That distinction matters. In a contract exploit, an attacker typically abuses a flaw in the logic of an on-chain application. In a support-impersonation scam, the attacker manipulates the account holder into authorizing—or enabling—the transfer. The vulnerable point is the user’s trust and decision-making, often reinforced by convincing personal details and a sense of urgency.
In February 2025, blockchain investigators ZachXBT and tanuki42 reported more than $65 million in Coinbase-user losses across December 2024 and January 2025, while estimating that annual losses from similar social-engineering scams could exceed $300 million. Their review included victim reports and on-chain activity, but also acknowledged that the available data was incomplete.
A later report attributed about $45 million in additional Coinbase-user losses to coordinated social-engineering scams in a single week in May 2025. These figures support the view that the attacks were persistent and organized. They do not, by themselves, prove that all reported incidents were controlled by the same wallet operator.
One investigation also identified a consolidation address associated with more than 25 victims. Such clustering can help investigators connect transactions and identify a campaign pattern, but it is still indirect attribution rather than proof of a real-world identity.
Coinbase disclosed in May 2025 that criminals bribed some overseas customer-support personnel to obtain customer information. The stolen data was reportedly intended to help criminals impersonate Coinbase and trick users into sending cryptocurrency. Coinbase estimated remediation and voluntary customer-reimbursement costs of between $180 million and $400 million.
That incident could make support scams more persuasive: a caller who knows a customer’s name, contact details or account information may appear much more credible. But the public evidence provided here does not establish that the criminals behind the insider-data incident were the same people controlling the wallets linked to the broader theft reports. The two stories should therefore be treated as related risk context, not a confirmed common attribution.
In May 2025, a wallet linked by investigators to Coinbase phishing campaigns reportedly swapped about $42.5 million in Bitcoin for Ether through THORChain. The wallet also sent ZachXBT an on-chain message reading “L bozo.”
The message showed that whoever controlled the wallet was willing to publicly provoke an investigator. It did not establish the person’s name, location or connection to every other theft attributed to the campaign.
A cryptocurrency mixer is designed to complicate the straightforward link between a deposit and a later withdrawal. Tornado Cash uses shared pools and privacy-preserving transaction mechanics so that funds deposited from one address may later be withdrawn to a different address. The result is not that the blockchain disappears, but that the simple deposit-to-withdrawal trail becomes much harder to establish.
Investigators can still examine timing, transaction sizes, repeated wallet behavior, bridges, decentralized exchanges and centralized-exchange deposit addresses. Those clues may help create a correlation. But correlation is not always enough to identify the person behind a withdrawal or to persuade an exchange or court to freeze funds. The longer assets remain outside a traceable custodian, the more difficult recovery can become.
On November 26, 2024, the U.S. Court of Appeals for the Fifth Circuit held that the Treasury Department’s Office of Foreign Assets Control exceeded its statutory authority when it sanctioned Tornado Cash’s immutable smart contracts. The court reasoned that those contracts were not “property” that could be blocked under the relevant law.
The decision addressed the legal basis for those sanctions; it did not legalize theft or money laundering, erase potential criminal liability, or guarantee that funds sent through a mixer can be recovered. It also does not convert suspicious mixer activity into proof of innocence or guilt. The ruling and the criminal-use question are separate issues.
The most persistent risk in this case is not a mysterious failure in Coinbase’s blockchain infrastructure. It is a convincing person on the other end of a call, message or link.
Users should:
The August movement shows that funds associated with the reported campaign remain active. But the larger conclusion is more basic: social engineering can defeat strong technical controls when an attacker successfully persuades a legitimate user to authorize the transfer.