutes before being bridged, with a portion routed through Circle’s Cross-Chain Transfer Protocol (CCTP).

This was not the first time the actor signaled activity on-chain. On May 21, the same wallet complex transferred more than $42.5 million from Bitcoin to Ethereum through THORChain. On the occasion, the hack left a message trolling ZachXBT.

Latest movement by Coinbase’s threat actor | Source: DeBank

A $300 Million Breach

Coinbase disclosed on May 15 that a data breach had occurred, affecting less than 1% of its monthly active users, according to the exchange.

A group of overseas support agents with privileged access was bribed and recruited by outside actors.

Those insiders exposed names, contact details, identity documents, and partially masked financial data, which was enough to supercharge impersonation campaigns.

Coinbase emphasized that core infrastructure, including authentication secrets, private keys, and Prime wallets, remained uncompromised, and it pledged to compensate affected users.

CEO Brian Armstrong stated that the attackers attempted to extort $20 million in Bitcoin.

However, the company refused the ransom and instead announced a $20 million reward fund for information leading to arrests and convictions.

Coinbase response to the data breach and thefts | Source: X

The US Department of Justice initiated an investigation immediately afterward, and Coinbase’s preliminary estimate for remediation and reimbursements ranges from $180 million to $400 million.

That insider-enabled data trove became the raw material for industrial-grade social engineering. Alliance DAO’s Qiao Wang described a highly scripted playbook.

Impostors posing as Coinbase staff flagged “compromised” accounts, steering targets into “verification,” and then captured assets by supplying pre-generated seed phrases for supposed security wallets.

The con blended urgency, authenticity cues from stolen personal data, and technical theater to extract custody.

Meanwhile, market voices, such as Wintermute’s Evgeny Gaevoy, argued that rigid KYC/AML frameworks can paradoxically increase civilian exposure by centralizing sensitive identity data, which, once leaked, fuels more crime.

Normalized Thefts

The October 2 transfers also re-exposed how compliant, allowlisted infrastructures are used in flight.

ZachXBT said part of the funds moved through Circle’s official CCTP, a legitimate bridge that burns USDC on one chain and mints it on another.

That matters because it converts bridging into an issuance workflow rather than an asset swap, potentially complicating freeze-and-seize options if controls are not wired to fire rapidly.

ZachXBT vented recently about how the crypto industry is dependent on government agencies. He said:

“For an industry that was founded on principles of independence from the government it’s embarrassing how reliant we are on them to find a solution for victims.

There’s no other industry that has normalized thefts to the same extent.” In his statement, the investigator emphasized “major problems” without a solution, and these issues continue to worsen.

Among the problems listed, he questioned what would happen when the majority of law enforcement agents are incapable of tracking funds on-chain.

He further questioned when there are jurisdiction barriers, and when there is a lack of action from stablecoin issuers to freeze funds quickly.

Viewed narrowly, the latest movement from the Coinbase threat actor is a status update. Hackers remain active, opportunistic, and confident in outrunning asset-level controls.

Viewed broadly, it is a stress test of the “full stack.” Exchanges’ internal access controls, customer-support vendor management, data-handling hygiene, law enforcement speed, and the responsiveness of stablecoin issuers and bridges when red flags are triggered.

Source: https://www.thecoinrepublic.com/2025/10/02/coinbase-breach-actor-behind-the-300m-heist-shifts-5m-in-fresh-moves/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Kalshi Partners with Solana & Base to Launch KalshiEco Hub for Onchain Prediction Markets

Kalshi Partners with Solana & Base to Launch KalshiEco Hub for Onchain Prediction Markets

The first prediction markets exchange to be regulated by the CFTC, Kalshi, has launched the KalshiEco Hub in partnership with Solana and Coinbase-backed Base. The new program aims to bring builders, traders, and content creators onto an expanding ecosystem of blockchain-based prediction markets. The launch of the KalshiEco Hub signals a step toward linking traditional […]
Share
Tronweekly2025/09/18 16:30
Share
GBP trades firmly against US Dollar

GBP trades firmly against US Dollar

The post GBP trades firmly against US Dollar appeared on BitcoinEthereumNews.com. Pound Sterling trades firmly against US Dollar ahead of Fed’s policy outcome The Pound Sterling (GBP) clings to Tuesday’s gains near 1.3640 against the US Dollar (USD) during the European trading session on Wednesday. The GBP/USD pair holds onto gains as the US Dollar remains on the back foot amid firm expectations that the Federal Reserve (Fed) will cut interest rates in the monetary policy announcement at 18:00 GMT. At the time of writing, the US Dollar Index (DXY), which tracks the Greenback’s value against six major currencies, holds onto losses near a fresh two-month low of 96.60 posted on Tuesday. Read more… UK inflation unchanged at 3.8%, Pound shrugs The British pound is unchanged on Wednesday, trading at 1.3645 in the European session. Today’s inflation report was a dour reminder that UK inflation remains entrenched. CPI for August was unchanged at 3.8% y/y, matching the consensus and its highest level since January 2024. Airfares decreased but this was offset by food and petrol prices. Monthly, CPI rose 0.3%, up from 0.1% in July and matching the consensus. Core CPI, which excludes volatile items such as food and energy, eased to 3.6% from 3.8%. Monthly, core CPI ticked up to 0.3% from 0.2%. The inflation report comes just a day before the Bank of England announces its rate decision. Inflation is almost double the BoE’s target of 2% and today’s release likely means that the BoE will not reduce rates before 2026. Read more… Source: https://www.fxstreet.com/news/pound-sterling-price-news-and-forecast-gbp-trades-firmly-against-us-dollar-ahead-of-feds-policy-outcome-202509171209
Share
BitcoinEthereumNews2025/09/18 01:50
Share
MoonBull Crypto Presale Site Climbs at Stage 4 With 27.40% Jump as Ethereum and Toncoin Strengthen

MoonBull Crypto Presale Site Climbs at Stage 4 With 27.40% Jump as Ethereum and Toncoin Strengthen

The post MoonBull Crypto Presale Site Climbs at Stage 4 With 27.40% Jump as Ethereum and Toncoin Strengthen appeared on BitcoinEthereumNews.com. The crypto presale site investors are buzzing about could already be igniting, while many are still standing on the sidelines. Every cycle brings projects that soar, but only a few combine smart mechanics with meme-level hype , the ones that go from whispers to roars in weeks. Chasing the top presale projects often feels like trying to catch lightning in a bottle. Some investors jump too late and end up “holding the bag,” while others secure early spots and watch their conviction compound. It’s the eternal race to spot the next breakout before it blasts off. Toncoin vs Ethereum comparison dominates headlines with their latest updates , one driven by network growth, the other by scaling solutions. But right now, the MoonBull presale opportunity is showing why meme coin presale hype is real: numbers are climbing, and momentum is undeniable. MoonBull: A Crypto Presale Site Built on Trust and Growth Two features separate MoonBull from countless other projects claiming to be the best crypto presale sites contender: Referral System , Rewards on Both SidesMoonBull ($MOBU) referral system flips the script on community growth. Share a code, and when someone joins, both benefit. The inviter receives 15% in tokens instantly, while the new participant gains 15% extra tokens on top of their purchase. Add monthly leaderboards with USDC bonuses, and suddenly word-of-mouth becomes a growth engine with teeth. It’s like turning community chatter into rocket fuel for everyone involved. MoonBull Presale Opportunity: Stage 4 Numbers Don’t Lie The MoonBull official site is tracking a presale that’s already making waves. At Stage 4, the token is priced at $0.00005168 with over $200,000 raised and 700+ holders onboard. With a listing price of $0.00616, current investors are staring at more than 11,800% ROI potential. Early participants who entered at Stage 1 have already…
Share
BitcoinEthereumNews2025/10/06 08:15
Share